Microsoft security: Your thoughts, Part 2

Opinion
Oct 15, 20033 mins

* Why some readers don't trust Microsoft 'security'

Last time out I reviewed the positive feedback I received about last week’s newsletter commending Microsoft for finally taking security seriously. That was only half of the responses I received, though. The rest – to one degree or another – said that Microsoft deserved only scorn (or worse). Here’s a sampling of the arguments that were used.

A frequent theme of the responses was: “To say that Microsoft should be commended for its new found religion is patently absurd!” But religion does provide a good analogy. The Judeo-Christian tradition teaches us to “love the sinner, hate the sin.” The important thing is not what the sinner had done before but that the sinner now repents and begins to lead a righteous life.

Another analogy could be the various “12 steps” programs (as used by Alcoholics Anonymous and other “Anonymous” organizations).  Just think of Bill Gates as the newest member of “Security Holes Anonymous” (“My name is Bill and my Software is full of buffer overruns.” “Hi Bill!”)

The oddest argument, to me, was put forth by a number of people who said – essentially – Microsoft’s track record on security is so bad that they would never use a Microsoft firewall to protect their network. What this means, if you follow it to its ultimate conclusion, is that Microsoft shouldn’t even bother trying to secure its operating systems and applications because users won’t believe them to be secure and won’t use any security-specific services the vendor provides. This, of course, guarantees that the software will never be secure and becomes a self-fulfilling prophecy.

I’m not asking anyone to blindly trust Microsoft, I’m not even asking that people forego other security solutions they feel safer installing. All I’m asking is that we get together and encourage Microsoft to continue to consider security as at least as high a priority as ease of use when developing applications, services and operating systems.

Folks on both sides of the argument suggested longer testing times before new versions of software were released, and that’s something everyone (except the marketing department) would like to see. But in order to be practical and to keep costs to a reasonable level, testing cycles will probably shrink rather than grow. More automation and better simulation will help, but the new approach, the “sandbox” or “firewall” should do more to protect all networks than even doubling or tripling the beta test time.

And speaking of time, only time will tell how effective this new initiative will be. I think we all hope it will be very successful and I know you’ll tell me how you feel about it as events unfold.