ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

Wanted: Evidence of MS security push

Published: 04 Mar 2002 16:26 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Five weeks after Bill Gates rang an alarm over security lapses in his company's software, observers are still waiting for real evidence that Microsoft has substantially refocused its priorities.

Microsoft has released some tools to help developers and customers add more security to their systems and has made much ado about retraining its developers during a security crash course that lasted all of February, but customers are waiting to see if the company has made a fundamental shift in philosophy, said Alan Paller, director of research for the Systems Administration Networking and Security (SANS) Institute.

"We have no data anywhere in the field about any (security) improvement on any product," he said. "That's not saying that nothing is better, but just that we can't judge yet."

On Thursday, Microsoft acknowledged that it wouldn't ship Windows .Net Server until the latter half of 2002. One of the reasons, a representative for the software titan said on Friday, was to allow the development team to further tighten security.

Other efforts also indicate that Microsoft is working to secure its products. In January and February, the company retrained more than 9,000 developers, product managers and testers in how to build security into their products. At the RSA Data Security conference last month, the company showed off a program to scan for known vulnerabilities in its products.

The initiatives follow a mid-January memo from Gates, Microsoft's chairman, exhorting employees to make the company's products more trustworthy and incorporate not just more security, but also more consumer-oriented handling of data. In the past, a similar message -- sent out to redirect the company's energy to Internet development and to undermine Netscape's browser leadership -- led to a fundamental shift in the Microsoft's strategy.

Another such shift may already be happening, said Marc Maiffret, chief hacking officer for network protection firm eEye Digital Security.

Maiffret maintained that a change in Microsoft's philosophy would be evident if the software giant released a string of advisories on security holes that it found itself. While such notices are generally bad for the company's image, he argued that notifying customers of any issues it patched would be showing that the company cared more about security than image.

Recently, the company did just that.

"There was one advisory where they had found the flaw themselves," Maiffret said. "I don't know that one means that they are being that proactive. But if they continue to make (flaws) public, that could indicate that another fundamental shift is under way."

While the software giant's delay in releasing Windows .Net server could also indicate a shift, the SANS Institute's Paller stressed that there is no way to judge whether the company really is adding a lot of security to the server operating system or merely pulling off a good marketing maneuver.

"If I needed to delay a product, and I wanted to avoid negative PR, that's what I would say as well," he said.

In fact, for Microsoft -- a company noted for its inability to keep a deadline -- the excuse could be used often.

"I bet every delayed product this year will be due to security concerns," Paller said.


See the Software News Section for the latest headlines on everything from peer to peer clients to Office software and beyond.

Have your say instantly, and see what others have said. Go to the ZDNet news forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
47 out of 106 people found this useful


Full Talkback thread

0 comments

Related Jobs

Exciting AS400 Operator / Suport role - Middlesex / NW London

A leading blue chip company is currently looking for a Shift Operations Analyst. iSeries. AS/400. The job role will require you to deal effectively ...

J2EE Java Software Developer, Massive Bluechip, South Wales

If you want to forge a career with an International Giant, this could be the job you've been waiting for! With massive projects for well-known ...

Interface Developer

HTML/JS - ODBC - Good analytical and problem solving skills - Excellent communication and presentation skills - Good planning and organisational ...

Discussions

keithmv keithmv

Password Deadlock

Saturday 26 July 2008, 12:02 PM

2 comments

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal