by John Obeto

Microsoft’s security improvements

Opinion
May 11, 20073 mins

Every day, and in comments re my blog post here, there is that bubbling-under-the-surface, wink-wink, nod-nod view that Microsoft is deficient when it comes to security.

From a security viewpoint, Microsoft’s primary problem has been that it, traditionally, has not been very proactive in anticipating threats.

If you look at computing from a product /threat perspective, then you would understand that Microsoft has been on the ball, however hobbled by 1) the omnipresence of the Windows operating systems, 2) the legacy needs of that very ubiquitous operating system family, and 3) antitrust consent decrees, especially those ridiculous EU verdicts.

Prior to the explosion of the internet, the threat was local, and Windows XP solved the problems of LAN security.

It was during the XP era that the Internet became the all-encompassing force it is today. The subsequent, IMO, undeserved reputation awarded Microsoft by members of the mainstream IT media for security porosity does not take that into consideration.

Indeed, the mainstream IT press should be severely admonished for hypocritical statements and articles.

They want a ‘secure’ Windows operating system, at the same time, they want unlimited down-level compatibility with applications written for earlier versions of Windows.

Just how this can be achieved, is never detailed.

Furthermore, Microsoft is also excoriated upon release of newer versions of its software for the cost of training/re-training, but when alternatives are mentioned, the cost of change is never mentioned.

For example, an IT glossy* a while back reviewed a Linux-based SoHo solution, and, incredibly, recommended it over Microsoft Windows Server 2003 SBS R2! Yes, they did.

I wrote the editor of that magazine asking what he was thinking, for not only recommending it over SBS, but also as a replacement for SBS without informing their readership of the costs involved, both in monetary costs, and in human/training costs. Several weeks later, no reply, no cost justification.

*My policy of not linking to articles I consider boneheaded and outright misleading to my constituency, the SMB space, disallows my mentioning the magazine here.

If you look at improvements Microsoft makes to each OS release from the previous, each one gets more secure. However, I feel Microsoft, some day, has to utilize some of the IP it has invented and purchased in order to break totally with the less secure earlier versions of Windows.

One thing you should note:

Windows Sever 2003 is the most robust OS out there today. In fact, there has not been a successful attack directed at Server 2003. Period.

And…..

Windows Vista is built on the foundation of Windows Server 2003!

Now go get Vista, OK?

Email me at john.obeto@absolutevista.com or reply here if you think I missed it.