Re: A more fundamental issue..
Jeroen van Drie <[email protected]>
| Newsgroups | gmane.comp.security.programming |
|---|---|
| Message-ID | <[email protected]> |
> > It's the end user that is be responsible. If msblast had not been a dud, if it had contained a dangerous payload (such as removing or crippling files), would the ensuing damage have been Microsoft's fault? Not really; companies have deployed microsoft knowing the risks. Companies could have chosen mac os, a linux desktop or even os/2. If the goal had been to become secure from microsoft vulnerabilities then that goal has always been attainable. Instead no solid security goals are set and despite knowing the risks no responsibility is taken. Instead, the end users collectively reward Microsoft for its expedient business and development model. Of course when things turn really sour a lot of managers will try to save their skin and point a finger at Microsoft but their decision to ignore security concerns really is their own. Microsoft just tries to please its shareholders with revenue and that's the whole point of being a public company. If end users reward Microsoft for this business and development model why should MS do anything different? If end users had rewarded security from the get go things would be very different at this point in time. The end user is the one making the decisions. The end user will also play the blame game, refuses to take responsibility, rewards gadgeteering over security. The end user also is a voter. Msblast brought some hospital and airline systems down. If msblast had not been a dud, if it had contained a dangerous payload (such as removing or crippling files), the ensuing damage could have dwarfed 9/11. Our dependence on these systems and the integrity of the data they contain is profound. The damage would almost certainly have prompted heavy handed government action, not just against Microsoft but against the software if not against the entire computer industry as a whole. Software would very likely be heavily regulated and in a capitalist society that means your product only survives if it passes the regulations. Naturally the tax payer is not going to pay for testing your operating system. It could mean the end of open source operating systems unless fairy godfathers like IBM or Apple would be willing to foot the bill for Linux and BSD respectively. It would make corporate sponsors de facto owners of the operating system development process: security is all about accountability and corporations can be held accountable. Not "the community". And then what would government regulation really matter? HIPAA compliance in Win2k server didn't stop msblast from infecting windows computers in hospitals. The US federal government through the NSA is well aware of poorly implemented security. Check out "The Inevitability of Failure: The Flawed Assumption of Security in Modern Computing Environments", http://www.nsa.gov/selinux/doc/inevitability/inevitability.html It's well worth reading. And it's sad that this paper, published in 1998, seems even more relevant now than it was back then. Unfortunately the NSA received a lot of loud complaints about selinux and pretty much had to abort the effort (http://news.com.com/2100-1001-950083.html?tag=fd_lede) And really what was the NSA thinking, using US taxpayer money to develop GPL software? While the principle of democratic governments developing GPL software is sound democratically, it is very much opposed to the ideas of free enterprise and fair competition. Why did I park my soapbox here in the security focus secure programming list? Well, some of you are pretty high up in your organisations and companies. Most of you are reading nothing new here. A lot of you realize that msblast was a dud. Most of you will know that government mandated computer security regulations would be detrimental to the open source development model. Most of you will see how government intervention could seriously hurt companies like IBM, Apple and Novell who have started to build their house on open source. Before governments start to step in and do this (and if the next msblast isn't a dud they very well might) the industry and the development community itself should step in and take this tiger by the tail, tacle it and neuter it. We who have this awareness also have the obligation to gently coax our higher uppers both in business management and government to understand it and become accountable.