, 2003-10-13
The proposed cure for the Internet's security woes might help Microsoft competitors, but it would only make our security problems worse.
Expand all |
Post comment
Yet another bad article from our resident MS apologist
2003-10-13
Hay guys I'm lolling on THE INTERNET! (6 replies)
Hay guys I'm lolling on THE INTERNET! (6 replies)
Yet another bad article from our resident MS apologist
2003-10-14
Anonymous (1 replies)
Anonymous (1 replies)
Yet another bad article from our resident MS apologist
2003-10-15
Anonymous (4 replies)
Anonymous (4 replies)
CCIA Report is Bad Medicine
2003-10-13
Anonymous (2 replies)
Anonymous (2 replies)
CCIA Report is Bad Medicine
2003-10-13
Anonymous (2 replies)
Anonymous (2 replies)
CCIA Report is Bad Medicine
2003-10-14
Anonymous (1 replies)
Anonymous (1 replies)
CCIA Report is Bad Medicine
2003-10-14
Anonymous (2 replies)
Anonymous (2 replies)
CCIA Report is Bad Medicine
2003-10-14
Anonymous (1 replies)
Anonymous (1 replies)
IPSec != Firewall
2003-10-14
Anonymous (3 replies)
Anonymous (3 replies)
Conveniently glossed right over the whole point
2003-10-15
A no no miss (2 replies)
A no no miss (2 replies)
Conveniently glossed right over the whole point
2003-10-15
Anonymous (1 replies)
Anonymous (1 replies)

The mere fact that a malware author needs to write for one poor api set creates a cascading effect which the authors of the CCIA Report warn of.
I aggree that there are draconian "fixes" included in this report. However, overall, they are right on the mark on the dangers of monoculture enviroments. Look, M$ can't get their latest patches right. There still is DoS in RCPDCOM, IE is broke beyond repair, GDI will always be exploitable (read Chris Paget's work on Shatter attacks 1,2,or 3), And untill the Win32 api is rewritten, we are going to see buffer explot after buffer exploit.Even much touted TPA is flawed to exploits. Xbox? Windows 2003? M$ has a long way to go to be soley depended on in a secure fashion, unless you unplug it from the Internet (secure by design).
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/190/23097#23097