Feeds

Microsoft is crawling toward trustworthy code – experts

Ten years to go

  • alert
  • submit to reddit

Top 5 reasons to deploy VMware with Tegile

A panel of security experts have faith in Microsoft's ability to produce trusted code. The problem is that they think it will take Redmond a decade to learn how to do it.

Famed phreaker Kevin Mitnick headlined a Churchill Club event here on Monday night, joining fellow security gurus from Oracle, ZoneLabs and Black Hat. This uncharacteristically subdued Churchill discussion perked up when the panel turned its attention to Microsoft's Trustworthy Computing mission.

Oracle's Chief Security Officer Mary Ann Davidson drew attention to Microsoft's double standard with its policy of source code disclosure.

"During the antitrust hearnings, Jim Allchin (VP of Platforms at Microsoft) said that opening up their interfaces would create a national security issue," Davidson said.

"So they won't open to the competition and yet they want to give their code to China and Russia. Help me out here. How is opening up your APIs to competitors a national security threat, but it's not if you are giving your code to non-US nations."

This assault on Microsoft resonated with the audience, and came as a bit of shock, following her earlier sympathy for Redmond's virus and worm woes.

Davidson said she felt great pains for her customers who also have Microsoft software and for the company itself, which was mortified by the crippling Slammer worm attack.

She must have wept like a crocodile.

Yes, Oracle's security is a competitive advantage, but it sure would make the world a better place if Microsoft could pull its weight:-

"It's in everybody's best interest if they succeed," she said.

But Gregor Freund, CEO & co-founder of Zone Labs, isn't holding out much hope for a quick fix in Microsoft products.

"I wish they would delineate exactly what Trustworthy computing means," Freund said. "They are starting to do it and in ten years or so the applications will be safe. If they would work with the security industry closely it would be helpful."

Star attraction Kevin Mitnick was muted. He spent most of his time hawking his company's skills in protecting against social engineering.

That said, here's to ten more years of getting there.®

Related Stories

MS relieves patching 'pain point'
Leeds Uni, MS teach undergrads to write secure code
Cost of securing Windows Server 2003? Nearly $200m
Trustworthy Computing does Moon Walk (but not yet)

Choosing a cloud hosting partner with confidence

More from The Register

next story
Azure TITSUP caused by INFINITE LOOP
Fat fingered geo-block kept Aussies in the dark
You think the CLOUD's insecure? It's BETTER than UK.GOV's DATA CENTRES
We don't even know where some of them ARE – Maude
Want to STUFF Facebook with blatant ADVERTISING? Fine! But you must PAY
Pony up or push off, Zuck tells social marketeers
Oi, Europe! Tell US feds to GTFO of our servers, say Microsoft and pals
By writing a really angry letter about how it's harming our cloud business, ta
SAVE ME, NASA system builder, from my DEAD WORKSTATION
Anal-retentive hardware nerd in paws-on workstation crisis
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Getting started with customer-focused identity management
Learn why identity is a fundamental requirement to digital growth, and how without it there is no way to identify and engage customers in a meaningful way.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Reducing the cost and complexity of web vulnerability management
How using vulnerability assessments to identify exploitable weaknesses and take corrective action can reduce the risk of hackers finding your site and attacking it.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.