Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Does Microsoft Give a Damn?
George Smith, 2003-09-15

The software-maker's dismal security record seems to have left it immune to criticism and shame.

Comments Mode:
Does Microsoft Give a Damn? 2003-09-15
Anonymous (6 replies)
Does Microsoft Give a Damn? 2003-09-15
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-18
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-23
Anonymous
One problem w/ SUS: 2003-09-16
Penguinisto (1 replies)
One problem w/ SUS: 2003-09-18
Anonymous (1 replies)
One problem w/ SUS: 2003-09-19
penguinisto
Does Microsoft Give a Damn? 2003-09-16
Anonymous
Does Microsoft Give a Damn? 2003-09-17
Anonymous
Does Microsoft Give a Damn? 2003-09-17
Anonymous
Make that Two problems with SUS 2003-09-23
Anonymous
We Must Do Our Job 2003-09-15
Sean M. Lynch (2 replies)
I agree with the posts about MS Bashing. Every OS has its own issues. If Unix or Linux was so secure, why are there security patches for those OSs as well? We cannot rely JUST on the OS, AV, IDS, or anything else as our sole savior against malicious attacks...FOR ANY PLATFORM. The issue is defense in depth. People should not have been tripped up by Blaster. The vulnerability was exposed well before the onset of the worm and critical system appropriately patched. There should be sufficient compensating controls in place to ensure that the exploitation of a single vulnerability does not expose the entire organization.

Some may say, it cannot be done. I say it can and have been doing such for a few years now. Blaster, Goner, Sobig, Klez have all been trapped by the multiple levels of impact on the organization I support because I do not trust any single level of protection. Does it cost? Sure. But, management here has found that while other organizations are busy recoverying from various levels of compromise, we are spending out time reporting our overall security posture, potental areas where there could be a compromise, recommendations to improve protection before any compromise, and monitoring the rates of identification and detection through our various protection mechanisms. We have not had to recover a single system because there has been no compromise.

I am not so arrogant to believe that we will never have an infection. But we have our controls set up such that we believe we can mitigate any enterprise outage. The investment of time has been worth it. We have not had to spend long hours cleaning our network from the last infestation, nor did we spend excruciating hours scrambling with the recent revelation either.

The best thing we can do is to remain vigilent, set levels of compensating controls, monitor, and patch as necessary...like we do with all the other OSs that we support and work with.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/185/22310#22310
Patch, reboot, patch, reboot.... 2003-09-16
Anonymous (1 replies)
Patch, reboot, patch, reboot.... 2003-09-17
Anonymous (2 replies)
Patch, reboot, patch, reboot.... 2003-09-18
Anonymous
Patch, reboot, patch, reboot.... 2003-09-18
Anonymous
We Must Do Our Job 2003-09-16
Anonymous (2 replies)
We Must Do Our Job 2003-09-17
Mark Kovacic
We Must Do Our Job 2003-09-17
Anonymous (1 replies)
Yes and no... 2003-09-18
Penguinisto
Useless rhetoric 2003-09-15
Anonymous (2 replies)
Useless rhetoric 2003-09-16
Anonymous (2 replies)
Useless rhetoric 2003-09-16
Anonymous
Useless rhetoric 2003-09-17
Anonymous
Useless rhetoric 2003-09-17
Anonymous (1 replies)
Useless rhetoric 2003-09-17
Anonymous (2 replies)
Useless rhetoric 2003-09-20
Anonymous
Useless rhetoric 2003-09-21
Anonymous
Does Microsoft Give a Damn? 2003-09-16
Anonymous
Does Microsoft Give a Damn? 2003-09-16
Gary K (1 replies)
Does Microsoft Give a Damn? 2003-09-16
Anonymous
Does Microsoft Give a Damn? It doesn't matter 2003-09-16
Anonymous - Jerk (1 replies)
Does Microsoft Give a Damn? 2003-09-17
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-17
Anonymous
We Must Do Our Job 2003-09-17
Sean M. Lynch
Does Microsoft Give a Damn? 2003-09-17
Anonymous
Does Microsoft Give a Damn? 2003-09-17
Anonymous
Does Microsoft Give a Damn? 2003-09-17
E(Ces)
Does Microsoft Give a Damn? 2003-09-18
Anonymous
Does Microsoft Give a Damn? 2003-09-18
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-20
Anonymous
Does Microsoft Give a Damn? 2003-09-18
Anonymoose
Does Microsoft Give a Damn? 2003-09-18
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-19
Anonymous
Of Course They Dont::Does Microsoft Give a Damn? 2003-09-18
Linux, Torvald. Mr. Linux Torvald to you. (1 replies)
Stop the whining, George! 2003-09-18
Anonymous (1 replies)
Stop the whining, George! 2003-09-20
Anonymous
Shut Up !!! 2003-09-18
Anonymous (1 replies)
Does Microsoft Give a Damn? 2003-09-19
Anonymous (1 replies)
Only two Suse patches?!? 2003-09-19
Anonymous (1 replies)
Only two Suse patches?!? 2003-09-21
Anonymous (1 replies)
Only two Suse patches?!? 2003-09-23
Anonymous
Does Microsoft Give a Damn? 2003-09-19
Anonymous
How Interesting 2003-09-20
Sigmund Einstein
Does Microsoft Give a Damn? 2003-09-20
haloflightleader at yahoo dot com
Does Microsoft Give a Damn? 2003-09-21
Anonymous
Does Microsoft Give a Damn? 2003-09-26
penfold
Shrill 2003-09-26
Anonymous
Should Microsoft Give a Damn? 2003-09-26
mr_jinx







 

Privacy Statement
Copyright 2008, SecurityFocus