Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Microsoft's Critical New Hire
Tim Mullen, 2002-01-21

Bill Gates can demonstrate that his new security push is genuine by choosing the right person to replace Howard Schmidt.

Comments Mode:
Bill Gates' Critical New Hire 2002-01-21
Philip Storry (1 replies)
How interesting:
"I can't help but notice that when Bill Gates makes a decree that speaks directly to securing his products, people consider it nothing but PR. But when Larry Ellison embarks on a blatant PR campaign of misinformation, people say he is raising the bar for security"

You appear to ...

[ more ]  [ reply ]
Bill Gates' Critical New Hire 2002-01-21
Chad Cyrisse
Yup, I'd bet that the columnists at SecurityFocus have an internal contest of who's getting the most comments to their columns...
Well anyway if they were, Mr. Mullen would certainly be among the best contestants.
About Mr. Mullen's comment on how people react to Bill Gates and Larry Ellison speec...

[ more ]  [ reply ]
Bill Gates' Critical New Hire 2002-01-21
Russ Rogers
I'd love to see Bruce get in there, but I don't think he would even consider the opportunity. But, in my mind anyway, the best person for the job is going to have to be someone they drag in there, kicking and screaming....

[ more ]  [ reply ]
Bill Gates' Critical New Hire 2002-01-21
J Horner <jjhorner@bellsouth.net> (1 replies)
Please don't tell me that you honestly believe this bit of crap! Bill & Co. have a long history of saying one thing and doing another. If I were at the helm, I wouldn't release another stinking thing until everything in testing and everything in development are audited by a trusted 3rd party. Wha...

[ more ]  [ reply ]
Bill Gates' Critical New Hire 2002-01-22
Joseph Finley (2 replies)
I find your lack of faith disturbing. Here's a fact: When Microsoft does announce their security and whatnot, people criticize it. When Larry Ellison announces his (I'm better than GOD) security, people seem to embrace it. One word, Titanic! Anyways to expand on this, this is Liberal Larry vs. ...

[ more ]  [ reply ]
Bill Gates' Critical New Hire 2002-01-28
Anonymous
I have not read any articles supporting Oracle's "Unbreakable" marketing. Could you please point out where we might find these articals?...

[ more ]  [ reply ]
Bill Gates' Critical New Hire 2002-01-29
J. J. Horner (1 replies)
I like Rush, but Rush is wrong here. Microsoft is a blight on the software business. I didn't believe any of Oracle's "Unbreakable" crap, as it was just a PR stunt. This has nothing to do with politics, and don't bring politics in. This has to do with another PR stunt from yet another security p...

[ more ]  [ reply ]
Bill Gates' Critical New Hire 2002-02-06
Anonymous
I agree. This has nothing to do with politics. It has much more to do with religion (especially for the anti-Microsoft/pro-Open-Source camp.) You either Believe or you don't! Unfortunately, once you get into the that realm, reason goes out the Windows...

[ more ]  [ reply ]
Bill Gates' Critical New Hire- I second the Bruce Schneier nonimation. 2002-01-21
Anonymous (1 replies)
I second the Bruce Schneier nomination!
AND if not Bruce... then this "other" person has to be able to convince MS that full cooperation and interaction is
needed with the *nix groups (to embark on an agreement toward any new standards that are needed).
However, Bruce Schneier, and maybe only Br...

[ more ]  [ reply ]
Bill Gates' Critical New Hire- I second the Bruce Schneier nonimation. 2002-01-23
Corrupt Sektor
This then raises couple of questions. First, would Bruce even want the job in the first place? Didn't he say something about MS PPTP being "sucks less"? Second, would Bill want to offer someone like Bruce, who has bagged the crap out of MS technology, a job? Hmmm...interesting.

Cheers,

CS...

[ more ]  [ reply ]
Bill Gates' Critical New Hire 2002-01-21
Night Hawk
Of course no one believes that M$ will do the right thing, by properly auditing their code.

How many times has M$ used "security through obscurity" in the past?

It will take a REAL effort on their developers part for any of us informed people to believe that M$ really is taking security to hea...

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-01-21
c.barbet
Simply following RFCs (and nix those proprietory extensions, i.e. Kerebos) in the software code would help for one. Microsoft could always try to pull expertise from the Linux community... ;-)

Perhaps "modulizing" more of the software code. Microsoft's security problems often relate to software ...

[ more ]  [ reply ]
microsoft column's 2002-01-21
Ilja <ilja@coders.be> (2 replies)
Tim, I bet you a case of beer, that you can't write 2 column's that do NOT involve microsoft.
(if, this does happen, feel free to email me and I will pay for that case of beer !)...

[ more ]  [ reply ]
microsoft column's 2002-01-22
Anonymous (1 replies)
Maybe if you quit your drinking you'd have a few brain cells
to realize that he writes his columns on Microsoft for a
reason. He is the columnist for the "Microsoft Focus"....

[ more ]  [ reply ]
microsoft column's 2002-01-23
michael
Mja, but microsoft is not what it's all about is it?...

[ more ]  [ reply ]
microsoft column's 2002-02-05
Anonymous
Ow please.. Is this the best you can do?...

[ more ]  [ reply ]
Microsoft's Sucker Bet 2002-01-22
Anonymous
I'd like the believe this is a major change for Microsoft. And it may well be. But there's a long road ahead for them. And that road is riddled with political minefields put in place by years of previous culture.

Don't fool yourself. Microsoft's culture has not changed, even when they execute...

[ more ]  [ reply ]
Should be beaten with Ugly Club 2002-01-22
Anonymous (1 replies)
You know, I went and got this article from July 1997,

http://www.win2000mag.com/Articles/Index.cfm?ArticleID=453

If you are too lazy to read it, it basically states that reactions to Windows NT being unsecure are unfounded and not valid.


Move ahead 4+ years, and somehow security is now th...

[ more ]  [ reply ]
Should be beaten with Ugly Club 2002-01-26
Bob Bramwell
Oh, that is *very good*:

Let's suppose you put an NT file server on an
Internet-connected computer. What can the bad guys do?

Indeed. The recent Schneier/Shostack "Results, Not Resolutions" response to the Gates memo gives some idea of the magnitude of the problem. Basically, you don'...

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-01-23
Anonymous (1 replies)
"...a long awaited public asseveration that Microsoft has finally put security above all else."....!?

Nice job on finding "asseveration," but it doesn't help your argument much.

Ask anyone who has worked for Intelligence agencies and/or financial instituitions and they will tell you that **not...

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-01-23
me@crymeariver.com (2 replies)
I wish MS all the luck on what ever they end up doing to their OS ..
Yes the have an OS which is like a pasta strainer , full of wholes , but at least they have finally step up or say they are going to step up to the plate and finally play ball.
As for all those who seem to be a little barkin...

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-01-28
Anonymous
I find it interesting that many (usually those who don't have an opinion, unless M$ told them what their opinion was) seem to want to claim that microsoft is pumping out miracle software 'that does everything, and woks with everything' as an excuse for the problems microsoft has. This is the basis ...

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-02-02
Anonymous
Just becuase an OS will have exploits does not mean that they are are the same level of insecurity. Linux has had plently of buffer overruns, yet most of the dangerous ones involve sitting on the console to actually take advantage of them.

Like if you take a look at MS products they leave gaping...

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-01-24
Anonymous
I'd think that if M$ could convince Bruce to do the job AND give him the authority to do it properly it would be of enormous benefit to everyone.

The question would remain though whether Bruce would risk having his credibility destroyed by being percieved to have 'sold his soul' - and lets face i...

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-01-24
Anonymous
Recommending Bruce Schneier to lead the Trusted Computing group is idealistic and incredibly myopic. First off, Bruce has not exhibited the ability to serve as a manager or leader beyond putting his name behind a company run by others, as a "visionary" author, and countless bite-size media blurbs i...

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-01-24
Anonymous
Hmm...

Remember that story "The boy who cried wolf"

Action speaks louder than words. The proof will be in the pudding!

Until then......

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-01-25
Anonymous
Screw Microsoft. They've been stealing technology for 20 years and still haven't gotten it right. Hopefully they fail horribly, freeing the now fettered software markets from "standards" designed only to enforce the Microsoft monopoly....

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-01-25
Anonymous
"But when Larry Ellison embarks on a blatant PR campaign of misinformation, people say he is raising the bar for security."

Who said that? Oracle's PR department? Buddy, you've gotta start listening to more credible sources. The only commentary I've seen regarding the Ellison's silly "unbreakab...

[ more ]  [ reply ]
Alarming News! Truely Alarming 2002-01-27
trowe (1 replies)
"...Howard Schmidt ... prepares for his new role as the number two man at the United States' Critical Infrastructure Protection Board,"

I hadn't heard this. This is scary news. The man who presided over security at one of the worst (if not *the* worst) software companies as regards security is n...

[ more ]  [ reply ]
Alarming News! Truely Alarming 2002-02-05
GCrumrine (1 replies)
I am not usually one to jump in the middle of these things, but I must set the record straight on this one. First I must ask the writer who remains anon if he has actually met or worked with Mr. Schmidt? I have I am lucky to say. I worked with him prior to his Microsoft days, found him immensly i...

[ more ]  [ reply ]
Alarming News! Truely Alarming 2002-02-06
Scott (1 replies)
I second that, Howard is highly respected throughout the security community. His integrity and skills are well known not just in the US but throughout many countries of the world. It is always disappointing when ignorant people make slurs on others without the slightest bit of knowledge of who they ...

[ more ]  [ reply ]
Alarming News! Truely Alarming 2002-02-07
Anonymous (2 replies)
> It is always disappointing when ignorant people make slurs on others without the slightest bit of knowledge of > who they are condemning. .

I'll give you the benefit of the doubt and trust you are using "ignorant" in it's real meaning ;-)
Yes, I plead ingnorance of knowing the man. I was basi...

[ more ]  [ reply ]
Microsoft interested in Security ~ I dont think so. 2002-02-08
Anonymous
That's the biggest line of shit I've ever read, you an idiot!!! Microslop products suck; they use their customers as bata testers on all of their products and never finish a product before cramming in our face with guatanteed incompatibilities. Security is not their interest, money and keeping t...

[ more ]  [ reply ]
Who knows this quote? 2002-02-12
trowe
After the name calling and vehement attacks on the opinion I expressed, I went and read some interviews with Howard Schmidt. I have to say, while he seemed thoughtful, many of his positions are what I expect from Miscrosoft. I was also dissapointed to read of his involvment in the USA Patriot Act, ...

[ more ]  [ reply ]
Pity that didn't work out. 2002-02-05
Anonymous
So much for the Bruce Schneier idea, looks like we got a lawyer with a
great background for DMCA prosecutions instead. I wasn't one of those
with high hopes for Microsoft's alleged plans to change their security
record, so I can't say I'm surprised. Still, someone with any IT background
at all...

[ more ]  [ reply ]
Microsoft's Critical New Hire 2002-02-05
B.Forestal
Can Microsoft really make their products secure? I doubt it, and if they can, it won't be any time soon. Having dealt directly with their security developers, I was amazed at their lack of knowledge and awareness of security. They don't have the security mindset, it's never been a priority for th...

[ more ]  [ reply ]
Microsoft's Staff can cope with this change 2002-02-06
Mike Walsh, Helsinki
Like many people I had this impression from Microsoft's public actions that their staff were arrogant monopolists. I thought that the reason that the MS people I had personal contact with were not like this was because they were Finns.

Then I went to the 2001 European MEC a couple of days before ...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus