Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Results, Not Resolutions
Bruce Schneier and Adam Shostack , SecurityFocus 2002-01-24

A guide to judging Microsoft's security progress.

Comments Mode:
Results, not Resolutions 2002-01-24
Anonymous
Results, not Resolutions 2002-01-24
Gary McGraw
Results, Not Resolutions 2002-01-24
David Litchfield (2 replies)
Results, Not Resolutions 2002-01-24
davep (at) pitt (dot) edu [email concealed] (1 replies)
Results, Not Resolutions 2002-01-25
Nicholas Harring
You mention that text files work for UNIX. And so they do, being a devoted Linux user I fully agree. However, I cannot imagine a corporate IT department attempting to support an enterprise wide deployment of Windows and having to tweak config.sys files.

Without getting into the trite, tired argument of why *NIX hasn't taken off, I just remind you that despite the technical superiority of many design decisions, it has failed to. It has failed to when available free of charge while Windows products (when purchased separately) averaged almost $200 US dollars for a single machine.

There must be a compromise between features being disabled by default and everything enabled out of the box. Providing an installation system which allows more than a series of clicks on the next button would be a great start. Extending the WMC to include more control, finer grain, and better documentation of both functionality and consequences would be excellent.

As the original piece states, security is not cheap, easy, or a single product. Security is a mindset, a process, and non-stop. MS has the resources to make security a cornerstone of their product line, however it is going to take time and dedication. They have products which are secureable, they have management tools which would allow IT departments to design their own security policy, and enforce effectively, if those tools are extended in reasonable, intelligent fashions.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/315/10105#10105
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-24
Anonymous (1 replies)
Results, Not Resolutions 2002-01-24
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Well, to conclude: Use Java, M$ 2002-01-25
Anonymous (1 replies)
Well, to conclude: Use Java, M$ 2002-01-25
Trithemius (1 replies)
Well, to conclude: Use Java, M$ 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
BMaximus
SOAP Recommendation is Silly 2002-01-25
Anonymous (1 replies)
SOAP Rec is correct 2002-01-26
Anonymous
Almost right on the compensation 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Anonymous
Results, Not Resolutions 2002-01-25
Chris
Regarding macros in documents... 2002-01-25
Anonymous
Things getting out of hand here? 2002-01-26
Toni Heinonen
Microkernel smog 2002-01-27
Grumpf
Inaccuracies and crazy talk 2002-01-28
Anonymous
Results, Not Resolutions 2002-01-28
Anonymous







 

Privacy Statement
Copyright 2007, SecurityFocus