WebProWorld Part of WebProNews.com
Page One Link To Us Edit Profile Private Messages Archives FAQ RSS Feeds  
 

Go Back   WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Subscribe to the Newsletter FREE!


Register FAQ Members List Calendar Arcade Chatbox Mark Forums Read

Internet Security Discussion Forum This forum is for the discussion of security related issues. If you find a new Phishing scheme, spyware, virus or malicious site - let us know about it. If any of the above found you... here's where you ask for help.

View Poll Results: Is Microsoft to Blame?
Yes 20 20.83%
No 34 35.42%
They are evil incarnate, I'm fanatical about that 42 43.75%
Don't you have anything better to do, mikmik??? 0 0%
Yes, but this is more fun 0 0%
Voters: 96. You may not vote on this poll

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-16-2004, 06:18 AM
mikmik's Avatar
WebProWorld 1,000+ Club
 

Join Date: Aug 2003
Location: Edmonton, AB, Canada
Posts: 3,406
mikmik RepRank 1
Default Is Microsoft to Blame?

15 Seconds
A year ago, if you put an unprotected machine on the Internet, it would be attacked within 15 minutes. Now it's 15 seconds.
Source: Symantec.
Quote:
Is Microsoft to Blame?
All modern software has bugs—lots of them. That goes for Windows, Linux, Mac OS, and any other operating system or application you can think of. Part of the problem is that regardless of how many developers are working on a software tool, and no matter how clever they are, they can't possibly anticipate each and every way someone could attack it.

"Just as you can't stop all bank robberies, you can't stop all software attacks," says Gary McGraw, coauthor of Building Secure Software and chief technology officer at Cigital, a firm that helps improve software security at several Fortune 500 companies. "In any field," he adds, "security is about risk management."

In the software business, however, there are two additional problems: First, modern software is often so complex that developers have trouble understanding exactly how it works, much less how someone could attack it. "Software is the most complicated artifact that we build as a species," posits McGraw. "Something like Window XP includes 40 million lines of code. How many people do you need in the room before they understand all that?"


Second, today's code is built atop yesterday's code, because everybody wants compatibility with old apps and old OSs. When those old apps were written, before the rise of the Internet, when viruses spread like molasses, on floppy disks handed from person to person, the average PC wasn't exposed to outside threats. It didn't have the same need for secure software.

Clearly, Microsoft has a difficult task on its hands. But so do its competitors, and their software isn't attacked nearly as often. Does this mean that Windows is somehow less secure? Maybe, maybe not
....
Quote:
Who's right? Proponents of the different operating systems will probably never agree, but a recent Forrester Research study seems to support Gates's claims. Between June 1, 2002, and May 31, 2003, the study says, security experts found more flaws in each of the four major Linux offerings than in Windows. In that time, for example, 286 flaws were found in Debian Linux, and only 128 were found in Windows. Forrester didn't track flaws in Mac OS or other operating systems, but at least when compared with Linux, Windows seems to be more secure
...
Quote:
"The fact that dedicated hackers working around the world are able to find security holes in Windows does not mean Microsoft is at fault," says Ian Ballon, cochair of the intellectual property and Internet practice group at international law firm Manatt, Phelps & Phillips and also the executive director of Stanford University's Center for E-Commerce. "It's like suing the New York City fire department for injuries arising out of 9/11."
__________________
What I am is what I am, are you what you are, or what.
Eddie Brickel
Reply With Quote
  #2 (permalink)  
Old 07-16-2004, 03:15 PM
mushroom's Avatar
WebProWorld Veteran
 

Join Date: Feb 2004
Location: Queen Charlotte B. C. Canada
Posts: 351
mushroom RepRank 0
Default

The original concept that windows was an OS for the home user is the root of the problem, back then there was no internet and security was sacrificed for ease of use. now all windows users have to pay for this lack of vision.
__________________
Irony: That for most people the most "trusted" web site on the planet is for a company the has been convicted of criminal activity.

Both Security and SuSe start with "S". www.oldslides.com
Reply With Quote
  #3 (permalink)  
Old 07-16-2004, 03:30 PM
mikmik's Avatar
WebProWorld 1,000+ Club
 

Join Date: Aug 2003
Location: Edmonton, AB, Canada
Posts: 3,406
mikmik RepRank 1
Default

Haha, hey mushroom. I found that late last night :O)

The conclusion of the article does state that Microsoft FAILS in their responsibilities!

Also, IE and Outlook Express are inately tied to the OS and there are some serious problems there, no doubt about it. The fact that these client apps are so weak needs to be stressed, and that it takes user knowledge and responsibility to fix is a large shortcoming.

The immense difficulty of controlling the windows scripting host, and stopping mintrusions from hooking to exe and com calls is also overlooked.

This makes windows less user friendly than I used to think.
__________________
What I am is what I am, are you what you are, or what.
Eddie Brickel
Reply With Quote
Reply

  WebProWorld > Webmaster, IT and Security Discussion > Internet Security Discussion Forum
Tags: ,



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Search Engine Optimization by vBSEO 3.2.0