Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
CCIA Report is Bad Medicine
Tim Mullen, 2003-10-13

The proposed cure for the Internet's security woes might help Microsoft competitors, but it would only make our security problems worse.

Comments Mode:
Maybe it's intended as a threat? 2003-10-13
Anonymous
One part spot on, ocmplexity... 2003-10-13
Nicholas Weaver
CCIA Report is Bad Medicine 2003-10-13
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous (2 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous
What free market? 2003-10-14
Anonymous (1 replies)
What free market? 2003-10-15
Anonymous
THANK YOU 2003-10-13
KGW (2 replies)
THANK YOU 2003-10-15
Ben
THANK YOU 2003-10-16
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous (2 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-21
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous
CCIA Report is Bad Medicine 2003-10-13
Anonymous (2 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-16
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-16
Anonymous
CCIA Report is Bad Medicine 2003-10-15
Anonymous
What is author's suggestion? 2003-10-14
Anonymous (1 replies)
What is author's suggestion? 2003-10-14
Anonymous
Jim Allchin's testimony to congress holds up CCIA conclsions 2003-10-14
ark0n
One just has to look back at Jim Allchin's (VP of Winows OS division) testimony in which he states that if M$ where to open even some of Windows OS source code, it would be a danger to National Security. Even in the book "Hack Proffing Your Network" whose authors often are found in Security Focus, there are very strong warnings of Monoculturism.
The mere fact that a malware author needs to write for one poor api set creates a cascading effect which the authors of the CCIA Report warn of.
I aggree that there are draconian "fixes" included in this report. However, overall, they are right on the mark on the dangers of monoculture enviroments. Look, M$ can't get their latest patches right. There still is DoS in RCPDCOM, IE is broke beyond repair, GDI will always be exploitable (read Chris Paget's work on Shatter attacks 1,2,or 3), And untill the Win32 api is rewritten, we are going to see buffer explot after buffer exploit.Even much touted TPA is flawed to exploits. Xbox? Windows 2003? M$ has a long way to go to be soley depended on in a secure fashion, unless you unplug it from the Internet (secure by design).

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/190/23097#23097
CCIA Report is Bad Medicine 2003-10-14
Anonymous (2 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous (1 replies)
IPSec != Firewall 2003-10-14
Anonymous (3 replies)
IPSec != Firewall 2003-10-15
Anonymous
IPSec != Firewall 2003-10-15
Anonymous
IPSec ~= Firewall 2003-10-15
Did my research (2 replies)
IPSec ~= Firewall 2003-10-20
Anonymous
IPSec vs. IPChains 2003-10-14
Anonymous (2 replies)
IPSec vs. IPChains 2003-10-15
Anonymous
IPSec vs. IPChains 2003-10-15
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Chris Caydes (1 replies)
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Anonymous
CCIA Report is Bad Medicine 2003-10-14
Matthew Murphy (1 replies)
CCIA Report is Bad Medicine 2003-10-15
Anonymous
CCIA Report is Bad Medicine 2003-10-15
blacklight
CCIA Report is Bad Medicine 2003-10-15
Anonymous (1 replies)
CCIA Report is Bad Medicine 2003-10-15
Anonymous
Mellen doesn't get it 2003-10-15
Anonymous (1 replies)
Mellen doesn't get it 2003-10-15
Anonymous (1 replies)
Mellen doesn't get it 2003-10-17
Anonymous
CCIA Report is Bad Medicine 2003-10-15
DBrown
Actually, Tim... 2003-10-15
Penguinisto (1 replies)
Actually, Tim... 2003-10-16
blacklight
Attachments? 2003-10-15
Anonymous
Conveniently glossed right over the whole point 2003-10-15
A no no miss (2 replies)
Conveniently glossed right over the whole point 2003-10-15
Anonymous (1 replies)
That's all well and good 2003-10-17
Anonymous (1 replies)
That's all well and good 2003-10-20
Anonymous
CCIA Report is Bad Medicine 2003-10-15
Richard Rager
Not about economics 2003-10-15
Anonymous (1 replies)
Not about economics 2003-10-15
Anonymous
CCIA Report is Bad Medicine 2003-10-15
Anonymous
Not bad medicine, just bad.... 2003-10-16
Anonymous
CCIA Report is Bad Medicine 2003-10-17
Outraged
CCIA Report is Bad Medicine 2003-10-17
Anonymous
CCIA Report is Bad Medicine 2003-10-17
Paul Kosinski (1 replies)
CCIA Report is Bad Medicine 2003-10-21
Anonymous
Tim Mullin is Bad Journalism 2003-10-18
SNMPGuru (1 replies)
Tim Mullin is Bad Journalism-Why? 2003-10-21
Anonymous
Attacks: 2003-10-22
Anonymous
CCIA Report is Bad Medicine 2003-10-23
Anonymous
Reader Comments 2003-10-23
R. Lambert
CCIA Report is Bad Medicine 2003-10-24
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus