ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Application development Toolkit

Spat over MS 'flaw' gets heated

Published: 18 Feb 2002 14:03 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A security company's assertion that a feature in Microsoft's latest software tools has a flaw morphed on Friday into an argument over whether the giant is doing enough to secure its code.

The crux of the debate is now focused on whether the feature -- a software switch known as the 'GS flag' that turns on additional security -- has sacrificed protection for performance, said Crispin Cowan, chief scientist at WireX Communications -- a maker of secure Linux applications -- and the co-founder of open-source security site Sardonix.org.

Cowan likened the GS flag to a flak jacket that protects against certain calibers of bullets. "Now, the disagreement is over the size of the bullets that can penetrate the jacket," he said.

In 1998, Cowan and graduate students from the Oregon Graduate Institute published a paper describing just such a software flak jacket, called StackGuard, that has since been utilised by thousands of open-source developers. Many contend that Microsoft largely held to Crispin's design in creating the GS flag.

The debate heated up on Friday, a day after Microsoft dismissed as "unfounded and patently false" allegations that applications built with its newly announced software tools are more vulnerable to attack.

Microsoft launched its Visual C++.Net and Visual C++ Version 7 on Wednesday and wasn't pleased when, just a few hours later, software-reliability company Cigital stated that a feature of those programs is "flawed."

"In its current form, the Microsoft feature leads to a false sense of security because it is easily defeated," stated a technical note published by Cigital on the issue. A program built using the GS flag option runs additional instructions that can catch some of a class of security flaws known as buffer overruns.

While the statement implies the existence of a vulnerability that makes the feature ineffectual, in reality the flag works against some buffer overruns and not against others. Rather than a vulnerability, both companies acknowledge that Cigital has identified a limitation to the design that Microsoft has chosen to implement.

Microsoft argued that, to add more security, too much code would have had to be added to new applications, slowing them down to an unacceptable degree. Yet, with the current design, at least some buffer overflows can be avoided, said Brandon Bray, program manager for Microsoft's Visual C++ compiler team.

"We maintain the opinion that fixing source code to eliminate buffer overruns is the best and only solid approach to securing software," Bray wrote in a statement. "However...buffer overruns are not always simple to find. Thus, anyone truly interested in writing secure code would not hesitate to use the (GS flag) for their builds."

Microsoft maintains that any additional security that can be added to a program is a good thing. Cigital, on the other hand, argues that Microsoft has only given a slight nod to security with its implementation of the GS flag.

"I stand by my claim that that security mechanism is incorrectly designed," said Gary McGraw, chief technology officer for the firm. "Microsoft's claims about what the GS flag could protect are overstated."

The two sides seem unlikely to relent, but many security experts agree with Microsoft that some security is better than none.

"At least they are putting run-time checking for buffer overruns, which you don't find in other (Windows) compilers," said Chris Wysopal, director of research and development for digital security firm @Stake. "They are trying to do the right thing but are limited by the technology, so you can't blame them for not catching everything."


See the Software News Section for the latest headlines on everything from peer to peer clients to Office software and beyond.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
23 out of 60 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

C++ Expert Bnaking London City

C++, UNIX An amazing opportunity for a C++ UNIX expert with OR without banking experience. You The will become a software developer & architect in a ...

Symbian Developer - C++ - Contract - URGENT

The successful candidate will have C++ Development experience and commercial experience with UIQ. Key words - Symbian, C++, UIQ. Huxley Associates ...

C++ willing to cross train into C# - Small but growing company - 27k

C++ Software Developer, Worcester 25-27k C++ on Linux and prepared to move into C# technologies Technology leaders in vehicle telecoms requires a ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment

Featured Talkback

The fact is: Software developers today are really designers and not coders. The reason that business anlaysts exist today to model solutions is because they understand the value of designing software before writing it. All too often developers create code that has little value because they do not understand that business classes interact with other classes within the confines of a working model or pattern.

By: 1000165269

Read full story:
Making sense of agile modelling