The Mac Observer

Skip navigational links

Featured Article: BMO Capital Forecasts 2.4M+ Macs For the Quarter

Security Firm Says Microsoft's Effort To Make Windows Secure Get Failing Grade

by , 12:00 PM EST, January 31st, 2003

Hold on to your hats, because a security company has given Microsoft a failing grade on its effort to make Windows secure. Those who do things like read newspapers, or Internet news sites, or even just surf the Internet may be shocked by that pronouncement, but that's What ZDNet is reporting.

The report was prompted by the latest Windows exploit to cause problems on the Internet, a worm called SQL Slammer. That worm was responsible for slow-downs on the Internet this past week experienced by TMO staffers, our forum members, and reported throughout the media. We point that out, because a recent editorial from Mac baiter John C. Dvorak said that he couldn't find any examples of Internet slow-downs caused by SQL Slammer, and faulted the media for causing a scare. Better yet, he suggested that the hubbub over the worm was possibly a conspiracy to promote anti-virus products. Seriously.

In any event, according to the ZDNet, TruSecure Corp. has given Microsoft an "F" on security since the company publicly made security Job One. From ZDNet:

Computer security experts said on Thursday the recent "SQL Slammer" worm, the worst in more than a year, is evidence that Microsoft's year-old security push is not working.

"Trustworthy Computing is failing," Russ Cooper of TruSecure Corp. said of the Microsoft initiative. "I gave it a 'D-minus' at the beginning of the year, and now I'd give it an 'F.'"

The worm, which exploited a known vulnerability in Microsoft's SQL Server database software, spread through network connections beginning on Saturday, crashing servers and clogging the Internet.

It hit a year and one week after Microsoft Chairman Bill Gates sent a company-wide e-mail saying Microsoft would make boosting security of its software a top priority.

Microsoft placed responsibility on computer users who failed to install a patch that had been available since at least last June.

"The single largest message is: keep your system up to date with patches," Microsoft Chief Security Officer Scott Charney told Reuters.

But the philosophy of patching is fundamentally flawed and leaves people vulnerable, Cooper said. For example, Microsoft didn't follow its own advice as executives confirmed that an internal network was hit by the worm.

"Microsoft was completely hosed (from Slammer). It took them two days to get out from under it," said Bruce Schneier, chief technology officer of Counterpane Internet Security, a network monitoring service provider. "It's as hypocritical as you can get."

[...]

"The problem is the whole patch regime has lots and lots of problems," [Richard M. Smith, a Cambridge, Massachusetts-based computer security consultant] said. "It would be much better if the software shipped from Microsoft with fewer problems to begin with."

There is much more in the full article at ZDNet's Web site.

The Mac Observer Spin:

Color us just as shocked as you are. One might think that a company that has paid only lip service to security for more than two decades could miraculously turn things around in only a year.

For those keeping score at home, please note the liberal amounts of sarcasm that drench today's coverage on this topic. Indeed, the only thing that we truly find mystifying about this whole topic is that the lemmings keep lining up to buy Microsoft's Windows offerings.

Observer Comments

Show: Subjects Only | Full Comments
Comment on this Article

Log in | Register | Having Problems? Reset TMO Cookies & Try Again
Username:   Password:   Log me on automatically each visit   

You are not logged in, and this post will appear as "Guest." Log in with your username and password from the TMO forums. If you do not have a username, you can register here.
Please note that guests are limited to including a maximum of two URLs per post.


Post A Comment
  Subject


  Your Comments



Please enter the word exactly as you see it in the image above. Registered users aren't prompted for this. Having trouble reading the image get a new one.


Recent Headlines - Updated Tuesday, July 8th, 2008

Tue., 6:55 PM
User Friendly Blog by Ted Landau - Why User Interface Design Matters
4:30 PM
Apple Trackpad Secrets and Technical History
4:05 PM
iPodObserver - Apple: What to Bring When Buying iPhone 3G
3:35 PM
Microsoft: We Have a Noisy Competitor
2:50 PM
Columnist: Safari Security Fails to Learn from Past
2:20 PM
iPodObserver - Services to Unlock Mobile Phones Gaining Momentum
1:00 PM
Daylite 3.7.4 Adds iWork 08, Dialectic Integration
12:20 PM
FoneLink 2.1 Adds Support for More Cell Phones
11:25 AM
Freeway 5.1.3 Adds Chinese Support
11:10 AM
iPodObserver - Rumor: Canadian Apple Stores Won't Sell iPhone 3G
10:35 AM
Microsoft Aligns with Icahn for Yahoo Takeover
10:00 AM
Hot Forum Topic - Is Internet Killing the Video Star?
8:20 AM
iPodObserver - MobileMe Launches on July 10
7:55 AM
iPodObserver - Apple: iPhone 3G Launches at 8AM Friday
6:00 AM
iPO Review - BudFits
 

The Mac Observer Reader Specials

  • Special Report: WWDC 2008
  • Special Report: iPhone
  • __________
  • Help TMO Grow
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!
  • New Media Expo 2008

Apple Stock Quote

  • AAPL: $179.55. Change Today: +4.39.
  • (Prices delayed up to 20 minutes.)
  • Discuss in our Apple Finance Board

Hot Topics

Top Deals From DealsOnTheWeb