, 2003-04-27
With Windows Server 2003, Microsoft has finally produced an operating system that isn't begging to be hacked on the first boot.
Expand all |
Post comment
Secure by Default - READ BEFORE YOU POST.
2003-04-28
Anonymous (2 replies)
Anonymous (2 replies)
Secure by Default - READ BEFORE YOU POST.
2003-04-28
Anonymous (1 replies)
Anonymous (1 replies)
Secure by Default - READ BEFORE YOU POST.
2003-04-29
Anonymous (2 replies)
Anonymous (2 replies)
Secure by Default - READ BEFORE YOU POST.
2003-04-30
Anonymous (2 replies)
Anonymous (2 replies)
Secure by Default - READ BEFORE YOU POST.
2003-05-01
Anonymous (3 replies)
Anonymous (3 replies)
Secure by Default - READ BEFORE YOU POST.
2003-05-02
Penguinisto (1 replies)
Penguinisto (1 replies)
Secure by Default, Insecure by Birth
2003-04-28
Drek Software Inc. (2 replies)
Drek Software Inc. (2 replies)
Well, I'll give you this much, Timster...
2003-04-28
Penguinisto (4 replies)
Penguinisto (4 replies)
Well, I'll give you this much, Timster...
2003-04-28
Anonymous (6 replies)
Anonymous (6 replies)
Well, I'll give you this much, Timster...
2003-04-29
Anonymous (2 replies)
Anonymous (2 replies)
Well, I'll give you this much, Timster...
2003-04-29
Penguinisto (1 replies)
Penguinisto (1 replies)
Well, I'll give you this much, Timster...
2003-04-29
Anonymous (2 replies)
Anonymous (2 replies)
Zealotry comes in all forms.
2003-04-29
matt@beatlab.org (2 replies)
matt@beatlab.org (2 replies)
Secure by Default (Pathetic)
2003-04-29
Anonymous (3 replies)
Anonymous (3 replies)
Secure by Default
2003-04-29
Anonymous (1 replies)
Anonymous (1 replies)

I will point out that our cracker friends have not yet put Windows 2003 through its paces yet. It can be claimed that Windows 2003 is secure if Windows 2003 meets the following conditions, which include but are not limited to: (1) our cracker friends can't successfully attack through those services that are turned on; (2) Windows 2003 patches do not open or reopen new security holes, even as they may close some existing ones; (3) Microsoft has a policy of admitting to potential vulnerabilities in a swift, thorough and explicit ways - again, there are ways of eliminating or mitigating security holes until patches become available. The worst policy from every standpoint is a refusal to admit to any shortcomings for the sake of "stability" and "public order", as for example the PRC did until recently with SARS. The PRC's original refusal to be forthright and open about SARS not only turned it from a controllable outbreak into an epidemic, but into an international PR disaster abroad as well as a huge political liability at home - not to mention the economic impact at home and abroad.
The phrase "Microsoft professionals" makes me wince: I haven't done a ton of Microsoft installations, but I have done a ton of cleaning up after the "setup.exe" and "winnt32.exe" MCSE geniuses who did those installations. I do accept that there are a few genuine Microsoft security professionals out there, but in general the phrase "Microsoft security professional" is apparently the latest marketing-oriented oxymoron.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/157/19632#19632