Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Microsoft: Closed source is more secure
Kevin Poulsen, SecurityFocus 2001-04-12

Redmond's security response chief warns the RSA Conference of the perils of open source.

Comments Mode:
Security under MS products VS. Linux, *BSD 2001-04-12
giard.pascal (at) teccart.qc (dot) ca [email concealed]
Now I know 2001-04-12
Anonymous
Crock of sh*t... 2001-04-12
Jim Powers
wow, that's a lot of spin 2001-04-13
wiggum
OpenBSD 2001-04-13
Carl Thomas
MS - Lipner Comments 2001-04-13
Nilanjan Chaks
opensource less secure? 2001-04-13
osiris
Microsoft should get a clue. 2001-04-13
Reaperx1
He's low on credibility 2001-04-13
Ajay Shah
Wha?? 2001-04-13
bleezer (at) plz (dot) com [email concealed]
FUD 2001-04-13
x3co
Closed source more secure? Really? 2001-04-13
counter_counterinsurgency (at) nospam.hotmail (dot) com [email concealed]
Is Microsoft code more secure than open alternatives? 2001-04-13
Larry Fahnoe <fahnoe (at) FahnoeTech (dot) com [email concealed]>
Open Souce security 2001-04-13
Charles E. Hill
Microsoft: Closed source is more secure FSVO secure 2001-04-13
Shmuel (Seymour J.) Metz <shmuel (at) acm (dot) org [email concealed]> (2 replies)
Closed source burdened by "boring, expensive" QA 2001-04-16
counter_counterinsurgency (at) nospam.hotmail (dot) com [email concealed]
When a product is already behind schedule and shipping late, I can just imagine how much pressure there is for security and QA to "accelerate" the review process. Somewhere, the bugs and vulnerabilities are probably ranked and prioritized (sorted by their cost-to-fix vs. the cost-to-M$-if-we-let-it-slide). Considering what we already KNOW has escaped the scrutiny of their security/QA review process, I wonder how much of this is truly undetected as opposed to problems they knew about and chose to ignore. It's the same result either way. Somewhere along the line, I think someone at M$ figured out that any number of patches could be released without spending any more than doing it right the first time. At first glance, this seems silly, but products that are held up in review are not generating revenue. At least open source is somewhat exempt from the profitability pressure to get the product out the door. IMHO, the need to minimize the cost/delay of the review process negates any advantage the closed source method could have had. Opinion: Traditionally, M$ has used the customer base as beta testers. For a long time, it kept their costs low, but now the security issue is getting out of hand. Another interesting point in the M$ argument is the reason why patches are delayed (because they are being tested.) Some of the security problems are so severe, even a "rough" patch might be better than nothing. Where was this rigorous testing when the products were being developed initially? One last point: At any closed-source vendor, who do you think is on the career fast track? It it the annoying QA person who detects a huge design flaw, or the project manager who kept "Widgets 2000" on schedule and pioneered interesting features that promise to keep the "Widgets" installed base on the upgrade trail? Would YOU want to work in a "boring" job, that was perceived by your employer as an "expensive" cost center? The prosecution rests.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/191/5296#5296
Microsoft: Closed source is more secure FSVO secure 2001-04-17
bassethound2 (at) yahoo (dot) com [email concealed]
Going through the motions != Security 2001-04-13
topeka (at) catchen (dot) org [email concealed]
Closed source software is secure 2001-04-13
soumyac (at) bigfoot (dot) com [email concealed]
An observation 2001-04-13
Harry G
Which explains why... 2001-04-13
Con Zymaris, CEO Cybersource Pty. Ltd. Australia
nobody buys ms argument 2001-04-16
j lock <jlock (at) compooter (dot) net [email concealed]>
Open vs. closed not necessarily it.... 2001-04-16
abostaph (at) usa (dot) net [email concealed] (1 replies)
Open vs. closed not necessarily it.... 2001-04-16
Microsoft Defender (2 replies)
Open vs. closed not necessarily it.... 2001-04-18
abostaph (at) usa (dot) net [email concealed] (1 replies)
I hope Mr Lipner reads this 2001-04-17
dirge
Security Vulnerability Open Source vs Closed Source 2001-04-17
Rod <snaketails (at) optushome.com (dot) au [email concealed]>
who gets cracked more? 2001-04-18
TauRine (1 replies)
who gets cracked more? 2001-04-18
M$ Defender (3 replies)
who gets cracked more? 2001-04-18
brian (1 replies)
who gets cracked more? 2001-04-18
M$ Defender
who gets cracked more? 2001-04-18
dirge
who gets cracked more? 2001-04-19
Bruce Garlock
His arguments contradict each other! 2001-04-19
nobody important







 

Privacy Statement
Copyright 2009, SecurityFocus