Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Suing Over Slammer
Mark Rasch, 2003-02-10

The Slammer worm was successful because thousands of users didn't patch Microsoft's security holes. Should we sue them all?

Comments Mode:
Suing Over Slammer 2003-02-10
Anonymous
Liability and Buffer Overflows... 2003-02-10
Nicholas Weaver
Suing Over Slammer 2003-02-11
Anonymous (1 replies)
Suing Over Slammer 2003-02-11
Villy
Suing Over Slammer 2003-02-11
keydet89@yahoo.com
Is Microsoft legally responsible 2003-02-11
Sick and tired of the excuses (5 replies)
"Sure, the SQL server shouldn't have been vulnerable -- but with hundreds of products comprising billions of lines of code, should Microsoft be required to discover and prevent every single vulnerability before releasing the product?"

The pure and simple answer is YES!

Using your automobile analogy, automakers are responsible for every little bolt and screw in the vehicle, and they don?t even make them. Yet it is their responsibility to test them and make sure they will do there job without failing. Software companies should be held as responsible for the code they write. People?s lives are in as much danger with bad code as they are with bad screws.

It doesn?t matter how many billions of lines of code or even if it were trillions of lines. It isn?t developed that way. It is developed one procedure at a time and it is not hard to test a single procedure for buffer overflows. No what is happening is laziness and negligence. As well as worrying too much about the bottom dollar and not at all about what quality of product they sell.

Enough said.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/141/18091#18091
Is Microsoft legally responsible 2003-02-11
Villy.Madsen@atcoitek.com (1 replies)
Is Microsoft legally responsible 2003-02-12
RobJ (1 replies)
Is Microsoft legally responsible 2003-02-12
Sick and tired of the excuses (1 replies)
Is Microsoft legally responsible 2003-02-19
Anonymous
Is Microsoft legally responsible 2003-02-14
Anonymous
Is Microsoft legally responsible 2003-02-14
Anonymous
Is Microsoft legally responsible 2003-02-18
Anonymous
Fraudulent claims of loss 2003-02-11
Fra. 219







 

Privacy Statement
Copyright 2009, SecurityFocus