Re: A more fundamental issue..

Jeroen van Drie <[email protected]>
Newsgroups gmane.comp.security.programming
Message-ID <[email protected]>
>  > It's the end user that is be responsible.

If msblast had not been a dud, if it had contained a dangerous payload (such 
as removing or crippling files), would the ensuing damage have been 
Microsoft's fault? Not really; companies have deployed microsoft knowing the 
risks. Companies could have chosen mac os, a linux desktop or even os/2. If 
the goal had been to become secure from microsoft vulnerabilities then that 
goal has always been attainable. Instead no solid security goals are set and 
despite knowing the risks no responsibility is taken. Instead, the end users 
collectively reward Microsoft for its expedient business and development 
model.

Of course when things turn really sour a lot of managers will try to save 
their skin and point a finger at Microsoft but their decision to ignore 
security concerns really is their own. Microsoft just tries to please its 
shareholders with revenue and that's the whole point of being a public  
company. If end users reward Microsoft for this business and development 
model why should MS do anything different? If end users had rewarded security 
from the get go things would be very different at this point in time.

The end user is the one making the decisions. The end user will also play the 
blame game, refuses to take responsibility, rewards gadgeteering over 
security. The end user also is a voter. 

Msblast brought some hospital and airline systems down. If msblast had not 
been a dud, if it had contained a dangerous payload (such as removing or 
crippling files), the ensuing damage could have dwarfed 9/11. Our dependence 
on these systems and the integrity of the data they contain is profound. The 
damage would almost certainly have prompted heavy handed government action, 
not just against Microsoft but against the software if not against the entire 
computer industry as a whole. Software would very likely be heavily regulated 
and in a capitalist society that means your product only survives if it 
passes the regulations. Naturally the tax payer is not going to pay for 
testing your operating system. It could mean the end of open source operating 
systems unless fairy godfathers like IBM or Apple would be willing to foot 
the bill for Linux and BSD respectively. It would make corporate sponsors de 
facto owners of the operating system development process: security is all 
about accountability and corporations can be held accountable. Not "the 
community". And then what would government regulation really matter? HIPAA 
compliance in Win2k server didn't stop msblast from infecting windows 
computers in hospitals.

The US federal government through the NSA is well aware of poorly implemented 
security. Check out "The Inevitability of Failure: The Flawed Assumption of 
Security in Modern Computing Environments", 
http://www.nsa.gov/selinux/doc/inevitability/inevitability.html  It's well 
worth reading. And it's sad that this paper, published in 1998, seems even 
more relevant now than it was back then. Unfortunately the NSA received a lot 
of loud complaints about selinux and pretty much had to abort the effort 
(http://news.com.com/2100-1001-950083.html?tag=fd_lede) 

And really what was the NSA thinking, using US taxpayer money to develop GPL 
software? While the principle of democratic governments developing GPL 
software is sound democratically, it is very much opposed to the ideas of 
free enterprise and fair competition.


Why did I park my soapbox here in the security focus secure programming list? 
Well, some of you are pretty high up in your organisations and companies. 
Most of you are reading nothing new here. A lot of you realize that msblast 
was a dud. Most of you will know that government mandated computer security 
regulations would be detrimental to the open source development model. Most 
of you will see how government intervention could seriously hurt companies 
like IBM, Apple and Novell who have started to build their house on open 
source. Before governments start to step in and do this (and if the next 
msblast isn't a dud they very well might) the industry and the development 
community itself should step in and take this tiger by the tail, tacle it and 
neuter it. We who have this awareness also have the obligation to gently coax 
our higher uppers both in business management and government to understand it 
and become accountable.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.