Re: Is Microsoft serious?



On Tue, 17 Jan 2006, in the Usenet newsgroup alt.computer.security, in article
<99d2e$43cdc1fb$45493f2f$7459@xxxxxxxxxxx>, Winged wrote:

>At least current versions of their server software comes shut down
>instead of everything left wide open, they have made progress on some
>fronts.

I find that to be startling.

>One issue I have found disturbing however is Microsoft engineers don't
>even understand portions of their own code. With so much of their code
>written overseas certain delicacies of the OS is not fully understood by
>their own engineers in the countries of origin. We ran across this
>writing active directory applications and noting certain values
>documented to do certain things that obtained values they could not
>explain. It was a confidence builder in there code yup, yup....

Bugtraq - two articles in the thread "Microsoft knew about the WMF flaw for
years" by "rms@xxxxxxxxxxxxxxxxxxxx ("Richard M. Smith")" and the response
from "ge@xxxxxxxxxxxx (Gadi Evron)" dated Tuesday. The later article (I
have no idea who Gadi is working for now - he was a conslutant to the
Central Bureau of Statistics, Israel [cbs.gov.il]) is speculation but
does sound convincing.

"I have heard"(tm) that this was due to staff turnover and documentation
problems. Certainly in older versions there were many reports of code in
the O/S that no one knew, no one "owned", yet was being used in
"undocumented" ways. I have never seen more than snippets of code in
college classes (and my C skills are for dire emergency use only), but can
understand how this would occur.

Old guy
.



Relevant Pages

  • Re: SwingWorker.execute() does nothing
    ... When dealing with the behavior of a Dialog, I would expect the rational user to be most likely to look in the documentation for the Dialog class. ... It is not an attitude that will help improve Java and its documentation, nor is it an attitude that will endear you to the people who ask questions here. ... Only the specific case that's especially likely to trip people up, which is where they pop up a progress dialog and then launch a SwingWorker to do a background task that will report progress. ...
    (comp.lang.java.programmer)
  • Re: GetFileSize Failed on Directory
    ... While copying it has to process the data so i cant simply use ... and use MFC Progress bar to indicate the progress ... CreateFile documentation says: ... Sloppy programming gives sloppy results, ...
    (microsoft.public.vc.language)
  • Re: Changing stream :element-type
    ... I'm looking at the 7.0 documentation as part of my Allegro ... >> the link above) is I/O progress. ... > My question here concerns free functions written to operate on streams ... >> to input streams (or, in simple-stream parlance, streams opened at ...
    (comp.lang.lisp)
  • DynToolKit BUILD 2006177192657 Released
    ... DynToolKit is a set of APIs to act as an abstraction layer to Progress ... -- Corrected documentation about minimum progress version this will ... -- Performance preprocessor between single and multiple DB applications ...
    (comp.databases.progress)
  • Re: Is Direct3D a rip-off of OpenGL?
    ... > Are you talking about the fact that the underlying graphics system is ... not even Microsoft engineers could make sense of using it or fixing it. ... The API, documentation, and sourcecode were a wretched hack. ...
    (comp.graphics.api.opengl)