NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft / Security

Security


Microsoft: Perfect Windows Security Not Achievable

So why even try?

By Marius Oiaga, Technology News Editor

24th of August 2007, 08:42 GMT

Adjust text size:


Windows Vista editions
Enlarge picture
The fact of the matter is that security and perfection are not complementary concepts. Not even for Microsoft, or for the company's Windows operating system. And certainly perfect Windows Vista security is but a pipe dream, although Microsoft is applauding its latest operating system as the most secure Windows platform to date. But because perfect security is not achievable, it doesn't mean that Microsoft does not apply itself. In this
context, an illustrative example is the work the company has done with the Secure Development Lifecycle.

Steve Lipner, Senior Director of Security Engineering Strategy in Trustworthy Computing, and the former director of the Microsoft Security Response Center, faced a tough crowd during the panel on the ethics of security vulnerability disclosure at Black Hat in Las Vegas. Lipner revealed that the discussion shifted from ethical disclosure of vulnerabilities by independent researchers, to the security model in general. Namely, Lipner had to answer to the practice of software companies, Microsoft included, to ship products with known classes of security vulnerabilities.

"At Microsoft, we hear these kinds of ethical questions more often than you would think. All of them tend to come down to two common themes: How much should a vendor do and how long should a vendor wait to make a release "secure enough?" Our answer is that we do as much as we can to make our products secure, but we're always mindful of the need to ship customers a product that will not only improve security but be timely enough so that they'll actually use it. It is not much more ethical to work forever on a secure product that you never ship and users never use than it is to ignore security altogether," Lipner responded.

The bottom line is that security is never a final product feature, but a continuous evolution of standards. It is a healthy management technique to consider security as well as the shipping date just as product features, and to create a product designed to meet certain quality standards, that recommend it for shipping. Aiming for perfect security is equivalent to a perpetual development status, and the product will never ship. Instead, the focus has to be on raising the bar, again and again. Nothing but the scope of the SDL: "Secure by Design, Secure by Default, Secure in Deployment and Communication."

"While we do the very best we can, we know that perfection is not achievable. What we do is add steps to a commercially viable development lifecycle that can be accomplished by real developers on a schedule that allows them to ship competitive products. We learn from our mistakes and update the processes as we go, but we never forget that it's important to ship," Lipner added. "I think that given the choice between shipping perfectly secure software (whatever that means) that no customers will use and shipping software with continuously improved security that will actually help customers, the better ethical path is to ship."

TAGS:

Microsoft | SDL | security | Windows | Windows Vista
Read by 1,219 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.0/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Microsoft Forefront Security for Exchange Server and Sharepoint

3 Years Before Windows Seven, Microsoft Is Already Working on Security

Microsoft: There Is Only One Solution for Security - Windows Vista

Final Kaspersky Anti-Virus 7.0 and Kaspersky Internet Security 7.0 for Windows Vista

IE7 in Vista Can Fall Victim to Specially Crafted Malicious Web Pages

The Evolution of the Windows Vista Security Center

Mozilla's Security Tools for Firefox 2.0 Will Not Impact Internet Explorer

Forget About an Antivirus - Windows Security Holes Require Full Network Access Control

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM