 2007 West |
|
GOLD SPONSORS:
|
Active Endpoints Your SOA Needs BPEL for Orchestration
|
BEA Virtualized SOA: Adaptive Infrastructure for Demanding Applications
|
Nexaweb Overcoming Bandwidth Challenges with Nexaweb
|
TIBCO What is Service Virtualization?
|
|
SILVER SPONSORS:
|
WSO2 Using Web Services Technologies and FOSS Solutions
|
|
Click For 2007 East Event Webcasts
|
|
TOP LINKS YOU MUST CLICK ON
News
i-Technology Opinion: Security Not a Microsoft Priority
'A cursory glance at two Microsoft-related security disclosures in February reveals that, for all of the rhetoric, Microsoft is very slow to respond to critical vulnerabilities' contends LinuxWorld advocacy editor Steve Suehring. 'It appears that Microsoft is merely controlling the information,' he continues, 'rather than controlling the security vulnerabilities and protecting their customers. In addition, old bugs are showing up in new versions of their products.' As Suehring notes: 'Complexity is the enemy of security.'
Reader Feedback : Page 1 of 1
#8 |
nouser commented on the 9 Mar 2005
>dtl commented on 9 March 2005: > > * " Many vulnerabilities for Linux systems are fixed >the same day that they are disclosed." > > I'm sure that patch was thoroughly tested, it >compiled, ship it, yehaaa let em buck... Heh. As opposed to Microsoft's stance: "I'm sure our software isn't vulnerable, and anyway we have to test, test, and re-test and even then the patch will have unintended consequences, better wait to release it, yehaaa let those customers get their systems hacked..." |
#7 |
dtl commented on the 9 Mar 2005
" Many vulnerabilities for Linux systems are fixed the same day that they are disclosed." I'm sure that patch was thoroughly tested, it compiled, ship it, yehaaa let em buck... |
#6 |
You can quickly disable the firewall from command via a netsh command. Disable: netsh firewall set opmode disable Enable: netsh firewall set opmode enable |
#5 |
AaronW commented on the 8 Mar 2005
Didn't SP2 make it impossible in Windows for an application to fill in an invalid source IP address? If this is the case, I wonder if this problem cropped up because Microsoft cannot generate the LAND attack with an up to date version of their OS. Also, I wonder what sort of vulnerabilities exist in Windows for IPv6? -Aaron |
#4 |
Even Garner analyst Neil MacDonald has finally realized: "Microsoft's overriding goal should be to eliminate the need for (antivirus) and (anti-spyware) products, not simply to enter the market with look-alike products at lower prices,..." href="[visit link]">[visit link]
Microsoft's desktop security issues stem from its continued reliance on the Antivirus industries "Infect-Scan-Remove" approach. In comparison, right from the outset, open source desktop platforms and applications have relied almost wholly on closing the infectable vectors, the exploited vulnerabilities used by malware, as quickly as possible.
The result is that both the KDE and GNOME desktop environments are a lot more secure and even more secureABLE. href="[visit link];cid=11539203">[visit link];cid=11539203
Follow this Usenet thread from September 2000 href="[visit link]@heretic.ihug.co.nz">[visit link]@heretic.ihug.co.nz
The thread covers the argument over securing applications Vs scan and repair in detail. David Harley and Robert Moir are two Anitvirus industry leaders. It also includes the prediction that Microsoft would eventually get into the antivirus/antimalware industry. With XP SP2, Microsoft have only just begun to adopt some of the "new" defence strategies outlined by myself in the above thread. However, in my opinion, Microsoft still has yet to secure the actual applications exploited, and five years after the release of Windows 2000, has yet to provide a safe desktop environment for business.
To quote Dr. Blaine Burnham, the former director of the Georgia Tech Information Security Center (GTISC) and previously with the National Security Agency (NSA), "Security is a system wide property". That requires applications, middleware, libraries and the operating system itself to be secured before the whole system can be declared secure.( If you have a spare hour, listen to Dr. Blaine's USENIX 2000 keynote href="[visit link]">[visit link] )
The Linux, Mozilla, KDE and GNOME based projects provide a more secure desktop environment because the developers and distributions secure the applications themselves where the application's vulnerabilities can be exploited. In most cases an updated package is available within days of the discovery. After years of double digit vulnerabilities discovered in Microsoft's Internet Explorer, Microsoft has reluctantly changed its mind again and offered yet another upgrade to IE7, but only for users of XP and the mythical Longhorn. Meanwhile 21 out of 87 Secunia advisories are marked as "Unpatched" in XP professional. href="[visit link]">[visit link] For a company with the financial resources of Microsoft, that is not even close to being a good enough passing grade. It the result of longterm neglect of the securty issues and the result will not be secured by any magic bullet based scan or behavour constraint system. href="[visit link]">[visit link]
Shop around and compare other vendors current ( number of serous issues unpatched ) security status. href="[visit link]">[visit link]
In late 1998 a number of securty experts wrote to Microsoft in an open letter; a number of anti-virus companies signed it saying "hey, here at the things you can actually do to Microsoft Word to dramatically reduce the chances of virus infection" href="[visit link]">[visit link]
It took over four years of the worst publicity and intense pressure from the security community before Microsoft finally began to react. href="[visit link]">[visit link]
Its time to raise the level of expected security in application and desktop design. href="[visit link]@heretic.ihug.co.nz">[visit link]@heretic.ihug.co.nz href="[visit link]@localhost.localdomain">http://groups |
#3 |
Patch-free March commented on the 8 Mar 2005
and in other news...Microsoft's Security Response Center has given advance notice to customers not to expect any security patches for this month!! |
#2 |
jschottm commented on the 8 Mar 2005
Every company that does computer work has to be a security company now. Many companies are completely dependent on computers and most of their crown jewels are stored on them. Many home users have sensitive banking information stored on their computers. Building broken software that allows system disruption or data to be stolen will loose customers. Part of my job is to migrate systems from Windows to Linux, specifically because of security and stability issues. |
#1 |
Tassach commented on the 8 Mar 2005
There is NO legitimate reason whatsoever for a modern, patched operating system to be vulnerable to a simple, 8-year-old DOS attack. What's next, reintroduction of the Ping Of Death vulnerability? This is sloppy quality control, pure and simple. This incident is just another example which demonstrates the importance (or more accurately, the lack thereof) that Microsoft's corporate culture places on security. Hasn't anyone at Microsoft ever heard about regression testing? Microsoft has consistantly demonstrated that, regardless of what their press releases say, security is NOT one of their priorities. People need to start waking up and realizing this before they entrust their critical infrastructure to Microsoft products. |
YOUR FEEDBACK  | PowerBuilder Editorial -
"There You Go Again" By Bruce Armstrong Franck Fasolin wrote: I
have been using PB for 16
years and I am still
waiting for a tool that
would let my developer
team conceive, develop
and maintain applications
with as much productivity
as PB does. I have been
looking to new business
applications developement
tools hopin... |  | After Ubuntu, Windows
Looks Increasingly Bad,
Increasingly Archaic,
Increasingly Unfriendly By Paul Nowak Toner Cartridges wrote:
there are many ubuntu
based linux distributions
that are user friendly. i
especially like the
cd-rom bootable versions
like freespire so I don't
have to forego my windows
permanently. |  | Xandros: An Excellent
Desktop Replacement By Steve Suehring Chris wrote: I have had
issues installing Xandros
4 on several PC's. My
Dell office pc SX 270
went almost perfect. One
of my home boxes at the
beginning of the
installation it said that
no hard disk were
detected - funny Fedora 9
and Vista worked fine.
On my 64 bit Vista PC ... |  | Sun Puts MySQL on an "All
You Can Eat" Plan By Maureen O'Gara Dave L. wrote: The link
to the comparison chart
in your article did not
work. Instead, the
following link is
correct:
http://www.sun.c
om/software/products/mysq
l/popup.jsp?info=1
HTH! |  | Web 2.0 Journal Case
Study: Transcending
E-mail as a Platform for
Multi-Person
Collaboration By Chris Yeh Alice McLane wrote: Email
is still the most popular
project collaboration
tool - this is right. But
its many draw backs are
not the reason to give up
on your favouite
communication medium. As,
you have noticed in your
article, SaaS are
offering more and more
options for
colla... |
SUBSCRIBE TO THE WORLD'S MOST POWERFUL NEWSLETTERS
|
SYS-CON FEATURED WHITEPAPERS  | Adobe's Kevin Lynch and
Microsoft's Scott Guthrie
to Keynote AJAX World RIA
Conference & Expo Two of the biggest
launches in Rich Internet
Application history took
place in 2007/2008 when
Adobe | Extended Validation SSL
Certificates Extended Validation (EV)
is a new standard in SSL
certificates. This guide
explains the needs which | Open Source - What is the
Total Cost of Ownership? In 2005, Scott McNealy of
Sun Microsystems quipped
that open source software
was 'free like a puppy | Cloud Computing - IBM
Creates Cloud Box IBM claims to have
created new species of
custom-built,
industry-standard,
Linux-based rack server f | Guilty of Arrogance Too You have perhaps heard
that while we were on
vacation Linux file
system ace and convicted
wife kille | SCO - Linux' Worst
Nightmare Is Back The court also said
Novell couldn't run
interference for Linux
and stop SCO from seeking
royalty pay | Virtualization Conference
Keynote Webcast Live on
SYS-CON.TV Brian Stevens, the Chief
Technology Officer and
Vice President of
Engineering of Red Hat,
delivered | Red Hat Delivers on Linux
Automation Red Hat announced
advancements that extend
the Company's Linux
Automation strategy by
providing expa | Linspire Collapses into
Xandros Xandros acquired
Linspire's Linux assets
after Linspire changed
its name to Digital
Cornerstone. Wit | Invitrogen Standardizes
on SUSE Linux Enterprise
From Novell Novell announced
Invitrogen has selected
SUSE Linux Enterprise as
the core operating
platform to sta | Reiser's Lawyer Says He's
Nuts On Monday, nine days
ahead of his sentencing
on July 9 for the murder
of his wife, William
DuBois, t | Kernel Developers Want
Linux Purity Not that long ago Linux
barely had two drivers to
rub together. Now it
claims to support 'more
hardw | Was GPLv3 Worth the
Effort? GPLv3, the great General
Public License rewrite,
is now a year-old and
used by 2,345 open source
pro | Novell Delivers Optimized
SUSE Linux Enterprise
Performance for VMware
Virtualization
Environments Novell announced it is
collaborating with VMware
to improve Linux
performance in VMware
environments | Blacknight Solutions
Deploys Parallels
Virtualization Software
to Launch Virtual Private
Servers Parallels virtualization
and automation software
is powering new virtual
private server (VPS)
offeri | Parascale Hires CEO Out
of NetApp Parascale, the
four-year-old firm with
the Cloud Storage system
software layered on the
Linux XFS fi | Xandros Management Tool
Facilitates Red Hat
Server Administration Xandros announced the
release of the all new
Xandros BridgeWays
Management Console for
Red Hat Enter | Desktop Virtualization
Market To Be Worth at
Least $1.8b by 2012 Up
From Nothing Pushing back against
VMware, its chief rival,
Tuesday, Citrix released
its ballyhooed, on-demand
Xen | SYS-CON's Virtualization
Conference & Expo: Themes
& Topics From Application
Virtualization to Xen, a
round-up of the
virtualization themes &
topics being discu | Reiser May Take
Authorities To Murdered
Wife's Body: Wired Right now Reiser faces a
sentence to 25 years to
life for first-degree
murder, a conviction
based on |
|