Microsoft’s long road to security

News
Mar 8, 20047 mins

Company makes progress, but experts and users say it still has a long way to go.

Two years after Microsoft Chief Software Architect Bill Gates vowed the company was making security its top job, users and experts say progress has been measurable but that a lot more work has to be done.

“There is a long way to go to make it easier for administrators to keep their networks secure,” says Russ Cooper, moderator of the NTBugtraq mailing list and surgeon general for security company TruSecure.

Some say Windows must be simplified or transformed with a major code overhaul, that an alternative to pushing out patches might be needed and that automated patch management will have to show it’s secure before it can help improve security.

Some say Microsoft also must focus on shoring up older software such as Windows 2000, given that the next major release of the operating system, code-named Longhorn, isn’t expected to ship until 2006 or 2007.

And foremost, Microsoft, which is a collection of autonomous product groups, must learn to work as one company when solving security issues.

“They are now seeing that coordination across the entire company takes a lot of time,” says Michael Cherry, an analyst with Directions on Microsoft, an independent research firm. “Installing one product should not undo security of another product.”

Cherry says security is driving change because it hit Microsoft on the bottom line. “The money companies spend fixing these problems is money they can’t spend on new products.”

Critics and end users say Microsoft will make some progress in the coming months when it ships Service Pack 2 for Windows XP, which is designed to make the operating system more resilient by turning off some features by default and makes available a set of new patch management tools, including new installer and updating software.

Those improvements come in addition to those in Windows Server 2003, including additional security features to lock down key components such as Active Directory and Internet Information Server.

However, all these improvements, according to some, might be feeding the problem.

“They are layering on more complexity, not simplifying the code to make it more secure,” says Dan Blum, an analyst with Burton Group. It’s a philosophy Microsoft seems to have failed at when it introduced its first major security push in 1999 with its Secure Windows Initiative team. The goal was to provide education, tools, process and testing while not adding more security features. 

Security review

Microsoft said two years ago that security would be Job 1. Since then, progress has been made despite several notable vulnerabilities, but critics say more needs to be done.
2002

Jan. 15, 2002

Bill Gates outlines Trustworthy Computing initiative in e-mail to 50,000 Microsoft employees.

February 2002

Microsoft ceases work on new products while developers are trained in how to write secure code.

July 18, 2002

Gates sends Trustworthy Computing memo to customers.

July 24, 2002

Patch for SQL buffer overrun vulnerability released. Slammer worm

hits 184 days later.
2003

July 16, 2003

Patch for RPC buffer overrun released. Blaster worm hits 26 days later.

Oct. 9, 2003

In keynote at Partner Conference, CEO Steve Ballmer reiterates Trustworthy Computing initiative and that security is Job 1.

Oct. 23, 2003

CFO John Connors admits that sales over the past three months were weakened as corporate customers dealt with security issues related to Blaster.
2004

Feb. 10, 2004

Patch for ASN.1 vulnerability released. Some critics call it the worst vulnerability ever discovered in Microsoft’s software.

May 2004

Windows XP Service Pack 2 expected to ship. Includes new security controls, including many turned on by default.

May/June 2004

Microsoft expected to release new and updated patching tools.

“It’s simplicity vs. complexity, flexibility vs. security,” Blum says.

Others say even more drastic measures should be taken by rewriting core code even though it would break compatibility with most existing applications.

“The blind spot is the code base because it is apparent now that Microsoft met ship dates of earlier products by using some sloppy code,” says John Kretz, president of Enlightened Point Consulting Group, a systems integrator in Phoenix. “The vulnerabilities can’t be addressed with check boxes and default configurations. I would like them to fix the code instead of changing defaults.”

It’s a drastic measure that points to the problem Microsoft has had establishing credibility for Trustworthy Computing. Every time progress seems to be made, Microsoft gets shot in the foot.

Critical weaknesses

Gates sent customers his original Trustworthy Computing memo in 2002, less than a week before the patch was issued for the SQL Server vulnerability that the MS-SQL Slammer worm eventually exploited. CEO Steve Ballmer touted the gains of Trustworthy Computing to corporate partners just a week before seven new critical vulnerabilities were revealed. Just after the two-year anniversary of Trustworthy Computing, the ASN.1 vulnerability was made public and Microsoft acknowledged that it had taken more than 200 days to develop the patch for a hole some called the worst ever discovered.

And last month, more embarrassing incidents occurred, including a leak of source code and a fix issued outside of Microsoft’s new monthly patch cycle to correct a bug in Internet Explorer.

It’s a list that leaves users cautious.

“I can’t say if security has gotten any better,” says George Defenbaugh, manager of global IT infrastructure projects for petroleum company Amerada Hess. “Who knows what’s out there that has not been discovered.”

Despite the pockmarks, Microsoft points to progress.

Win 2003 needed six critical or important patches in the first 300 days after release, an 83% drop compared with the 36 critical or important patches issued in the first 300 days after the release of Win 2000.

Win 2003 was the first major product that Microsoft developed under its Trustworthy Computing Release Process, an internal process including security design reviews. Office 2003 and Exchange 2003 are some of the 20 products that have been subjected to the same reviews.

Customers: Tighten up now

“Our No. 1 request from customers is to ship more secure products,” says Jeff Jones, senior director of the security and technology business unit at Microsoft. “We think we are on track and doing well in terms of progress.”

Jones says success in the short term and long term will be based on writing more secure code, developing protective technologies such as personal firewalls to protect against the spread of malicious code and updating Microsoft’s patching technology. “We know we have a lot of work ahead of us,” he says.

The company has formed a number of alliances and awareness programs to enlist the help of partners, including the Virus Information Alliance and the Global Infrastructure Alliance for Internet Safety for service providers.

Software also is on tap. Before July, the company plans to ship its Software Update Services 2.0 and Microsoft Update, both tools for downloading patches, and the Internet Security and Acceleration Sever 2004. In the second half of the year, it will ship Service Pack 1 for Win 2003 and more patching tools. And down the road it plans a secure Simple Mail Transfer Protocol gateway, behavior-blocking technology and the Next Generation Secure Computing Base, a combination of hardware and software to lock down the operating system.

TruSecure’s Cooper says the upcoming XP service pack, which will turn on by default the personal firewall within the operating system, shows progress not just in technology but also in attitude.

“It’s a huge step forward turning something on that will break legacy functionality,” Cooper says. “That will create support calls, and it shows Microsoft acknowledges that the security risk is greater than the annoyance and cost of all those support calls.”