Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register
ENTERPRISE WINDOWS  

Microsoft sued over security? No surprises here

The latest lawsuit comes at a time when Redmond is finally taking security seriously -- or seems to be

By Oliver Rist
October 10, 2003
 

Oh, who am I kidding? I’m a columnist. To us, saying “I told you so” means validation akin to Dante Hall ’s 95-yard  touchdown punt return against Denver last weekend.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

So I get to revel a bit, and once again, I’m doing it at Redmond’s expense. I’ve said it here and in the pages of other publications: If Microsoft doesn’t clean up its security act, it risks becoming a prime lawsuit target. Lo and behold, last week, a class-action lawsuit was filed against Microsoft in California, alleging that the company’s insecure products have placed customers at an extended risk of security breaches with global repercussions due to the potential for “massive, cascading failures.”

Ironically, the lawyers finally get into the game at a time when Microsoft is paying more attention to security issues than ever before. Windows Server 2003, for example, represents several new Microsoft security initiatives and a host of related features.

Not to digress, but a systems administrator recently asked me to help out while he tested one of these new security features, namely Quarantine. This feature is intended to mirror the functionality of third-party VPN products that check client hardware or software for specific requirements before allowing log-in. So, for example, clients without Symantec’s AntiVirus software could be quarantined from the network, even if the user has an account and knows the correct passwords.

Microsoft built this functionality into its own VPN feature set, allowing a Windows Server 2003 machine running VPN services as well as the IAS (Internet Authentication Service) and RADIUS authentication to run a script on any remote client attempting access. This script can then perform a variety of queries looking for appropriate software or even specific files.  Depending on what this script discovers and reports back to the IAS server, one of several remote access policies can be enforced on the user — including permanent or temporary lockout from the network. Quarantine.

Windows Server 2003 has several similar features, many revolving around Active Directory and even more ways to use GPOs (group policy objects) to implement secure network policies than were available under Windows 2000. After we finished hashing out the Quarantine testing and gazing at new security documentation from Microsoft, my buddy asked me if I’d use Microsoft’s Quarantine feature over a third-party product such as one from Cisco Systems.

The answer to that, for now, is "no." Not because I don’t like the feature; I think Microsoft has responded admirably on the new security-features front. What worries most about Windows security has never been lack of features; it’s been a lack of proven, quality code. Even Redmond has spent nearly a decade cultivating a reputation for releasing sloppy code riddled with security holes. Hackers the world over have spent many hours giggling over glowing screens in the dead of night, repeatedly proving this very fact.

Having Microsoft throw new security features at me is partially reassuring, but how are we to know if these very same new features don’t contain yet more code-based security loopholes? Systems administrators, especially us consulting types, simply don’t have the clearance or resources to check code quality ourselves. To get us to trust our reputations to Microsoft-based security, Redmond needs to do more than add features. You boys and girls need to prove to everyone that your coding practices have improved. And you’d better do it fast or you’ll be joining some senior tobacco executives in weekly “I can’t believe we had to pay that much” support groups.





 


 
Oliver Rist is a senior contributing editor at InfoWorld.

  More of Oliver Rist's column
  Oliver Rist's Weblog

Newsletter Check out all of our free newsletters!
Enter e-mail address:




 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




FIVE WAYS TO REDUCE IT COSTS IN 2009
The demands on IT have never been greater, particularly in light of lower revenue and uncertain demand for the goods and services. There are many ways that IT can help organizations adjust to this new economic environment. Learn about five key technology trends that can immediately impact your organization's bottom line, and how to build a strategy to implement these technologies within your current budget. Sponsored by: Riverbed

»  Click here to view this Webcast
  Virtualization Solutions Guide
This comprehensive IT Strategy Guide covers Virtualization and puts you at the forefront of the discussion. You'll learn all you need to know from the cost of virtualization, how to implement it for your business, how to back it up safely and which products are best. Sponsored by Riverbed

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity