Re: Time-to-patch vs Disclosure method

From: Blue Boar (BlueBoar@thievco.com)
Date: 10/18/01


Date: Thu, 18 Oct 2001 13:31:46 -0700
From: Blue Boar <BlueBoar@thievco.com>
Subject: Re: Time-to-patch vs Disclosure method
To: vuln-dev@securityfocus.com
Message-id: <3BCF3C32.E0A19FEE@thievco.com>

A few things to keep in mind about Scott's essay:

In a large company like Microsoft, there are many competing interests.
Scott likely has no where near the influence on product security that
he would like. I've been a corporate security guy for a large
software company (not Microsoft.) I had reasonable influence over
the IT infrastructure's security, and absolutely 0 over the product
security. The two just weren't related. My understanding is that
Scott has some degree of both, but that he has much more control over
things like responding to reports, driving patches, helping
with services packs, etc... and probably a little over actual
product development. I know several of the guys in various
Microsoft security groups, and they actually want to improve
the product, and they actually know what they are doing. Having
said that, they get to say very little about how to improve the
development process, unless security becomes Microsoft's #1
marketing item. Yes, this is akin to closing the barn door
several years after the horses have run away. Microsoft clearly
cares more now about security after the worms, but think about
what this means for product development. XP is done and out the door.
The next whatever is halfway done. If security takes new development
rules for development, we're looking at Windows 2005 before they
show up.

I'm not apologizing for Microsoft. I'm simply trying to point out
that there is a way that Scott could be sincere, and Microsoft
could act they way they do, and both can appear in the same
company.

And of course, given the list I run, my opinion is that Scott's
opinion is misguided. But then I'm not willing to be the guy
who has to answer for Microsoft's shortcomings, either.

                                BB



Relevant Pages

  • [NT] Cumulative Security Update for Internet Explorer (MS04-025)
    ... Get your security news from a reliable source. ... * Microsoft Windows NT Workstation 4.0 Service Pack 6a ... Navigation Method Cross-Domain Vulnerability ...
    (Securiteam)
  • SecurityFocus Microsoft Newsletter #75
    ... Microsoft's Internet Security & Acceleration Server with fault-tolerance ... The Microsoft UPnP Vulnerability ... Relevant URL: ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #120
    ... Strengthening Network Security: FREE Guide Network security is a ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows File Protection Signed File Replacement... ... PlatinumFTPServer Information Disclosure Vulnerability ...
    (Focus-Microsoft)
  • Re: A 6% fix from Microsoft Security Bulletin MS03-040 - 828750
    ... Now if the geeks over at Microsoft could get "infected" with some of this ... The Internet is already mind blowing in the way it can bring people ... that creates an unacceptable risk of security compromise and we need to shut ... down all Internet browsing with IE. ...
    (microsoft.public.security.virus)
  • Re: A 6% fix from Microsoft Security Bulletin MS03-040 - 828750
    ... Now if the geeks over at Microsoft could get "infected" with some of this ... The Internet is already mind blowing in the way it can bring people ... that creates an unacceptable risk of security compromise and we need to shut ... down all Internet browsing with IE. ...
    (microsoft.public.win2000.security)