Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


May 2003

Microsoft Needs to Get Serious About Security

The Band-Aid approach to security fixes is no way to treat enterprise customers
RSS
Subscribe to Windows IT Pro | See More Hotfixes Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

In spite of all its rhetoric and impressive-sounding initiatives, Microsoft doesn't really seem to get what enterprise security is all about. When I step back and look at Redmond's response to security concerns, I too often see that Microsoft seems to view security exposures more as a marketing tool than as a product defect.

Microsoft's much-ballyhooed Trustworthy Computing initiative and Palladium both fall into the security-by-marketing category. Neither initiative addresses the pressing needs of current customers. To receive the vital security benefits that these schemes promise, you must abandon products you've already invested in and come up with more money to spend on the next big thing down the road.

This security-by-marketing mindset doesn't sit well with customers, but Microsoft appears to be blind to the problem. Microsoft's all-too-common response to a defect in a product is, "We know about that, and we're fixing it in [fill in the follow-on product's name]." But as the ship date approaches and the new product inevitably falls behind schedule, many of the promised features drop off like leaves from trees in autumn.

Band-Aids Are Not Enough
As evidenced by the ongoing flood of hotfixes and security patches, Microsoft takes a Band-Aid approach to its security strategy for current customers. Although the company responds to known security exposures, its patch-and-fix solution results in a maintenance nightmare for systems administrators and adds to Sun Microsystems and other enterprise competitors' skepticism about Microsoft security. Patch management has become one of the toughest jobs of Windows systems administrators. Just to keep their heads above water, administrators who deal with the onslaught of security fixes for Windows and components such as Microsoft Outlook and Microsoft Internet Explorer (IE) must find time for daily maintenance and invest in third-party management and deployment tools.

To its credit, Microsoft took a step in the right direction in early 2002 by briefly stopping new development to concentrate on internal security training and code review. Unfortunately, the company cut short this effort. Instead of culminating in a set of comprehensive security fixes for all major enterprise products, the moratorium surrendered its aspirations to Trustworthy Computing and Palladium. From the customer's standpoint, this turn of events is another example of Microsoft saying that fixing current products isn't a worthwhile endeavor and that selling fixes as part of a future product is easier and more profitable. That attitude doesn't constitute trustworthy computing.

What Really Constitutes Trustworthy Computing
If Microsoft wants to enjoy the same respect in the enterprise arena that enterprise-centric competitors such as Sun, IBM, and Oracle do, Redmond must get serious about security. Having spent 9 years in a large IBM mainframe and midrange shop, I can attest that marketing important security fixes as a part of the next release is a foreign mindset to IBM. We expected better, and we got better.

If Microsoft wants to succeed in this market, it needs to stop trying to sell security as a feature of an upcoming product and instead take responsibility to fix its current products. Microsoft needs to do a real security analysis and update all its current enterprise product lines—even if doing so requires time, money, or a product redesign. Then, Microsoft needs to make the fixes freely available to current customers—not just to the customers of a future release.

Imagine being able to count on Microsoft to make good on its promises for the products that you've already purchased. Now, that's trustworthy computing!

End of Article



Reader Comments
Imagine if a few columnist wrote about the industry security issues equally and made people aware of other platforms having difficulties as well. That would require people to actually track other vulnerabilites and platforms which is what many Engineers do and columnists do not.

John April 23, 2003


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
CES 2009: Ballmer Announces Windows 7, Windows Live, Live Search Milestones

During his first-ever Consumer Electronics Show (CES) 2009 keynote address last night in Las Vegas, Microsoft CEO Steve Ballmer announced the pending public availability of a feature-complete Windows 7, the final version of Windows Live Essentials, and ...

Command Prompt Tricks

One reader shares his tip for setting up the command prompt to reflect a remote path. ...

Where is Microsoft NetMeeting in Windows XP?

...


Security Whitepapers The Impact of Messaging and Web Threats

Why SaaS is the Right Solution for Log Management

Protecting (You and) Your Data with Exchange Server 2007

Related Events Security Summit

Virtualization Forum: Optimizing Storage, Networks, Desktops, and Security

Cloud Computing Forum: Integrating Software, Server and Storage as a Service into Your Enterprise IT Delivery Model

Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technology Resource Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2009 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing