Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Results, Not Resolutions
Bruce Schneier and Adam Shostack , SecurityFocus 2002-01-24

A guide to judging Microsoft's security progress.

Comments Mode:
Results, not Resolutions 2002-01-24
Anonymous
Results, not Resolutions 2002-01-24
Gary McGraw
Results, Not Resolutions 2002-01-24
David Litchfield (2 replies)
Results, Not Resolutions 2002-01-24
davep (at) pitt (dot) edu [email concealed] (1 replies)


> Would you rather people used notepad to edit text files?

Yes...and why not? It works for Unix...I know I would rather edit some simple, keep-the-changes-I-made text files than have the "mystery settings" that keep coming back even after I change some settings! In addition, you can have finer-grained access control using the filesystem's permissions, rather than some black-box (for me anyway...perhaps you have some extra goodies) single-point-of-failure database of settings.

Regarding the ship enabled/disabled argument, it seems simple enough to at least give you the choice (and perhaps a little explanation of the ramifications of the decision) to install and/or enable a package when you install/upgrade software (lets not forget the issue of silently "re-enabling" software during patches and upgrades!)

I can only imagine what must have driven this fundamental change...falling profits due to Open Source competition and bad publicity? Fear of a massive faulty-product class-action lawsuit? (even tho' the E.U.A. basically signs away your consumer rights, this may change with the help of some states Attorney Generals)

As far as these changes being impossible, they most certainly are not. Open Source organizations are able to do much of this with volunteer time, so a multi-billion dollar company can do this. Are they improbable given the culture and past behaviour? Absolutely, and that's probably why this article was called Results, not Resolutions!

Dave P

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/315/10100#10100
Results, Not Resolutions 2002-01-25
Nicholas Harring
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-24
Anonymous (1 replies)
Results, Not Resolutions 2002-01-24
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Well, to conclude: Use Java, M$ 2002-01-25
Anonymous (1 replies)
Well, to conclude: Use Java, M$ 2002-01-25
Trithemius (1 replies)
Well, to conclude: Use Java, M$ 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
BMaximus
SOAP Recommendation is Silly 2002-01-25
Anonymous (1 replies)
SOAP Rec is correct 2002-01-26
Anonymous
Almost right on the compensation 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Chris
Regarding macros in documents... 2002-01-25
Anonymous
Things getting out of hand here? 2002-01-26
Toni Heinonen
Microkernel smog 2002-01-27
Grumpf
Inaccuracies and crazy talk 2002-01-28
Anonymous
Results, Not Resolutions 2002-01-28
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus