Feeds

Microsoft is crawling toward trustworthy code – experts

Ten years to go

  • alert
  • submit to reddit

Beginner's guide to SSL certificates

A panel of security experts have faith in Microsoft's ability to produce trusted code. The problem is that they think it will take Redmond a decade to learn how to do it.

Famed phreaker Kevin Mitnick headlined a Churchill Club event here on Monday night, joining fellow security gurus from Oracle, ZoneLabs and Black Hat. This uncharacteristically subdued Churchill discussion perked up when the panel turned its attention to Microsoft's Trustworthy Computing mission.

Oracle's Chief Security Officer Mary Ann Davidson drew attention to Microsoft's double standard with its policy of source code disclosure.

"During the antitrust hearnings, Jim Allchin (VP of Platforms at Microsoft) said that opening up their interfaces would create a national security issue," Davidson said.

"So they won't open to the competition and yet they want to give their code to China and Russia. Help me out here. How is opening up your APIs to competitors a national security threat, but it's not if you are giving your code to non-US nations."

This assault on Microsoft resonated with the audience, and came as a bit of shock, following her earlier sympathy for Redmond's virus and worm woes.

Davidson said she felt great pains for her customers who also have Microsoft software and for the company itself, which was mortified by the crippling Slammer worm attack.

She must have wept like a crocodile.

Yes, Oracle's security is a competitive advantage, but it sure would make the world a better place if Microsoft could pull its weight:-

"It's in everybody's best interest if they succeed," she said.

But Gregor Freund, CEO & co-founder of Zone Labs, isn't holding out much hope for a quick fix in Microsoft products.

"I wish they would delineate exactly what Trustworthy computing means," Freund said. "They are starting to do it and in ten years or so the applications will be safe. If they would work with the security industry closely it would be helpful."

Star attraction Kevin Mitnick was muted. He spent most of his time hawking his company's skills in protecting against social engineering.

That said, here's to ten more years of getting there.®

Related Stories

MS relieves patching 'pain point'
Leeds Uni, MS teach undergrads to write secure code
Cost of securing Windows Server 2003? Nearly $200m
Trustworthy Computing does Moon Walk (but not yet)

Security for virtualized datacentres

More from The Register

next story
It's Big, it's Blue... it's simply FABLESS! IBM's chip-free future
Or why the reversal of globalisation ain't gonna 'appen
'Hmm, why CAN'T I run a water pipe through that rack of media servers?'
Leaving Las Vegas for Armenia kludging and Dubai dune bashing
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
CAGE MATCH: Microsoft, Dell open co-located bit barns in Oz
Whole new species of XaaS spawning in the antipodes
Microsoft and Dell’s cloud in a box: Instant Azure for the data centre
A less painful way to run Microsoft’s private cloud
AWS pulls desktop-as-a-service from the PC
Support for PCoIP protocol means zero clients can run cloudy desktops
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.