Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Security Holes That Run Deep
Mark Burnett, 2004-12-20

How a seemingly simply Microsoft bug betrayed its author's disdain for a wide range of secure coding principles.

Comments Mode:
Security Holes That Run Deep 2004-12-20
Anonymous (2 replies)
Security Holes That Run Deep 2004-12-22
michaels (1 replies)
Security Holes That Run Deep 2004-12-23
Anonymous
Security Holes That Run Deep 2004-12-26
Anonymous
Nothing new from MS here... 2004-12-21
Anonymous
Security Holes That Run Deep 2004-12-21
bazzargh
Failing Open vs. Closed 2004-12-22
Andy S.
Security Holes That Run Deep 2004-12-23
Anonymous
The bigger issue is Microsoft's overall posture when it comes to security.
While I know the majority of the software engineers at Microsoft are very dedicated to producing secure and stable code, Microsoft's overall corp stance has left alot to be desired.
Microsoft's business plan has always been pretty reactionary in nature.
Back when Microsoft started selling retail versions of DOS, Microsoft would wait for 3rd party developers to produce great OS utilities, then they would copy the idea
and incorparate this into the next release
of DOS. While many will say this was a good thing for consumers, I feel Microsoft should have been spending R&D money developing these concepts on thier own, not letting some 3rd party developer do the r&d, take the idea, and run the 3rd party company out of business.
When the Internet broke into the public consciousness, Microsoft only jumped on the bandwagon after it saw others making money, and released competing products.
Once again not developing new concepts.
Now we come to security, and Microsoft is only taking it serously now that they see they can make money with it
( http://www.securityfocus.com/news/10146 )

Looking back the last couple of years, of all the Microsoft products released, how many did NOT experience some form of a VERY SERIOUS vulnerability?

Microsoft has recieved a free ride both legaly and in the general press when it comes to accountability for it's security issues.

I fully understand Microsoft (like any properly run company) is in business to make money and fully support this.
What I'm saying is security should not be an optional upgrade to it's software.


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/285/29663#29663
Security Holes That Run Deep 2004-12-29
Anonymous-Philippines (1 replies)
Re: Security Holes That Run Deep 2009-06-10
Anonymous - US







 

Privacy Statement
Copyright 2009, SecurityFocus