All the stupid people. Where do they all come from?

Campaign to Re-Educate the Public

  • alert
  • submit to reddit

Build a business case: developing custom apps

Opinion Microsoft's best chance for regaining the revenue lost to security concerns isn't in eliminating bugs, writes SecurityFocus columnist Tim Mullen.

Two years ago I wrote about how security would become critical to the success of Microsoft, and how the challenge of combining "simplicity and security" would represent the highest costs in IT.

For what is apparently the first time in Microsoft's financial disclosure history, the company has reported that security issues, or more appropriately insecurity issues, have directly affected their balance sheet in a negative way. Though quarterly stock earnings were up from last year (and above industry projections), Microsoft has identified losses of approximately $700 million in unearned revenue from non-renewed contracts in product futures. This was primarily attributed to industry concern over recent product vulnerabilities and other security-related problems.

Microsoft bashers will be quick to say things like: "All of Microsoft's revenue is unearned!" But that's just because they don't know any better. The truth is that from a business perspective, Microsoft does an excellent job in their support of customers and partners.

Even so, revenue has been lost, and it is due to customer perception. It isn't a critical hit -- most companies do not get to enjoy unearned revenue; they're lucky if the earned revenue is enough to keep them in business. But this is significant because it marks a time when businesses are finally taking security into account when making their purchases. It shows that the industry is maturing -- that it's ready to hold someone accountable for bad security.

Now that they've grown up, all we have to do is educate the corporate masses to point their fingers at the right places: Not at Microsoft or other vendors, but at themselves.

That's right: education -- not some software Manhattan Project to eliminate buffer overflows -- is what's needed here. The reason most vulnerabilities become issues is because the products are used by people who don't know what they are doing.

Village Idiots

This may get the ire up on some anti-Microsoft zealots, but to be honest, I really don't care. After my last column about the CCIA report, I received many an email from Linux aficionados telling me how fatally flawed the architecture of Windows was. I was amazed at how totally ignorant some of these people are to what the Microsoft reality is -- it seems that many still think the Windows operating system is synonymous with Windows 95. News Flash: It's 2003, time to grow up and get a place of your own.

But Microsoft is not trying to win these people over. In fact, some of the company's worst enemies are the ones who are already their clients.

A case in point comes from a notice in the latest SANS NewsBites. It seems a buddy of Stephen Northcutt's works for a company who has a "C-Level executive" mandating that RPC and NetBIOS not be blocked at the border routers or firewalls. (The editor's note says "between organizations," but the full memo shows that this is the desired configuration over the Internet.) This is so Exchange servers at different sites can communicate over RPC and executives can easily use file sharing. SANS is soliciting solutions for this quandary.

Here's mine: Fire the dolt.

For one thing, you don't block ingress ports on firewalls -- they should all be blocked by default already. You allow them when you have to, and only when you have to.

But regardless of the default firewall policy, any executive who mandates that RPC and NetBIOS be opened at the gateway in order to make file sharing easy needs to find a village missing an idiot, and move there.

And this is probably the same guy who did not renew his contract with Microsoft because his company got hit with Blaster.

Microsoft isn't the problem. The problem is the executive who doesn't want to pay for security to be implemented properly, who mandates ridiculous policies, and who ultimately refuses to do anything that provides any real level of security. These are the people don't take the time or commit the resources to ensure that the products they use -- the ones they have become dependent upon -- are being administered by those with security training. Then they blame all their woes on the vendor, while making their staff suffer through the effects of their poor judgment.

This is why the next big step for Microsoft should be in the arena of security education -- right behind patch management. Look for this shift soon, as this time, right or wrong, security is hitting Microsoft's bottom line.

If this kick in the Microsoft wallet has the end result of increasing security, then it's ultimately a good thing. Even if we have to lose a clueless executive or two along the way.

SecurityFocus columnist Timothy M. Mullen is CIO and Chief Software Architect for AnchorIS.Com, a developer of secure, enterprise-based accounting software. AnchorIS.Com also provides security consulting services for a variety of companies, including Microsoft Corporation.

The essential guide to IT transformation

More from The Register

next story
Rupert Murdoch says Google is worse than the NSA
Mr Burns vs. The Chocolate Factory, round three!
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
Know what Ferguson city needs right now? It's not Anonymous doxing random people
U-turn on vow to identify killer cop after fingering wrong bloke
Germany 'accidentally' snooped on John Kerry and Hillary Clinton
Dragnet surveillance picks up EVERYTHING, USA, m'kay?
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
prev story


Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Solving today's distributed Big Data backup challenges
Enable IT efficiency and allow a firm to access and reuse corporate information for competitive advantage, ultimately changing business outcomes.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.