“I would never blame Microsoft” VC says about security

Analysis
Jun 15, 20071 min

Here is an interesting comment from part of a longer article. Security-guy-turned-venture-capitalist, Ted Schlein,  argues that network-based security doesn’t cut it anymore . Schlein has been investing in security companies for the last decade as a money man with Kleiner Perkins Caufield & Byers. Prior to that he was known for helping Symantec create its original antivirus software. 

When answering a question on how Microsoft is doing with security, Schlein says:

“Most of the code and applications in the world are not written by Microsoft, so I would never blame Microsoft. They’re doing their part to curtail as much as they can the various exploits. I applaud them for trying different things. But they are not a security company. Security to them is a cost center and not a profit center, so it is difficult for them to focus on it.”

This goes contrary to the general opinion that Microsoft wouldn’t have so much trouble if it built more secure code in the first place.

How much responsibility does Microsoft have in securing its products and are they doing a good job?