Slashdot Mirror


Microsoft to Focus on Security

Anonymous Minion writes: "The Associated Press is reporting that Bill Gates announced to employees Wednesday a major strategy shift across all its products to emphasize security and privacy over new capabilities. In e-mail to employees, Gates referred to the new philosophy as "Trustworthy Computing" and called it the "highest priority". Gates said the new emphasis was "more important than any other part of our work."" People criticized Microsoft for treating security breaches as a public relations problem, so Bill Gates sent this email out to the Associated Press to prove them wrong. (rimshot!) Meanwhile, Richard Smith notes that the Globally Unique Identifier in every installation of Windows Media Player allows websites to universally track users, and Microsoft does not consider it a security problem.

720 comments

  1. So microsoft will focus on security? by redhairedneo · · Score: 0

    Adopting new ideas I see..

    1. Re:So microsoft will focus on security? by two_socks · · Score: 1, Redundant

      I don't see anything that indicates M$ is going to do anything more to protect privacy or security. Those seem to be just the new marketing buzzwords.

      --
      I can't help it - I'm a 19D.
    2. Re:So microsoft will focus on security? by alfredo · · Score: 1

      whos's security? The record companies? Never accept what they say at face value.

      When they talk of security, it means to me they are going to tighten the screws on us.

      --
      photosMy Photostream
    3. Re:So microsoft will focus on security? by SpaceLifeForm · · Score: 1

      DOJ.

      --
      You are being MICROattacked, from various angles, in a SOFT manner.
    4. Re:So microsoft will focus on security? by ghostdoguk · · Score: 0

      In the Microshite world adopting is usually stealing and does ANYONE really trust them.

      --
      Seize the day
    5. Re:So microsoft will focus on security? by hAkron · · Score: 1

      um....I think you mean:
      "They that can give up essential liberty to obtain a little temporary safety deserve neither liberty nor safety." -Ben Frankin

    6. Re:So microsoft will focus on security? by nixnixnix · · Score: 1

      Better yet:

      "Those who would give up a bit of security for a bit of freedom are in greater danger of losing both, for only in the protection of freedom can saftey be ensured" -- Sidney Crooke, American Abolitionist

  2. AND THE TOP STORY... by ekrout · · Score: 0, Troll

    Microsoft to Focus on Security and pigs fly, tonight at 11!

    --

    If you celebrate Xmas, befriend me (538
    1. Re:AND THE TOP STORY... by ekrout · · Score: 2, Funny

      Thanks, Eric! And in other news, Microsoft announced that they are to rename Windows 98 "Windows Diana". They expect that it too will be superficially attractive, consume lots of resources and crash horribly. (from http://members.ozemail.com.au/~lbrash/msjokes/)

      --

      If you celebrate Xmas, befriend me (538
    2. Re:AND THE TOP STORY... by Anonymous Coward · · Score: 0

      --Smithers, I think I'll donate a million dollars to the local orphanage...when pigs fly!

      --Will you be donating that million dollars now, sir?

      --No, I'd still prefer not.

    3. Re:AND THE TOP STORY... by Anonymous Coward · · Score: 0

      That is neither funny nor clever. Fuck you.

    4. Re:AND THE TOP STORY... by Anonymous Coward · · Score: 0

      i think microsoft bugs in general (that causes things to crash) are more important than security.

  3. Do we Trust Bill on this? by flafish · · Score: 0, Flamebait

    not after all of the problems in the past.

    1. Re:Do we Trust Bill on this? by ScourgeOfGod · · Score: 1

      um, yeah sure. and Al Haig is in charge.

      --
      If you're happy and you know it, think again!
    2. Re:Do we Trust Bill on this? by ryanr · · Score: 4, Funny

      Of course. I hear they're going to make their software "unbreakabale."

    3. Re:Do we Trust Bill on this? by Anonymous Coward · · Score: 0
  4. Come on now... by xinit · · Score: 4, Interesting
    We should know that this is more than just a simple PR move by Microsoft. I mean, don't they normally release information to the press in order to let their employees know how they're changing their focus?

    If you look at the other side of the story, this is pretty much admitting that they haven't cared about security at all. At least now they'll release more PR regarding security issues.

    Especially if they find that anyone's distributing exploit code.

    --
    --- http://foo.ca
    1. Re:Come on now... by hogsback · · Score: 2, Informative

      They didn't release it to the press.

      In e-mail to employees obtained by The Associated Press, Gates referred to the new philosophy as ``Trustworthy Computing''

      Now, of course, they may have deliberately leaked it ...

    2. Re:Come on now... by xinit · · Score: 1

      Yeah, that'd be a new way of them "secretly" changing focus.... heh

      --
      --- http://foo.ca
    3. Re:Come on now... by xinit · · Score: 1

      How embarassing, though, when you're simply showing a friend a new web site you found, and the .NET music server checks your music listening history and begins playing your all-time favorite song by N*Sync. You'd kept the obsession a secret for all these years, only to be betrayed by Microsoft. Damn them all.

      --
      --- http://foo.ca
    4. Re:Come on now... by Anonymous Coward · · Score: 0
      s/N\*Sync/Britney/;

      Everybody secretly listens to Britney Spears... I'm a Slave 4 U? That's one sweet song!

    5. Re:Come on now... by Zico · · Score: 0, Flamebait

      But is it any more of a PR move than Slashdot, owned by an open source (mostly) tools vendor focused mainly on Linux, pretending that Visual Studio.NET wasn't just made available last night? As well as the .NET framework SDK and redistributable runtime, free for download? VS.NET is probably more impressive than any software that's ever been released for Linux, but I think it's a remarkable job of denial that's been pulled off by the Slashdot editors so far in pretending it doesn't exist.

    6. Re:Come on now... by Anonymous Coward · · Score: 0
      What do you mean they didn't care about security?


      Don't you remember when windows 2000 was released.
      Microsoft touted then security was very important
      then.

    7. Re:Come on now... by Anonymous Coward · · Score: 0

      can't...let...truth...get...out...

      must...mod...down

    8. Re:Come on now... by Anonymous Coward · · Score: 0, Flamebait

      No shit. Slashdot has been feeding everyone propaganda for months about how evil .NET is, but now it actually comes out and slashdot appears to be frightened to mention it. Guess it's just easier to spread FUD about it.

    9. Re:Come on now... by prSpectiv2 · · Score: 1

      Maybe, but it's also worth noting that you can disable this "unique" identification quite easily by checking the appropriate box in WMP preferences. Despite the best (or worst?) intentions of M$, you can still wiggle your way around some of these "features".

      .

      --
      Nice guys don't finish last. In reality, they're abducted halfway through the race.
    10. Re:Come on now... by Ramadog · · Score: 1

      Does not matter whether the box is tickered or cleared on my wifes machine. The test site for that still gives the same number. This also applies after reboots.

    11. Re:Come on now... by sql*kitten · · Score: 4, Insightful

      We should know that this is more than just a simple PR move by Microsoft. I mean, don't they normally release information to the press in order to let their employees know how they're changing their focus?

      The last time Microsoft made an annoucement like this, they refocused the company on the Internet, and started hammering out MSIE into a Netscape-killer. For all his faults, once Gates and his people get an idea in their heads, they can turn on a dime and they won't stop until they do what they want to do.

    12. Re:Come on now... by jaavaaguru · · Score: 1

      on my wifes machine

      Kinda like saying "my friend really fanices you"...

      C'mon, we all know you're just hiding the fact that it's your PC that's got .Net on it :-)

    13. Re:Come on now... by xinit · · Score: 0, Offtopic

      Populate Washington State with clones of Bill Gates and Steve Ballmer?

      --
      --- http://foo.ca
    14. Re:Come on now... by uebernewby · · Score: 3, Insightful

      Agreed. Sure, Bill and his minions may usually end up the last people to "get it" (*starting* to think about the internet in 1995? sheesh), but like you said, once they've put it into their heads to do something, they'll get it done. Just don't expect results any time soon (witness the tediously long time it took to turnn MSIE into something useful, or how many versions of windows were released before they managed to build one that didn't suck).

      --

      News and bla for computer musicians: http://lomechanik.net/
    15. Re:Come on now... by fanatic · · Score: 2, Funny

      how many versions of windows were released before they managed to build one that didn't suck

      Is there some new totally different version of Windows (beyond XP) that I haven't heard about? ;)

      The day MS makes something that doesn't suck, it'll be a vacuum cleaner.

      --
      "that's not encryption - it's a new perl script that I'm working on..." - from some Matrix parody
    16. Re:Come on now... by xinit · · Score: 1
      I used to work with RealPlayer when I was working for a long-gone Real Partner. They had that Unique Identifier idea as well, and you could turn it off, too.

      There was a call, however, that would allow the server to flip the switch and enable it again. Another allowed you to turn cookies on or off in your default browser. Very interesting.

      I can't imagine anyone like Microsoft doing anything like that, though.

      --
      --- http://foo.ca
    17. Re:Come on now... by Anonymous Coward · · Score: 0

      You can talk about how bad MS sucks when the Linux "community" actually releases a desktop OS that's as user-frienly as Windows 3.1 Linux suxs man, get over it. Go write some drivers so you can get your shit to work.

    18. Re:Come on now... by Anonymous Coward · · Score: 0

      LOL, your lack of experience is obvious.

      What shit would that be? Winmodems????

    19. Re:Come on now... by poirotsj · · Score: 1

      That's an odd perspective. I've been reading alot about .NET all over, and virtually all of it is negative due to the bugs and security problems, to say nothing of the fact that it only runs on MS operating systems. So did you expect /. to bias it's stories towards .NET?

    20. Re:Come on now... by Unknown+Bovine+Group · · Score: 1

      ahh, more of the usual vitriolic anti MS FUD.... however this:

      The day MS makes something that doesn't suck, it'll be a vacuum cleaner.


      is pure gold.

      --
      m00.
    21. Re:Come on now... by Analog+Penguin · · Score: 2

      The real question, I guess, is what they're actually going to do. Focusing on MSIE did give new users immediate access to a (somewhat) functional browser, but it did have the added bonus for MS of furthering their monopoly power. Their decision to focus on security could well follow the same pattern: a (debatable) benefit to some users while giving MS the keys to a much stronger position.

      For instance: What if they patch the security for .NET, but only on their side (i.e., you only receive the benefits of their security features if you store your personal info on their servers; your home machine would be as insecure as ever)?

      Or what if their focus on security means they cripple or remove networking support with any systems but their own? (I can imagine the justification: they have no control over the software running the *nix servers, so in order to ensure security, they only allow contact with servers running MS software.)

      Plus, then you have to consider the upgrade prices (I doubt if MS will throw all that time and money into software revision and then give it away), and also, I imagine that they will somehow find some way to work this into their defense in the antitrust case...

      MS has proven repeatedly that they cannot be trusted. I have a sinking feeling that this new focus on security will manage to lead only to bad things for the computing world as a whole. If I am proven wrong, I will be the first to admit it, but I fear that there is little chance of that.

    22. Re:Come on now... by Sj0 · · Score: 1

      You can talk about how bad MS sucks when the Linux "community" actually releases a desktop OS that's as user-frienly as Windows 3.1 Linux suxs man, get over it. Go write some drivers so you can get your shit to work.

      That's a new approach to linux bashing -- apparantly comparing Windows 3.1 to RedHat 4.2?

      For users, Linux in it's current state is very good compared to Windows. I'm running RedHat 7.2, and it's fast and easy. Internet access was at the very least on par with Windows, though I found it easier because I didn't have to convert microsoftese into real language (Press 'OK' to continue, or 'Cancel' to skip this step(but still continue with the point after this step))

      On the other hand, I suppose you're going to tell us about how shitty the Model 'A' ford is too?

      --
      It's been a long time.
    23. Re:Come on now... by Corrado · · Score: 1

      Yea, it works the same way on my Win2000 box. Is this a security bug? :)

      --
      KangarooBox - We make IT simple!
    24. Re:Come on now... by juan2074 · · Score: 1

      Please don't.
      California has more people a lot like them. Send 'em there.

    25. Re:Come on now... by doofus1 · · Score: 0, Offtopic

      Hold your horses, I guarantee .NET will some day run on the Mac OS and Linux. If Mono doesn't make it happen, Microsoft will.

      HaHaHaHa, I'm laughing so hard, I have to pee now.

    26. Re:Come on now... by BlueUnderwear · · Score: 2

      Actually, most winmodems are supported now: Linmodems

      --
      Say no to software patents.
    27. Re:Come on now... by uebernewby · · Score: 3, Informative

      < feed the troll ... must feed the troll ... >

      The first versions of Windows were released in the late 80's. Not very many people saw those, because they were sold alongside the first versions of Excel (which not very many people saw either). There was some serious MacOS copying going on in those Windows-es IIRC, except they didn't work very well. Then there was Windows 3.11 (3.1 was so buggy it was quickly replaced by a much needed upgrade version; I doubt anyone here actually used Win 3.1 proper). Then 95 and the (usable, if unstable) upgrades for that. At the same time, MS experimented with a DOS-free OS as well (NT), which, in its 5th incarnation, actually turned into a usable, stable system (Win2K). Windows XP marks the end of the DOS-based 9x series; the consumer friendly aspects of these OSes got bolted onto the Win2k (=NT 5) kernel. By most accounts, it's a pretty decent OS. A resource hog and riddled with security holes, but pretty much as stable as Linux or any other decent OS. I had to use it for a month or so, and it never crashed on me once during that time.

      So there.

      --

      News and bla for computer musicians: http://lomechanik.net/
    28. Re:Come on now... by tweakt · · Score: 1
      Then there was Windows 3.11 (3.1 was so buggy it was quickly replaced by a much needed upgrade version; I doubt anyone here actually used Win 3.1 proper). Then 95 and the (usable, if unstable) upgrades for that.

      Acutally 3.1 was around for a while, but IIRC, 3.1 did not have a native TCP/IP stack. My first internet and modem ISP experiences were with 3.1 and I used it for the better part of a year. Windows 3.11 (or commonly known as Windows for Workgroups or WfWg) added more support for networking and filesharing, and added a native TCP/IP stack (previously microsoft only supplied NetBEUI and IPX).

    29. Re:Come on now... by eam · · Score: 1

      Actually, I started using windows on Win3.1. I installed & deleted each previous version. When I put Win3.1 on, I decided it sucked as bad as all the others, but it was obvious that Bill wasn't going to give up, so I left it there so I could get used to it. I still mostly used DOS, but win3.1 was the version that I started installing windows applications in.

      I've nearly gone full circle. I've moved off of windows & onto linux (except for a vmware installation for a few old windows applications that I haven't moved off of).

    30. Re:Come on now... by ilovecheese · · Score: 0

      how many versions of windows were released before they managed to build one that didn't suck

      But the strategy - if they did build vacuum cleaners, it wouldn't work 1/2 the time, and when it did, you'd have to keep continually be buying parts for it to keep it running. And after that, it would crash the other 50% of the time.

    31. Re:Come on now... by Anonymous Coward · · Score: 0

      You can talk about how bad MS sucks when the Linux "community" actually releases a desktop OS that's as user-frienly as Windows 3.1 Linux suxs man, get over it. Go write some drivers so you can get your shit to work.

      Funny. Last night I reeived a netfinity server I won on E Bay. My friend used his restore disks from a penguin server to install Red Hat 6.2 The install was mostly next...next...next except for one filesystem error which required one minor change. Full time 20 minutes to create a functioning server. As an MCSE I have yet to break the hour mark with any WinBlows server. My Linux desktop rocks. You go back to work as I am sure MS employees can only spend "so much" time on /.

    32. Re:Come on now... by FleshWound · · Score: 1
      Then there was Windows 3.11 (3.1 was so buggy it was quickly replaced by a much needed upgrade version; I doubt anyone here actually used Win 3.1 proper).
      IIRC, the only major difference between Windows 3.1 and 3.11 was stronger networking. 3.11 was primarily used by businesses (before NT came out), and 3.1 was primarily used by home users. It wasn't a patch, per se, but an upgrade that added functionality that not everyone needed, so not everyone used it.
    33. Re:Come on now... by Anonymous Coward · · Score: 0

      That's a new approach to linux bashing -- apparantly comparing Windows 3.1 to RedHat 4.2? I think the comparison was between Windows 3.1 and a modern distro (ie: Redhat 7.2). I also think that's a rather accurate comparison. Maybe comparing a random distro to win95 is more accurate, but linux certainly hasnt come as far as win98 yet, neither in driver support or in usability. I'm running RedHat 7.2, and it's fast and easy Oh, that distro that comes complete with ext3, yet doesnt supply patches to new kernels, so you cant ever update? The one that still doesnt support my year old webcam, or pci firewire adapter? Hmmmm, yea, great. Windows plug-n-play found both, first time, no driver disks needed.

    34. Re:Come on now... by Anonymous Coward · · Score: 0

      If win2k is so great. How come when I move a folder to the desktop, or anywhere else for that matter the damn thing is still used even with code that explicitly points to this folder in its old location. This has caused me endless nightmares, so yes winblows does suck.

    35. Re:Come on now... by kman_txun · · Score: 1

      Which Win version that doesn't suck? I have tried most of them and all suck for me. I'm really angry at this work becuase here in Guatemala, most the computer have software without lincense and I have really hard time introducing linux and using netscape to navigate. MSIE, is not useful, it takes a lot of memory.

    36. Re:Come on now... by nolageek · · Score: 0

      When my 64 year old mother can install Linux as easily as she has installed Windows (She did have to call me) we can begin saying Linix is "easy".

      I'm pretty computer literate and I have problems setting up Linux - and I eventually broken it quite a few times (Yes, i log in as root way too much - I know this)

      The point is, Linux is far too easy to break if you're a novice, and it's far too complex to set up if you dont have time to search the web and newsgroups looking for drivers. I wish it was different, but it just isn't at this point in time. I am finally dropping my Windows 2000 partition and just going Win98/Linux this weekend. Dont even get me started on how much I hate Windows 2000. uhg.

      --
      ---- The one good thing about music: When it hits you, you feel no pain.
    37. Re:Come on now... by Warin · · Score: 1

      Actually, IIRC,

      A -LOT- of people used 3.1. 3.0 was broken beyond belief, but 3.1 was fairly usable (As far as that goes. Slackware was still more stable and less of a system hog) 3.11 was the 'networking' upgrade to 3.1.

      Ahh...the good old days of configuring Trumpet Winsock to access the internet via PPP. Lord how I miss them!

    38. Re:Come on now... by Anonymous Coward · · Score: 0

      Microsoft stated some weeks ago, READ AS NOVEMBER OR DECEMBER of 2000. That they were going to provide Backdoors in WindowsXP for DOJ/FBI work. Does anyone remember reading this. That they are saying now that they are the internet security people is stupid.

      Benjamin

    39. Re:Come on now... by nixnixnix · · Score: 1

      And that Win98 machine with recognize all that hardware right before it crashes. Heck, yeah, that's far superior to Linux!

    40. Re:Come on now... by Fat+Casper · · Score: 2
      There's a version of Windows that doesn't suck? I think you're talking about WINE 1.0.

      My copy of '98 is secure. I wiped it and locked up the CD. That's the only way to make it "trustworthy."

      --
      I spent a year in Iraq looking for WMD and all I found was this lousy sig.
  5. timing? by cgenman · · Score: 3, Flamebait

    Hmm... Now that basically all of our code is developed and systems are embedded in concrete... let's try to secure this, shall we?

    Maybe they should have thought of this BEFORE they rewrote the OS?

    1. Re:timing? by xinit · · Score: 0, Redundant
      Closing the barn door after the horse has gotten out.

      Trying to add major baseline features to code in the wild... that'd be a potentially CLM for your average software engineer, wouldn't it?

      On another tangent, I'm highly amused by the bit about how they're also focusing on privacy. Yup, .NET will help MS keep your data secure.

      --
      --- http://foo.ca
    2. Re:timing? by asyncster · · Score: 0, Troll

      Well, with nearly 100 million lines of code or so, and hoards of incopetent developers working on it, problems are only natural. Maybe Microsoft should spend some time debugging their current software instead of forging on ahead with new products every year. I have talked with some Microsoft employees and if they make a silly mistake, such as a buffer overflow, they could lose their jobs. I bet there are many yet-to-be discovered bugs in Windows.

    3. Re:timing? by daniel_isaacs · · Score: 5, Funny

      Yes, it's all about timing. The rest of the email outlined thier other goals:

      1. To workout more
      2. To eat better
      3. To be nicer to the people we love
      4. To not drink so much

      The email closed with a lamentation about how these beginning of the year resolutions never seem to work, followed by a humorous panel from the comic strip "Cathy".

      --
      - Dan I.
    4. Re:timing? by Anonymous Coward · · Score: 0

      if they make a silly mistake, such as a buffer overflow, they could lose their jobs.

      Isn't that a little too harsh? But if so Microsoft must be looking for a few new employees. Do it quickly before someone else applies.

    5. Re:timing? by Anonymous+DWord · · Score: 2

      So what would you propose instead?

      --
      "If he thinks he can hide and run from the United States and our allies, he's sorely mistaken." Bush on bin Laden
    6. Re:timing? by MrBlack · · Score: 2

      do M$ really have hoards of incopetent developers?I thouught they had a reputation for hiring and retaining some of the best developers around. Sure, there may be developers just as good or better working in other companies but to characterize M$'s development team as incompetent is being silly. I think it is more a case of priorities, they do what their superiors want, and in most cases M$ want things to be easy to use and convenient before they want them to be secure. They want to develop cool features and be first to market. Now if Bill G. has cracked the whip for real, and isn't just after good PR we can expect these priorities to change somewhat...

    7. Re:timing? by Anonymous Coward · · Score: 0

      As anyone who administers windows or any programmer that has ever tried to do anything remotely interesting with the API can tell you, is that there has never been anything "concrete" about the OS.

    8. Re:timing? by Boiling_point_ · · Score: 2
      It's still about new features. "Security features" exist in Microsoft products - it's just that there's not enough of them, they work poorly and more often than not, they default to "I'm naked and alone" - see my sig.

      From the sound of the article, MS have simply realised that security is a very fashionable feature to promote nowadays, just like "streaming multimedia" was in about 1997.

      Maybe they should have thought of this BEFORE they rewrote the OS?

      I'm sure they did consider it when they were designing XP a couple of years back - but they realised that they'd profit more by re-skinning Win2K. They had no way of knowing that both Sept. 11 and Code Red would occur, and now they're reacting to the environment like any savvy business would.

      --
      "If you create user accounts, by default, they will have an account type of Administrator with no password." KB Q293834
    9. Re:timing? by Hatechall · · Score: 1

      What is a CLM?
      Excuse my ignorance. Some sort of post-programming incompatability issue?

    10. Re:timing? by Hatechall · · Score: 1

      Is THIS it?

    11. Re:timing? by xinit · · Score: 1

      Sorry - it's a three letter acronym for "Career Limiting Move"

      --
      --- http://foo.ca
    12. Re:timing? by Arker · · Score: 2

      All true.

      At the same time, the point of the parent poster should not be underestimated - even the best coders would face a monstrous task trying to secure a codebase that is so large and that has been, to this point, engineered to meet totally different priorities.

      Of course the smart money says they don't mean a word of it anyhow - just PR. Oh, sure, they'll probably fix a few more bugs than usual for a month or two, but institutional inertia combined with the technical problems would probably keep them from doing more than that even if the Borg Queen really does mean it.

      --
      =-=-=-=-=-=-=-=-=-=-=-=-=-=-
      Friends don't let friends enable ecmascript.
    13. Re:timing? by Tony-A · · Score: 3, Insightful

      "Security Features" is too much like putting a steel security door on a tar-paper shack. Looks impressive, but there are too many ways around it. OpenBSD's security doesn't come from "features". It's there because they've taken the trouble to secure the perimeter.

    14. Re:timing? by staeci · · Score: 2

      Mac on the desktop, Linux on the server.
      Who are these Microsoft people again?

      --
      'Welcome to Rivendell, Mr. Anderson...'
    15. Re:timing? by ZaMoose · · Score: 2

      I don't know why McNealy and crew haven't pushed for "Sun in the server room, Mac on the desktop." Especially with OSX out. I'd have to say that M$ would have a hefty fight on their hands in the corporate space if Jobs and McNealy could get along and push a similar vision...

      --
      I wish I had a kryptonite cross, because then you could keep Dracula and Superman away.
    16. Re:timing? by Anonymous Coward · · Score: 0

      ure, there may be developers just as good or better working in other companies but to characterize M$'s development team as incompetent is being silly.

      Oh, really? What would you call it when they produce a mail client app with a Turing-complete language embedded in it, which has full access to both the outgoing mail queue and the file system, and which happily executes any code found in incoming messages?

      Sure, the script-kiddies are the perps in this scenario and they're lighting the matches, but who is it that keeps building the houses out of balsa wood and flash paper?

      Maybe MS does have some competent coders, but it's pretty clear that there's nothing in place in their organization to keep the work of the incompetent coders out of the shipping products.

    17. Re:timing? by Anonymous+DWord · · Score: 2

      And Microsoft does what, give up? Your idea is fine by me, but they might not take it so easily.

      --
      "If he thinks he can hide and run from the United States and our allies, he's sorely mistaken." Bush on bin Laden
    18. Re:timing? by matrix29 · · Score: 1

      do M$ really have hoards of incompetent developers?I thouught they had a reputation for hiring and retaining some of the best developers around.

      BIG FUCKING WHOOPTIE DOO!

      As the saying goes, "The proof is in the result."

      Microsoft software is buggy as hell and unreliable to the extreme. I can hire a genius to do my programming, but if it is buggy does this mean my money was well spent?

      To you I say once again, BIG FUCKING WHOOPTIE DOO!

      Their software is crap and it shows EVERY FUCKING DAY!

      --
      "Face it, a nation that maintains a 72% approval rating on George W. Bush is a nation with a very loose grip on reality.
    19. Re:timing? by Anonymous Coward · · Score: 0

      Interesting comment but, I thought that .Net was a new architechture. It could be that intrducing an completly new architecture makes it possible. Perhaps the concrete is still wet.

    20. Re:timing? by nixnixnix · · Score: 1
      Oh, really? What would you call it when they produce a mail client app with a Turing-complete language embedded in it, which has full access to both the outgoing mail queue and the file system, and which happily executes any code found in incoming messages?

      Amen brutha. That about sums it up. Making an OS secure doesn't sell, and if you're in it for the money (Microsoft), instead of in it for solving problems (The Open Source World), security takes a back seat. As a result everybody loves to use Windows because they do such a great job making it easy to use, everybody complains Linux and BSD is "too hard" and that they need to "get with the program".

      Please, BSD people, Linux people do not "get with the program". The different emphasis is why you exist! Duh!

  6. MS security by dunedan · · Score: 0, Redundant

    sure no problem, now that we've got about 100x10^6 lines of code lets go through and ask ourselves which are not safe in combination =>

    1. Re:MS security by Anonymous Coward · · Score: 0

      100x10^6

      don't you mean 10x10^7?

      or 1000x10^5?

      or simply 10^8

  7. That GUID on WMP? Yeah . . . by GlassUser · · Score: 2, Offtopic

    Normal slashdot staff overreacting again. You can turn that ID off. Granted, they should make it default to off, and ask you before they go around putting out supercookies, but it's possible to fix the hole. Even in WMP6.x. This was going across bugtraq today. Apparently, if you have the ID backdoor disabled, it generates a random number each time the control is queried. Spare his page, though, I wrote this with no replies (first post, almost), and the page was already horribly slow.

  8. too little, too late. by Anonymous Coward · · Score: 1, Informative

    for anyone who avoids M$ because of their lack of security, i think this will be seen as too little, way way too late.

  9. Microsoft focusing on security? by BeneathTheVeil · · Score: 0, Offtopic

    Shouldn't this be in the humour section, instead?

    1. Re:Microsoft focusing on security? by Anonymous Coward · · Score: 0

      Nah. Creative fiction.

  10. Yeah Right by Wheaty18 · · Score: 1

    Gates referred to the new philosophy as "Trustworthy Computing" and called it the "highest priority".

    For some reason, whenever I boot into Windows, I have a strange feeling that it's spying on me. That quote from Billie G certianly does not reassure me.

    1. Re:Yeah Right by Anonymous Coward · · Score: 0

      That is obviously because you either:

      a) have no idea how any computer works or how to find these things out
      b) have no idea how to check out your running processes and how they work/what they do,
      c) are blindingly stupid, or
      d) are just karma whoring.

      Fag.

    2. Re:Yeah Right by Anonymous Coward · · Score: 0

      Yah.. I didn't like the feeling. I bought some apples to play with os x on. Go there, its where you want to be.

    3. Re:Yeah Right by Anonymous Coward · · Score: 0

      I once read in a review of XP:
      "XP reminds me of E.T. - it always wants to call home"

  11. Funny, I Don't Feel More Secure... by The+Spie · · Score: 5, Funny

    Why does Microsoft saying they're going to focus on security remind me of the US government talking about campaign finance reform?

    --
    If using Linux is about choice, how come people complain when I choose to use Windows?
    1. Re:Funny, I Don't Feel More Secure... by Arandir · · Score: 2

      Campaign Finance Reform: individual contributions are capped while they put out a welcome mat at the back door for corporations and unions; finance candidates through tax revenues so that you are forced to finance the campaigns of those you wouldn't vote for if a gun were put to your head.

      Microsoft Security: store all your personal information at One Redmond Way so that malicious corporations can't invade your privacy; argue that public disclosure of exploits and bugs are criminal acts.

      --
      A Government Is a Body of People, Usually Notably Ungoverned
    2. Re:Funny, I Don't Feel More Secure... by FFFish · · Score: 1

      People say "corporations and unions" as if they were different things.

      IMO, when a union is large enough to hold any sort of political power, it is a corporation.

      --

      --
      Don't like it? Respond with words, not karma.
    3. Re:Funny, I Don't Feel More Secure... by Arandir · · Score: 2

      Although over a certain size they amount to the same thing, a lot of people still make a distinction between corporations and unions. Conservatives don't like unions and liberals don't like corporations, despite the existance of conservative unions and liberal corporations.

      Both are legal entities that cannot vote but which have more influence in politics than individuals have. My plan for Campaign Finance Reform: zero limits on contributions, but they can only be made by qualified voters.

      --
      A Government Is a Body of People, Usually Notably Ungoverned
    4. Re:Funny, I Don't Feel More Secure... by Karl_Hungus · · Score: 1

      ...a lot of people still make a distinction between corporations and unions.


      You mean the distinction between people who work and people who profit from that work? Lots of people still make distinctions between night and day as well. But I mean, come on, do we have to sit here all day and make distinctions between things like hot and cold, on and off, black and white, terrorist and freedom fighter?

      Your plan is ridiculous. It would give 10 people with $100,000 each to burn the same power as 100 people with $10,000 each or 1000 people with $1000 each, or 10,000 people with $100 each or 100,000 people with $10 each or 1,000,000 people with $1 each. One citizen, one vote it is not. Please go to the corner and rethink this. When people talk about "voting with your dollar" they mean doing business with businesses that share their values, not buying politicians. I can't believe this has to be said, but there it is.

    5. Re:Funny, I Don't Feel More Secure... by MrFredBloggs · · Score: 1

      corporations exist to make profit
      unions exist to help people

      i think there is a difference.

    6. Re:Funny, I Don't Feel More Secure... by FFFish · · Score: 1

      " 'corporations exist to make profit
      unions exist to help people
      ?'

      Unions exists to make a profit at the expense of people they are pretending to help."

      What he said.

      I firmly believe unions are a necessary thing in most corporations, because I've seen all too often how employees are screwed-over by their employer when it's convienent, and particularly when the employer needs to blame someone.

      But at the same time, I've seen a lot of greed and sloth in the unions. My current beef is with a union that insists that all union employees travelling to union functions must fly Air Canada... commonly at 5x to 10x the cost of using WestJet.

      Air Canada is a fucking pig of an airline, subsisting on government bailouts, predatory pricing when there's competition, and monopoly pricing when there isn't competition. It's management is overpaid and undercompetent, and it shafts its employees as much as possible.

      WestJet is a fantastic airline, efficiently run with great bennies for its employees, and smart and savvy management. It has great prices and great service.

      But AC is union, and WestJet isn't unionized. So the other large unions insist that AC be used. Rewarding the worst airline in Canada, and at a great cost to the employees they represent.

      That's stupid beyond belief. That is how a union can act as a corporation: screwing its members for the sake of some idiotic idealized advantage, instead of behaving sensibly.

      --

      --
      Don't like it? Respond with words, not karma.
    7. Re:Funny, I Don't Feel More Secure... by MrFredBloggs · · Score: 1

      I guess their argument is that they ARE helping union members - just not the members of their own particular union.
      I`ll admit to not knowing how the unions work over there (i`m not exactly an expert on UK unions!). But surely theres some room for a vote on that sort of thing? Fly by the cheap airline but voluntarily donate some money to the other union, or have some reciprocal arrangement?

    8. Re:Funny, I Don't Feel More Secure... by dillon_rinker · · Score: 2

      OK. Let's go with "NO CAMPAIGN CONTRIBUTIONS!" Any candidate who accepts ANY money from ANYONE (except possibly their immediate family) immediately goes to the electric chair.

      So the only way to afford running for national office is to ALREADY HAVE MONEY! That's right, by eliminating campaign contributions, you have guaranteed that the only people who will campaign for office will be the rich folk. Us po folk can run, but we'll get trampled 98% of the time.

      What's the solution? Realize that MONEY = POWER, POWER = MONEY, always has, always will. This will never change.

    9. Re:Funny, I Don't Feel More Secure... by sharkey · · Score: 2

      put out a welcome mat at the back door for corporations and unions

      Yeah. Our collective "back door".

      --

      --
      "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
    10. Re:Funny, I Don't Feel More Secure... by remande · · Score: 2

      At least, if you do that, the rich candidates that do run will be influenced by their own consciences and their constituents. This is a big deal better than Big [Oil|Tobacco|Software|Media] throwing so much money around in so many different directions that, no matter who you vote for, they've already been bought off.

      --

      --The basis of all love is respect

    11. Re:Funny, I Don't Feel More Secure... by Anonymous Coward · · Score: 0

      Wow. So far every post I've read is offtopic. Somebody may as well change the original post.

      > Both are legal entities that cannot vote but which have more influence in politics than individuals have. My plan for Campaign Finance Reform: zero limits on contributions, but they can only be made by qualified voters.

      And then all that happens is Bob Smith (CEO of GeneriCorp), gives $10,000,000 to Bob Smith (Individual Voter), who then promptly donates it to *insert name here* (CorruptPolitician).

  12. secure comp != comp with winbloze on it! by neologee · · Score: 0, Offtopic

    install linux, remove winbloze :)

    1. Re:secure comp != comp with winbloze on it! by flafish · · Score: 1

      Better yet, don't install it in the first place.
      Odd that this comes from M$ after the BBC story.

  13. Standard Corporate Security Policy by ZenJabba1 · · Score: 5, Insightful

    After reading the article, and also having my Microsoft account rep call me up after I have told her that I wont be installing my "enterprise" (every time I say that word, my whole team breaking to ST:TNG theme song), becuase the cost of making sure Microsoft's buggy software (generally Office and Windows W2K) costs me more than the operating system does itself in both actually purchasing costs of software and man power required to check, recheck and check again that everything is set up tight... My account rep had the hide to say this afternoon, "So now we have promised to do this, will you upgrade to Office XP now"...

    Nothing has changed as far as I can see, nothing will in the next 1 - 2 years because Microsoft will take that long to get what we currently have running NOW working correctly, and I just feel this is another ploy to get Microsoft to force us to upgrade to the latest and greatest operating system because they are promising that this time, really folks, this time it will be the most secure and stable release of Microsoft software EVER!, as if this is hard to to!

    Grrrr, too many NT crashes, not enough intellegent techs to figure out what went wrong, other than.. oh just reboot!

    --
    `find / -name "*your_base*" -exec chown us:us {} \;`
    1. Re:Standard Corporate Security Policy by Dudio · · Score: 1, Interesting

      You know, I think they're actually serious this time. I just sat in on a 3-day .Net developer workshop, and the trainer told us that the current directive in Redmond is for all product groups to sweep the entire code base for security-related bugs. Supposedly, new development has been halted during this process, and product groups will be held accountable for all future exploits of their products.

      Quite honestly, I don't think they have much choice in the matter, and it's not just a question of liability. Security concerns are one of the top reasons firms decide not to use Microsoft software for enterprise applications, and this is obviously a market they covet. Products like Datacenter Server and SQL Server don't sell well if the customers keep hearing about Microsoft products being exploited.

    2. Re:Standard Corporate Security Policy by phidipides · · Score: 2, Insightful

      The typical Slashdot post seems to assume that Microsoft will fail because they have not succeeded in the past. That's a really dangerous attitude -- the same attitude probably prevailed when Internet Explorer 1.0 came out, but now web logs show that some IE variant accounts for 95% of traffic. Never mind HOW Microsoft achieved this result, the fact is that they DID achieve it because they made a commitment to be successful at all costs.

      There are a lot of intelligent people working for Microsoft, many of whom are management and are capable of focusing resources when required to do so. Say what you will about their code quality, their business practices, and their tactics, but don't dismiss them lightly...

    3. Re:Standard Corporate Security Policy by qqtortqq · · Score: 0, Offtopic

      > I just sat in on a 3-day .Net developer workshop

      You must have gone before the truth in advertising suit came through and M$ was ordered to change the name of that workshop to "3 days of brainwashing"

    4. Re:Standard Corporate Security Policy by Waffle+Iron · · Score: 5, Insightful
      current directive in Redmond is for all product groups to sweep the entire code base for security-related bugs.

      Problem is, that's not going to do a lot of good if these people don't have the experience to spot security bugs in the first place. The potential universe of exploits is huge, and it includes interactions between components written by different groups. I doubt that they even have the talent base to do this job effectively.

      It's possible to create an OS that's secure out of the box; OpenBSD is an example. Now Microsoft wants to get to the same place, but with orders of magnitude more code, a small fraction of the time, and next to zero corporate security culture. This is beyond "trying to have a baby in one month". This is more like putting 5900 women in a room and trying to get a baby in one hour.

    5. Re:Standard Corporate Security Policy by alex_siufy · · Score: 1

      Successful yes, but at what cost?

      User's privacy perhaps... Now they're trying to fix the holes they left open just so they could be "successful".

    6. Re:Standard Corporate Security Policy by Rooktoven · · Score: 2, Insightful

      I'll do that.

      Their code quality is mediocre, their business practices unethical, and their tactics despicable.

      One dismisses them as one dismisses something that threatens one's very freedom itself.

      Of course that may not mean much in America...

      --

      Acquiescence leads to obliteration
    7. Re:Standard Corporate Security Policy by Anonymous Coward · · Score: 0

      oh just reboot!

      You forgot, "oh, just reinstall!".

    8. Re:Standard Corporate Security Policy by whereiswaldo · · Score: 3, Insightful

      Here's the real deal, IMO:

      Microsoft's brand name is going down the crapper - faster than you can say "Flush". They MUST do something about their lax security image, or it will only get worse. Read on...

      Probably every IT magazine has blasted them about their security practices. People everywhere think Microsoft's security breaches are a joke these days.

      What's making them peddle even faster is that Linux is breathing down their neck and getting more and more mainstream. I find a lot of irony in this. Why? Microsoft crushed Netscape and many other companies by giving software away for free. They can do this because they have a huge bankroll and don't need the extra revenue of addon products. Linux is free, too... this hits them dead on where it hurts - their OS market. It was said many times during the Netscape vs. Microsoft browser war "you can't beat free". Only now, Linux and Open Source have something better than a large bankroll. They have practically unlimited development capacity. WAY more than Microsoft thousands of engineers. They also have the hearts and minds of hundreds of thousands of developers around the world. They have goodwill. They have quality and security far superior to Microsoft.

      I believe this is the way. Eventually everything gets commoditized. The operating system is next. Microsoft - the ride's just about over. You know it because you're digging your claws into just about every market you can. You're differentiating. Not everyone is buying your differentiated crap, though, are they? Your reputation will follow you wherever you go... remember that.

    9. Re:Standard Corporate Security Policy by whereiswaldo · · Score: 1
      oh just reboot!
      oh, just reinstall!

      and now... oh, just upgrade!

    10. Re:Standard Corporate Security Policy by Captn+Pepe · · Score: 3, Funny
      This is beyond "trying to have a baby in one month". This is more like putting 5900 women in a room and trying to get a baby in one hour.

      And as everyone knows, if you put 5900 randomly chosen (American, normally distributed) women in a room, you have to wait roughly 18 days for one of them to have a kid. You actually need 2.5 million to get a kid in an hour, and not even MS employs that many programmers. Though to hear some tell, the Open Source Movement might. Of course, they're predominantly male geeks, so you'd probably have to wait several years before 5900 open source programmers produced offspring, and even then it might just be a replicant.

      --

      Quantum mechanics: the dreams that stuff is made of.
    11. Re:Standard Corporate Security Policy by phidipides · · Score: 1

      If you dismiss them you fail to recognize them as a legitimate threat. True, right now sysadmins everywhere beg management not to force them to use NT because of the security flaws and bugs. But if Microsoft is planning to focus more on these two areas, it would be a good idea not to assume they will fail. And if they don't fail, the success currently enjoyed by Linux and BSD may go the way of Netscape and Netware.

    12. Re:Standard Corporate Security Policy by Anonymous Coward · · Score: 0

      At one point, Microsoft had NO software support for the Internet. Microsoft must have made some kind of change to get where they are today.

      I imagine at some point, they had next to zero corporate internet culture.

      Watch out. Microsoft has proved suprisingly agile for such a large company.

    13. Re:Standard Corporate Security Policy by Anonymous Coward · · Score: 3, Interesting

      I imagine at some point, they had next to zero corporate internet culture.

      That's not true -- they were a VAX shop and had a usenet feed and e-mail back in the days of bang-paths. billg@microsoft.com has been a live address for decades.

      Back in '89 or so, they made it clear that TCP/IP was going to be the LAN protocol of choice by building it into OS/2 LAN Manager, even though IPX had something like a 90% marketshare at the time.

      What they didn't get very quickly was that the WWW (primarily stupid pictures of people's cats at the time) was going to be a major revolution in corporate computing, or that it would be more useful to the home user than a proprietary online service.

    14. Re:Standard Corporate Security Policy by Anonymous Coward · · Score: 0


      "Not everyone is buying your differentiated crap, though, are they? Your reputation will follow you wherever you go... remember that." I've got the number of a fantastic anger-management counsellor if you would like it.

    15. Re:Standard Corporate Security Policy by pHDNgell · · Score: 5, Funny
      This is more like putting 5900 women in a room and trying to get a baby in one hour.

      I don't know about the rest of you guys, but I'm buying this video when it comes out.

      --
      -- The world is watching America, and America is watching TV.
    16. Re:Standard Corporate Security Policy by linzeal · · Score: 0, Flamebait

      I don't know about you but I've met my fair share of beer gutted, facial hair, and sexually ambiguous female types in college. They typically were near the gender studies offices. Eventaully the geek population could live in a hive like situation with a snarl toothed dumb breeder queen for every 1000 or so geeks with only 10 or so alpha geeks being the drones.

    17. Re:Standard Corporate Security Policy by kiwipeso · · Score: 0

      It could be that they've heard about my plans for KAOS, a very secure operating system.

      If I were in their shoes, I'd be scared of someone who doesn't have to limit the security to please the government .

      This may sound like wishful thinking, but because most of the OS and apps are designed in Java2 it could be a concern.

      --
      - Kaos games and encryption systems developer
    18. Re:Standard Corporate Security Policy by kiwipeso · · Score: 0

      They have the talent to do the job, but they won't allow people to know enough of the program for it to work.

      I am creating an OS which is secure out of the box, KAOS is based on OpenBSD.
      It's possible to make a full OS under 100 megs of code, which is what XP has.
      I have the advantage of letting evolution do hard work on my code, I don't need to open source it to get reliable code.

      Put 5900 women in a room and I'll try making babies for an hour with each one...
      That's 1 year of sex, 16 hours per day.

      --
      - Kaos games and encryption systems developer
    19. Re:Standard Corporate Security Policy by fajoli · · Score: 1

      Nice comment. This comment has got to be the closest thing I have seen to a good old fashioned bible thumping sermon I have ever seen on slashdot.

    20. Re:Standard Corporate Security Policy by warpSpeed · · Score: 1

      MS is vigorously investing it self in other revenue streams at the moment. They know that the OS market is getting comoditized, and they possibly have a limited window of keeping control of the OS market. They may or may not lose this dominance in a few years. So in the mean time they are paddling like ducks (calm on the surface, webbed feet going madly under the water) trying to invest in other technologies where they can gain a simmilar dominance and continue the monopoly.

      MS is not going away any time soon, baring the Gov't growing some gonads and dealing with them.

      ~Sean

    21. Re:Standard Corporate Security Policy by ethereal · · Score: 1

      The difference is that you can use an existing OS monopoly to get everyone to use IE. You can't take advantage of a monopoly situation (a financial and marketing-oriented thing) to force security (a thinking and planning and reviewing process) to occur. Throwing money at it will not completely solve the problem either. The spreading of IE is nothing compared to the challenges of securing this far-flung empire. Remember - Microsoft is a marketing and investment business with a software front end. Is there actually any money in spending years to secure the whole thing, when you could be creating new features or new GUIs instead?

      Even if this announcement were true (and so far I don't see why I should believe this any more than past dedications to security), no business will really embrace security unless its salable, and that won't happen until software purchasers understand that they really need security. That realization has been a long time coming, and for most people is still not here yet.

      --

      Your right to not believe: Americans United for Separation of Church and

    22. Re:Standard Corporate Security Policy by Catiline · · Score: 2

      This is more like putting 5900 women in a room and trying to get a baby in one hour.
      You're a little low. It would take 9 months x 30 days x 24 hours = 6480 women.

    23. Re:Standard Corporate Security Policy by Jucius+Maximus · · Score: 2
      "Only now, Linux and Open Source have something better than a large bankroll. They have practically unlimited development capacity. WAY more than Microsoft thousands of engineers. They also have the hearts and minds of hundreds of thousands of developers around the world. They have goodwill. They have quality and security far superior to Microsoft. "

      And more importantly, the development goals of the linux community are not driven by quarterly profit goals. They are instead driven by making something that's worth using.

    24. Re:Standard Corporate Security Policy by Anonymous Coward · · Score: 0
      I don't know about the rest of you guys, but I'm buying this video when it comes out.

      Particularly if it includes the making babies part...

    25. Re:Standard Corporate Security Policy by GSloop · · Score: 1

      Widom lurks above!

      I like the post...too bad I don't have points to grant!

      Thanks for the clairity!

    26. Re:Standard Corporate Security Policy by GSloop · · Score: 1

      Uh, that would be WiSdom... {sigh}

    27. Re:Standard Corporate Security Policy by Anonymous Coward · · Score: 0

      oh hey i just grabbed root on an openbsd 3.0 box yesterday. openbsd is more secure than MS (I run it everywhere) but nothing is ever secure out of the box or at any other time.

    28. Re:Standard Corporate Security Policy by Anonymous Coward · · Score: 0

      Bullshit - offtopic?

      Virtually any "seminar" offered by any vendor is brainwashing... This isn't offtopic at all...

      Moderator, you only wish you were smoking crack, then you'ld have an excuse for being so stupid.

    29. Re:Standard Corporate Security Policy by Sj0 · · Score: 1

      "Windows SX is faster and more reliable than ever!"

      One day later:

      "Uh...I'm still having the same problems!"

      :)

      You know what I'm talking about.

      --
      It's been a long time.
    30. Re:Standard Corporate Security Policy by Anonymous Coward · · Score: 0
      They are instead driven by making something that's worth using.

      Worth using for who? For what purpose? The basic failing of most open source is that it ignores the need to serve human goals (i.e. goals that aren't intrinsically tied to the computer) in favor of an empty technical elegance.

    31. Re:Standard Corporate Security Policy by StormyMonday · · Score: 2

      This is beyond "trying to have a baby in one month". This is more like putting 5900 women in a room and trying to get a baby in one hour.

      No, it's like putting 5900 men in a room and trying to get a baby in one hour.

      Microsoft has consistantly demonstrated a very deep level of cluelessnes in security matters. First, they have to convince their people why security matters. Then they have to figure out how to make code secure, in general. Then they have to rewrite (or at least audit) their entire code base.

      I'm not holding my breath.

      --
      Welcome to the Turing Tarpit, where everything is possible but nothing interesting is easy.
    32. Re:Standard Corporate Security Policy by jo42 · · Score: 1
      > product groups will be held accountable for all future exploits of their products.

      How? Public flogging or a 15 minute time-out?

    33. Re:Standard Corporate Security Policy by jo42 · · Score: 1
      > Then they have to rewrite (or at least audit) their entire code base.

      The issue is not just code, some things need a brand new design - throw out the crap and do it over again.

  14. MS Pioneers Trustworthy Computing by timanderson · · Score: 0

    This will undoubtably be followed by another announcement, claiming that MS pioneered the "Trustworthy Computing" movement in the computer industry.

  15. "Let them eat e-mail" by DaSheeter · · Score: 0

    I don't know what form this security missive may take, but I would assume years of integrating identifiers into anything they can would be hard to overcome.

  16. only one thing to say by nomadic · · Score: 2, Funny

    HAHAHAHAHAhahahahahaHAHAHAHAHAHAHAhahahahaheeheehe e.

    I guess those stories suggesting that software companies might become liable for damages arising from security holes put the fear of God into him.

    1. Re:only one thing to say by Anonymous Coward · · Score: 0

      Not sure why I'm replying to this, as the moron poster is obviously subliterate, but here goes:

      Nowhere in the post did it mention anything about linux. Nowhere did it imply that linux, open source, or anything even remotely related had anything to do with it. It was the report by the National Academy of Sciences which suggested that software companies should be liable, not anything originating on slashdot. Which you would have realized if you'd taken the 3 seconds to follow that link, but I guess it's hard to use the mouse when you lack opposeable thumbs.

  17. so all those pr0n sites... by kootch · · Score: 3, Funny

    so now all of the pr0n sites will know exactly what TYPE of pr0n to feature on the front page whenever I *happen* to stop by...

    well, atleast maybe I'll get more targeted advertising... ya know, nothing against transvestites, but the pr0n of them in an advertisement just does NOT make me want to subscribe!

    1. Re:so all those pr0n sites... by Anonymous Coward · · Score: 0

      Hee hee, now maybe I won't get those javascript popups of copraphilia...

  18. Oh no! by avalys · · Score: 0, Redundant

    Just think of the implications!! Microsoft has already been "focusing" on performance, stability and security for many years - and look at the results! Such delightful products such as Windows 95, 98, ME, and NT.

    --
    This space intentionally left blank.
    1. Re:Oh no! by Anonymous Coward · · Score: 0

      that's really original. nobody else in this whole thread said anything like that. really. here's a cookie.

  19. That'll work. by Rothfuss · · Score: 3, Informative

    Security over function. That makes sense. I already love it everytime windows warns me that I am about to do something dangerous, restricts me from seeing files I shouldn't touch by default, and dumbs down everything to the point where it takes me 45 minutes to make the machine useful after a clean installation.

    Now they are going to focus on security instead of function.

    I have a pocket calculator that adds, subtracts, multiplies and divides. The square root button is broken. I just jammed an RJ-45 cable into the slot where the battery normally goes. It appears to be doing nothing.

    I'm certain that my calculator now meets Bill's new objectives. It does nothing, but is entirely secure. Particularly since it is behind a firewall.

    Good idea Bill.

    -Rothfuss

    1. Re:That'll work. by poot_rootbeer · · Score: 1

      I already love it everytime windows warns me that I am about to do something dangerous

      "You are about to do something dangerous and stupid. Do it anyway? [Cancel] [OK]"

      Is that really security?

    2. Re:That'll work. by Anonymous Coward · · Score: 0

      Actually, that should be [OK] [Cancel].

      Stupidity's the default option, remember?

  20. Microsoft and Security by Anonymous Coward · · Score: 0

    Now that's an oxy moron!

    I wonder if people actually catch that line in the EULA, "I give my soul and first born to microsoft, yarda yarda!"

    I Agree.... Click!

    ;-)

  21. It's far from being the ONLY identifier by javaDragon · · Score: 1

    Remember : the latest version of windoz itself is subscription-based, which means another unique ID. Not taking into account the other uids found so far in the microsoft office, processor id, network card MAC, not counting the yet to be discovered unique ids, the "passport" centralized accounting, the whole micro$oft thing is in itself a gigantic polymorohic security and privacy concern.

    --
    -- javaDragon is an instance of JavaDragon.
    1. Re:It's far from being the ONLY identifier by J.+J.+Ramsey · · Score: 1

      > the latest version of windoz itself is subscription-based

      Nope. Windows XP is licensed in perpetuity. Now it may not be activatable in a few years . . .

    2. Re:It's far from being the ONLY identifier by Anonymous Coward · · Score: 0

      But all these aspects are quite variable.
      Only the GUID can be associated with a
      windows user license etc....

      Also IP's change on each connection (dialup).

      MAC address of a modem ? WTF

      GUID of WMP, hey we can match that to the
      windows reg no, wow !

  22. Holy shit! by I.T.R.A.R.K. · · Score: 1, Funny
    The devil is probably out buying a parka as we speak!

    I almost lost my Mountain Dew when I read that headline!

    --

    "Adequacy.org: Where congenital stupidity is not an option, but a requirement."

  23. Now windows is going to suck even more to use by Publicus · · Score: 3, Funny

    Hmmm, I think I'll go read slashdot today...

    It looks like you're trying to reach the internet, this is a potential security risk. Find out more about how your internet experience is made more secure with Microsoft by clicking "Find out more." If you wish to continue, click "Ok."

    Arrgh, *click ok* (stupid microsoft)

    Your computer has begun downloading information, this is a potential security risk. Find out more about how your internet experience is made more secure with Microsoft by clicking "Find out more." If you wish to continue, click "Ok."

    And so on!

    --

    My Karma was at 49, then they switched to words. All that work for nothing!

    1. Re:Now windows is going to suck even more to use by xinit · · Score: 1
      That will only happen if you try to access so-called "pinko commie" sites that endorse use of "heretical anti-american" software such as "LUNIX" or "Red Hats."

      So just back off, what are you, a Linus Lover? Damn commies. Everytime you click "Ok" another Microsoftie gets to vest their options.

      --
      --- http://foo.ca
  24. Define security by FrostedWheat · · Score: 1

    This is all fine and well ... but it really depends on what MS consider to be security problems.

    And will they fix security holes in older products? Probably not .. just give the old "To fix this problem we recommend upgrading". Which of course, isn't free :)

    This is why I like opensource so much ... even the oldest projects can be fixed!

    Anyway it's all probably only a PR stunt. Well soon find out I guess :)

  25. In the News by hyyx · · Score: 1

    As I am reading this discussion, I see the same story on the 10:00 news. The story ends with the line: "...to make users feel safe on the Internet," as they show boxes of Windows 98 Upgrade rolling down an assembly line. Yeah, I feel safe.

  26. Y'know... by Anonymous Coward · · Score: 2, Insightful

    ..."Trustworthy Computing". This sounds suspiciously like a buzzword-name for digital rights management, especially after that paper on making an OS that prevents anything unauthenticated from getting at secure content.

    Anyone else notice this?

  27. uh micheal? by jeffy124 · · Score: 2, Insightful

    m:
    the Globally Unique Identifier in every installation of Windows Media Player allows websites to universally track users, and Microsoft does not consider it a security problem.

    It's not a security problem to have a number assigned to you, it's a privacy problem.

    --
    The One Rule Of Chess You'll Ever Need: Don't play someone who carries a kit in their bookbag.
    1. Re:uh micheal? by hogsback · · Score: 1

      It's a security problem because the number is given out to people who shouldn't have it.
      Untrusted websites can easily get the number with some simple scripting.

      I have a social security number - this is neither a security or privacy problem because I look after it.

      ---
      Hogsback (078-05-1120)

    2. Re:uh micheal? by Graymalkin · · Score: 3, Insightful

      Websites with some simple scripting can also track you with cookies and static IP adresses. Neither of these methods needs any more software than your a browser on the client's end. Besides that, a GUID for Media Player has little effect other than to allow tracking of the computer it is installed on. Getting the GUID from WMP isn't going to get anyone access to any of your personal fucking information like a SS number is.

      --
      I'm a loner Dottie, a Rebel.
    3. Re:uh micheal? by Anonymous Coward · · Score: 0

      Even if someone is using a cookie blocker add-in, SuperCookies will still work.

      If a user has deleted cookies from his or her computer to stop tracking, a Web site can restore an old cookie value from this ID number. Once the cookie value has been restored, new tracking data can be combined with tracking data that was previously collected by the Web site.


      Actually, I consider the ability to restore information from my computer that I have removed, and the ability to circumvent my preferences to be a security issue.

    4. Re:uh micheal? by gleisner · · Score: 1

      It's not a privacy issue. A privacy issue is one where information about you is concerned. This is an authentication issue; who are you. You can either be authenticated or not.

  28. Microsoft must read Slashdot! by Com2Kid · · Score: 1

    Microsoft must read /.

    http://slashdot.org/article.pl?sid=02/01/16/1534 25 2&mode=thread

  29. Writing Secure Code by hogsback · · Score: 5, Interesting

    A couple of Microsoft's security people published a book - Writing Secure Code - recently.
    It's obviously Windows biased with respect to code samples, but it's actually very good.

    Now they just need to read it themselves - for example, all the vulnerabilities exploited by the universal plug and play fiasco (buffer overruns, trusting untrustworthy data and denial of service attacks) are well described in the book,

    1. Re:Writing Secure Code by theNeophile · · Score: 3, Troll
      A couple of Microsoft's security people published a book - Writing Secure Code - recently.

      Also coming soon from BitterIrony press:
      GNU's guide to user-frendly UI.
      The U.S. D.O.J.'s guide to speedy legal precedings.
      And:
      Larry Wall's guide to maintainable code.

    2. Re:Writing Secure Code by Anthracks · · Score: 1

      That was pretty funny stuff, if I had some lousy mod points I'd bump you up :) Anthracks

      --
      Rock over London, Rock on Chicago. Wheaties: Breakfast of Champions.
    3. Re:Writing Secure Code by cooldev · · Score: 5, Interesting

      To whet your appetite, a little excerpt from the beginning about how quickly machines get attacked:

      Surely, no one will discover a computer slipped onto the Internet, right? Think again. The Windows 2000 test site was found almost immediately, and here's how it happened... Someone was scanning the external IP addresses owned by Microsoft. That person found a new live IP address; obviously, a new computer had been set up. The person then probed various ports to see what ports were open, an activity commonly called port scanning. One such open port was port 80, so the person issued an HTTP HEAD request to see what the server was; it was an Internet IIS 5 server. However, IIS 5 had not shipped yet. Next the person loaded a Web browser and entered the server's IP address, noting that it was a test site sponsored by the Windows 2000 test team and that its DNS name was www.windows2000test.com. Finally the person posted a note on www.slashdot.org, and within a few hours the server was being probed and flooded with IP-level attacks.

    4. Re:Writing Secure Code by Jace+of+Fuse! · · Score: 1

      Now they just need to read it themselves

      Well, then it's obvious, the people at Microsoft who know how to write secure code have been writing books, not code. *snicker*

      --

      "Everything you know is wrong. (And stupid.)"

      Moderation Totals: Wrong=2, Stupid=3, Total=5.
    5. Re:Writing Secure Code by Anonymous Coward · · Score: 1, Funny

      GNU tools have user-friendly UIs. They take some time to get to know, but they're not shallow personalities which are all about lip gloss and initial appearance. Once you get to know them, they'll be your firend for life...

    6. Re:Writing Secure Code by osolemirnix · · Score: 1
      You mean like they have a book on human interface design guidelines too: Microsoft Windows User Experience

      It's actually a pretty good book. The problem just is that their own programmers mostly ignore it (read the chapter on consistency and then compare the behaviour of some of their major apps - grin).

      --

      Idempotent operation: Like MS software, wether you run it once or often, that doesn't make it any better.
    7. Re:Writing Secure Code by swb · · Score: 2

      Once you get to know them, they'll be your firend for life...

      Because you've spent your whole life learning them, it seems a shame to consider them anything but a friend.

    8. Re:Writing Secure Code by Sj0 · · Score: 3, Insightful

      Finally the person posted a note on www.slashdot.org, and within a few hours the server was being probed and flooded with IP-level attacks.

      Sounds bad. Does that make us hacker terrorists?

      --
      It's been a long time.
  30. But then... by I.T.R.A.R.K. · · Score: 0

    ...better late than never, right?

    --

    "Adequacy.org: Where congenital stupidity is not an option, but a requirement."

  31. Old story versus new story by SilentChris · · Score: 2, Informative

    How did this old story manage to make the front page of Slashdot when this new story with far greater implications didn't?

    1. Re:Old story versus new story by ZxCv · · Score: 2
      --

      Perl - $Just @when->$you ${thought} s/yn/tax/ &couldn\'t %get $worse;
  32. Freedom to Immolate??? by lan@panix.com · · Score: 1
    This follows some of the recommendations from Bruce Schneier's editorial dated yesterday. I give it even odds that this is release is real vs. someone hacking Microsoft's network and putting out a fake release or wire story.

    If real, it's good news, since MS products are a security nightmare.

    If fake, it's brilliant, since Gates will be faced with either admitting the breach and the unimportance of security or keeping quiet and being held to his new "highest priority".

    In any case it looks like this will get very interesting!

    1. Re:Freedom to Immolate??? by Anonymous Coward · · Score: 0

      False. Microsoft will for now fix security holes
      and remind us everytime they're being fixed. But figure
      within a year, they'll go back to not caring until
      a hole becomes public. In reality, nothing will change.

  33. Hhhmmm... by yamla · · Score: 4, Insightful
    Well, after all the ribbing, we have to give Microsoft some credit. There was no reason to believe that Windows XP actually was designed to be secure. Certainly, recent events have shown otherwise. But this really could be a change for the better.

    However, take a look at OpenBSD. They really are secure, or at least as secure as anyone can reasonably expect for an operating system. They have done a great job, but it takes time. A lot of time. OpenBSD was based on NetBSD, so security was always a priority, OpenBSD just made it more of a priority.

    But really... even if security really is job one now at Microsoft, we aren't going to see any concrete results in the near future. Forget Microsoft's next operating system. It is going to take years, not months, to get results. I mean, we are looking at 2006, likely, until Microsoft systems have a hope of being secure. Will Microsoft (would any corporation) invest that many years of development? Are their customers really demanding security?

    --

    Oceania has always been at war with Eastasia.
    1. Re:Hhhmmm... by Splork · · Score: 2

      openbsd is only secure if you don't install any third party software. after that, its not much better than any other bsd or linux flavor for server (non multi-user shell account) systems.

    2. Re:Hhhmmm... by Anonymous Coward · · Score: 0

      This part of the article is interesting:

      "Compensation plans of Microsoft product engineers, such as raises and bonuses, will also be tied to how secure their products are."

    3. Re:Hhhmmm... by guttentag · · Score: 2
      There was no reason to believe that Windows XP actually was designed to be secure.

      You mean, other than Microsoft's own insistence that:

      Windows XP has it all, along with unmatched dependablity [sic] and security.
    4. Re:Hhhmmm... by yamla · · Score: 2
      Actually, no, I was including Microsoft's own insistence. Show me even one person who believed XP would be more secure than OpenBSD. Come on, Microsoft issues PR releases for everything to do with security holes in their products.



      Hardly anyone really believed that Windows XP would be more secure than Windows 2000, at least the level that Win2k is at now and the level that Win XP is at now.

      --

      Oceania has always been at war with Eastasia.
    5. Re:Hhhmmm... by dimator · · Score: 1, Troll

      we have to give Microsoft [microsoft.com] some credit.

      Hey, thanks for that link to http://www.microsoft.com, I was not totally sure what their site was...

      By the way, if any of you have heard of that cool search engine called "Google" but you don't know where to find it, it's here: http://www.google.com

      --
      python -c "x='python -c %sx=%s; print x%%(chr(34),repr(x),chr(34))%s'; print x%(chr(34),repr(x),chr(34))"
    6. Re:Hhhmmm... by rbeattie · · Score: 2

      This is a bit offtopic, but it's a real question: Why are there still three BSDs? OpenBSD, FreeBSD and NetBSD? And if these are all open-source, why doesn't Linux benefit from their code and just implement their kernel (since, from what I understand BSD scales better than Linux). I can understand why there was Unix fragmentation before open source was common, but why now?

      And finally (back on topic) why EXACTLY is BSD more secure than other OSs (Windows, etc.) Does it automatically protect from buffer overruns or something?

      -Russ

      --
      Me
    7. Re:Hhhmmm... by Llywelyn · · Score: 1

      "There was no reason to believe that Windows XP actually was designed to be secure."

      Hmmmmmmm. So you are saying it is a feature, not a bug?

      --
      Integrate Keynote and LaTeX
    8. Re:Hhhmmm... by Anonymous Coward · · Score: 0

      The most obvious and likely result of a change in policy from convenience to security will mean things like IIS and UPnP will be disabled by default. Simple things like that will make an enormous difference in terms of overall security - they are dead simple to do, but require Uncle Bill telling everyone to do it. That's likely to be the result of this, not a huge focus on OpenBSD-like security.

      I mean, does OpenBSD provide a web browser or web server or any of the things like are considered part of the Windows operating system?

    9. Re:Hhhmmm... by Anonymous Coward · · Score: 0

      The 3 BSD's exist for 3 different reasons.

      FreeBSD -> A completely free Unix operating system
      NetBSD -> The most portable Unix operating system
      OpenBSD -> The most secure Unix operating system.

      Those are their different goals. Part of the growing problems with Linux operating systems is that they try to be everything at once, server, workstation, desktop, embedded, etc. It succeeds pretty damn well even at that, but inevitably, there will be shortcomings when you kinda throw everything together and mix it up. BSD's fragmentation is the cure for the disease that befalls more homogeneous operating systems like Linux.

      Is it good or bad? Who knows. It's a choice. OpenBSD hasn't had a rooter in the default install in a long time, so it's probably achieved its goal.

      Unix based systems (arguably) are more secure than Windows for a variety of reasons, but the main reason is that Unix has been a multiuser system for over 20 years since making the difficult shift from a time-sharing system (Multics) where everyone had access to everyone else's data. Security was unheard of in such environments. Over time, however, as Unix matured, there has been a lot of experience in the proper choices to make regarding design and pragma.

      Windows has been multiuser for about 7 years now. And NT didn't become massively popular until 4.0 went gold in 1996. So Unix has quite a large head start on Windows in terms of prior art, and was well prepared for the Internet explosion, with very few exceptions. Microsoft, however, being a johnny-come-lately, is making all the same mistakes that the Berkeley people did in the beginning, and they're going to continue to make them unless they start to think of security as a _core feature_ instead of as an afterthought.
      "Hey, it's ready to ship, did you poke at it and see if it breaks yet?"

      To answer your question, Unix by itself is no less susceptible to buffer overflows than MS is, as it's not Windows that causes the buffer overflows, it's bad code within Windows. (I believe I've read somewhere, however, that big-endian systems like Intel are more susceptible to overflows for some reason. Don't know if that is actually true or not.)

      Anyway, if Unix people wrote bad code all the time (cough sendmail, cough wu-ftpd, etc), there'd be a lot more action on the Unix side. But there isn't, because Unix programmers (and open source programmers in particular) tend to be quite a bit more meticulous about their work than the average MS programmer.

      Just my opinion, flame away

    10. Re:Hhhmmm... by sconeu · · Score: 2

      Just a note... Unix has been around for over *30* years, not just 20. Also, Unix is not derived from Multics, but Thompson and Ritchie came from that project, IIRC.

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    11. Re:Hhhmmm... by FFFish · · Score: 2

      Sure, here's some firestarter: how many patches did Microsoft release for its OS and core applications (MSIE, Office, Outlook, servers, etc); and how many were released for the BSD market; and how many for Linux?

      It'll be an interesting comparison.

      --

      --
      Don't like it? Respond with words, not karma.
    12. Re:Hhhmmm... by Sloppy · · Score: 2

      And finally (back on topic) why EXACTLY is BSD more secure than other OSs (Windows, etc.)

      In the case of OpenBSD, it seems to be due to the developer's priorities and values. Instead of adding lots of features (e.g. OpenBSD doesn't even have SMP yet!), Theo and friends have instead elected to spend their time actively seeking and destroying bugs.

      Does Microsoft even have a single person whose job is to, not develop their products, but read through source code looking for problems and imagining weaknesses and thinking of ways to attack it? Maybe there is such a person, but there doesn't seem to be any evidence of it.

      Development speed has something to do with it too. If OpenBSD were developed at the same speed as Windows and Linux, not only would the team have less time for debugging, but there would be more new code that would need it.

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    13. Re:Hhhmmm... by sydsavage · · Score: 1

      And finally (back on topic) why EXACTLY is BSD more secure than other OSs (Windows, etc.) Does it automatically protect from buffer overruns or something?

      It's OpenBSD the previous poster was referring to as more secure. It's more secure because the developers make security top priority. They accomplish this through an exetensive auditing process, pro-actively fixing bugs like buffer overruns, and the use of cryptography. They also follow a philosophy that all non-essential services are off by default, with the assumption that in the process of learning to turn something on, you are more likely to learn how to run it safely. But don't take my word for it, read more about it here.

    14. Re:Hhhmmm... by Anonymous Coward · · Score: 0


      Get a friggen grip, slashdot adds those brackets automagically since, oh, a few months now at least.

      Tool.

    15. Re:Hhhmmm... by Anonymous Coward · · Score: 0

      You're such a fucking moron. I suppose slashdot added the link to Microsoft by itself, huh? Thought so.

      Now get a brain, and STFU.

    16. Re:Hhhmmm... by shking · · Score: 1
      An OpenBSD motto, if you can call it that, is "Secure by default". One of most important things they do is to TURN THINGS OFF by default. Turning off everything except what's necessary is one of the fundamental things sysadmins will do to harden a machine. Most everyone else (especially Microsoft) leaves on all sorts of things they think you might find convenient. You need a very good sysadmin to competently harden most systems.

      The point is this: if you don't know what's running, you don't know where to watch

      --
      -- "At Microsoft, quality is job 1.1" -- PC Magazine, Nov. 1994
    17. Re:Hhhmmm... by Dahan · · Score: 1
      Heck, you don't even have to install third-party software--just enable the stuff that comes bundled with the system. E.g. lpd, ftpd, sshd (OpenSSH), dhclient, et cetera, et cetera...

      OpenBSD's just got good marketing... as you say, their security's on par with the other *BSDs and the better Linux distros.

    18. Re:Hhhmmm... by Paul+Komarek · · Score: 2

      In fact, the name "Unix" is something of a pun (Ritchie described it as a "somewhat treacherous pun" ;-) on Multics. They weren't supposed to build Unix, but Multics was just to darn big and complicated to be genuinely useful. So they went from Mul (bigness) to Un(i) (small). I think there were also political considerations when making an new operating system while you're supposed to be working on another.

      -Paul Komarek

    19. Re:Hhhmmm... by scrytch · · Score: 2

      > Why are there still three BSDs?

      Developer differences. First there was 386/BSD, which contained much that was architecture-specific, and this was seen as baleful and abhorrent to some developers, who founded NetBSD, which probably has a port to the abacus -- it's so portable it makes linux look about as portable as Win95. FreeBSD decided that performance and features were more useful than architectural purity, so they stuck with being architecture specific. OpenBSD spun off of NetBSD when its founder was drummed out of the group for being somewhat less cuddly than your average poisonous sea urchin. It tends to track more closely with FreeBSD these days.

      To this day, they still retain these focuses. If you want to learn OS design with neat theoretical underpinnings, you want NetBSD. If you want something fast and featureful, FreeBSD is for you, and if you want something that's been audited by some freakishly security-attentive reviewers, then the choice is OpenBSD.

      Personally I find three forks better than 233252635265246 various distributions

      --
      I've finally had it: until slashdot gets article moderation, I am not coming back.
    20. Re:Hhhmmm... by thrig · · Score: 2

      Look-at-the-numbers approach to "Why Open Source?"

      http://www.dwheeler.com/oss_fs_why.html

      You probably want the security section.

      http://www.dwheeler.com/oss_fs_why.html#security

    21. Re:Hhhmmm... by doug363 · · Score: 1
      ... that big-endian systems like Intel are more susceptible to overflows for some reason. Don't know if that is actually true or not.
      Actually it's not true. Intel (well, x86) systems are little endian :). I've seen a few people who seem to think that little endian is less logical than big-endian, though I really don't see why. Both big and little endian have their logic to them. I have a feeling it's mostly from people who hate Intel and all things x86, though, as most CPUs that aren't x86 are big-endian. Similarly, I really don't see why little endian systems are more suseptible to buffer overflows. You just have to remember to use htons() or htonl() if appropriate.
    22. Re:Hhhmmm... by Tony-A · · Score: 2

      (Multics) where everyone had access to everyone else's data
      Under controlled circumstances, only. Multics had better security than anything you are like to find now. Probably the only system where you would even consider putting the CIA and the KGB with sensitive data on the same mainframe.
      For buffer overflows, it's not the endianness, it's the Unix/C trick of null-terminated strings that allow strings to be handled by a 1-tuple instead of 3-tuples. It also applies to any storing that is done without bounds checking.
      You're very right about the significance of Unix being multi-user. The constant source of security issues are those complicated programs which must cross user boundaries. Microsoft Windows has the problem that Solitaire fundamentally has all the potential for damage as sendmail.

    23. Re:Hhhmmm... by Jebediah21 · · Score: 1

      Kinda reminds me of those people who type in www.randomwebsite.com in a search engine. Really, if you know the address why not just type it in? I am not making this up. Saw it happen while watching MetaSpy one day.

      --

      Everytime you look at porn a devil gets their horns.
    24. Re:Hhhmmm... by arkanes · · Score: 2

      I've done it more than a few times on accident :P Theres also legit reasons to do it, such as to find cached pages from the site or sites that link to the site.

    25. Re:Hhhmmm... by Anonymous Coward · · Score: 0

      Your computer is killing you

      So is the beef you eat, the air you breath and the water you drink...

      What is your point?

    26. Re:Hhhmmm... by weinerdog · · Score: 1

      Well, after all the ribbing, we have to give Microsoft [microsoft.com] some credit. There was no reason to believe that Windows XP actually was designed to be secure. Certainly, recent events have shown otherwise. But this really could be a change for the better.

      Microsoft gets no credit for making promises or stating intentions. If they actually deliver something, then we can credit them.

      Microsoft touted XP as its most secure Windows ever, and it has at least strongly implied that NT4's security was superior to that of Unix, especially Linux. Microsoft has always claimed to take security very seriously, and has always claimed that the current incarnation of Windows features state-of-the-art security and stability. Whether you call this marketing spin, telling the public what they want to hear, or lying, it doesn't bode well for Microsoft's latest claim.

      Microsoft's general solution to security problems is to tell people not to use a particular feature (like opening email attachments) rather than change its applications to reduce security threats. This way, it tries to eat its cake and have it. It says, "Windows is full of great features. It's also very secure, provided you don't use any of those great features."

      --
      There's no such thing as Scotchtoberfest!
    27. Re:Hhhmmm... by Cy+Guy · · Score: 1

      I just want to congratulate dimator for getting a post modded +5 Troll, truly an astounding and well earned moderation. To get it he would need to be modded up at least four times, to make up for the -1 of the Troll moderation.

      FYI to one of the AC responders to this post:
      the bracketed domain name can be turned on and off in your user preferences. Others might still see brackets for links you make, but you don't have to se them in the posts you are reading. I the feature was added as a counter-measure to the numerous links to goatse.cx that were labeled as something else, though at least one of those posters knows how to get Google's cache to to bring the same site, so I find the brackets of little personal use.

    28. Re:Hhhmmm... by Anonymous Coward · · Score: 0


      First, air and water aren't optional.

      The computer is not your friend. Every second you spend in front of computer is a second you're not doing something else. It's there to solely to suck the life from you, second by second.

      More specifically, slowly and surely, radiation, chemicals and electromagnetic forces are entering your body from this machine that you spend 15 hours a day with.

      Think about it...

      -R

    29. Re:Hhhmmm... by Anonymous Coward · · Score: 0

      > One of most important things they do is to TURN THINGS OFF by default.

      Have even ever installed OpenBSD? Out of the box, you have
      portmap and inetd enabled with 8-10 or so open ports.

      It is not that everyting is off, but only the things that they are sure have no problems are turned on.

    30. Re:Hhhmmm... by mpe · · Score: 2

      Most everyone else (especially Microsoft) leaves on all sorts of things they think you might find convenient.

      Including things which are virtually never used (except as backdoors for crackers.)

      You need a very good sysadmin to competently harden most systems.

      Especially when it isn't well documented which services are even there.

    31. Re:Hhhmmm... by dimator · · Score: 2

      What I'd really like to know is, why would anyone want to waste a mod point on marking a Funny post as Overrated; I'd like to hear the justification. Maybe if you don't think it's Funny, you just didn't get the joke, and you should find another post to promote instead of demote. Fucking moderators...

      --
      python -c "x='python -c %sx=%s; print x%%(chr(34),repr(x),chr(34))%s'; print x%(chr(34),repr(x),chr(34))"
  34. Hmmmm... Might Be... by scott_oooo · · Score: 1

    Bill G could be telling the truth. Windows is a more popular desktop and one big reason is that it is 'easier' to setup and use as a web browser and word processor for the "Johnny Lunchpail"s of the world.

    Since those common applications are pretty well matured, what else does he have to work on? Trying to force Apache out of the internet market by developing IIS? Not bloody likely.

  35. too late by Anonymous Coward · · Score: 0

    Hey bill, it's too late for you. MS messed up big time with security and it's too late for you.
    Nice try with your PR. ...sadly, most of the people will say " ... you see, MS are the most secure OS....security is important for them" .... Yeah, since Jan. 16 2002.

    install OS X...

  36. Actually an interesting announcement... by Steve+G+Swine · · Score: 4, Insightful

    Microsoft does have a pretty strong track record of hearing what their big customers want to buy, and then building it.

    I'm not surprised that they're hearing about security... and I won't be surprised if they find a way to build it.

    Hey, I'm just sayin'.

    --
    "Consider yourself a member of a virtual corporation with Mr. Torvalds as your Chief Executive Officer." - Linux Advocac
    1. Re:Actually an interesting announcement... by arfy · · Score: 1

      I think they're responding with PR, but trying to get decent security into their products after the fact will be a daunting task indeed. I suspect we'll see token efforts and lots of marketing and not much else: can you imagine the effort of adding the security their products would need to those bazillions of lines of code? Not to mention how unfriendly the product might seem to the privacy-invaders Microsoft has coddled to date with IE's defaults.

  37. About windows media.. by guacamole · · Score: 5, Informative
    Meanwhile, Richard Smith notes that the Globally Unique Identifier in every installation of Windows Media Player allows websites to universally track users, and Microsoft does not consider it a security problem.

    Right. This is not a security problem. This is a privacy issue.

    And speaking of which. Many of us have fixed IP addresses. Web sites already track our actions with cookies. Telcos sell information about us to anyone who wants to pay for it. Get over it. We have no privacy to begin with.

    1. Re:About windows media.. by blibbleblobble · · Score: 1

      Would you be interested in working on a P2P where a group of 20 friends can bounce HTTP requests through each others' IP addresses?

      Kinda' like the privacy-added browser the hackers were supposed to be working on last year, but with the lovely people from slashdot to help?

      Let me know, it's just an idea at the moment

    2. Re:About windows media.. by Anonymous Coward · · Score: 0

      Even if someone is using a cookie blocker add-in, SuperCookies will still work.

      If a user has deleted cookies from his or her computer to stop tracking, a Web site can restore an old cookie value from this ID number. Once the cookie value has been restored, new tracking data can be combined with tracking data that was previously collected by the Web site.


      No, this is a security issue. Providing a method for any old company to come and restore any old information to my computer regardless of the settings I have made or my efforts in blocking them goes beyond privacy.

    3. Re:About windows media.. by maxpublic · · Score: 1

      Get over it. We have no privacy to begin with.

      Nothing says "clueless college boy" like seeing the phrase "get over it". Ad nauseum. It ain't new, kid, and you aren't even close to original by repeating what ten thousand other idiot college boys have said before you.

      If you aren't a college boy...hey, it's time to stop wearing your baseball cap backwards. In the world of grownups you look like a moron. Both literally and figuratively.

      Max

      --
      My god carries a hammer. Your god died nailed to a tree. Any questions?
    4. Re:About windows media.. by 3.1415926535 · · Score: 1

      Not having any privacy is not something to just "get over". Or do you like being pushed around by large corporations?

  38. Re:That GUID on WMP? Yeah . . . by Rubbersoul · · Score: 2, Insightful

    You make a good point that it can be turned off, but how many "normal end users" of Microsoft products are going to know this. It is not you or I, or for that matter anyone on /. (for the most part ;}) that I am worried about here. It is the people that do not have the first clue about computers, or security, and think that AOL is the internet that I am concerned about with security issues such as this one (and the countless others).

    --
    man .sig
    No manual entry for .sig.
  39. Re:That GUID on WMP? Yeah . . . by Greg+Lindahl · · Score: 3, Informative


    Just because it's possible to fix the hole doesn't make it "Normal slashdot staff overreacting again." Not only does the original report contain the information for how you can turn off the ID, it makes some good arguments for why that isn't good enough.

    So no, not an overreaction at all.

  40. If.. by AnalogBoy · · Score: 5, Insightful

    If microsoft can, by some complex reorganization of their development and review process, make their code have the same, or less, incidence of critical issue as, say, Linux (I swear I didn't choose that just because its the godhead of this entire forum), What would we do?

    Honestly, and not trying to troll. What will everyone here do if microsoft ceases being the evil empire? What if they can pull this off, and find some middle ground with the government? I said before, in a much earlier post, that most religions have an antagonist; What happens if we lose ours? Will /. topics get more sensational?

    MS Press Release:
    "Microsoft released a patch today to save 15K of RAM in explorer.exe"

    Slashdot:
    Microsoft wasting gobs of memory for extra red-dot in windows logo.

    Personally, I say good for microsoft. Microsoft, right now, is an intergral part of so many organizations, and admittedly they have security problems; They could use the positive PR. They could also deal with less -unfounded sensationalism- nonsense from the peanut gallery (note, this does not mean the founded, intelligent, objective news items which from time to time may appear in the comments section.)

    Just my $0.02, Refundable with a $2.00 restocking fee.

    1. Re:If.. by Junta · · Score: 2, Insightful

      One point, even if they do produce reliable, secure code, doesn't mean they are no longer the evil empire, they are the evil empire with better stuff :) They are the evil empire because they want to control a lot more than they should, and while this is no different than most other businesses, they are much closer to success... But then again you probably already knew that, just didn't think about it... Of course, AOL-Time-Warner is at least as scary as MS, if not more so now, IMHO...

      --
      XML is like violence. If it doesn't solve the problem, use more.
    2. Re:If.. by AnalogBoy · · Score: 4, Flamebait

      AOL/TW is, IMHO, a bigger threat now. They control major gateways to information, and can readily manipulate news and, in turn, ideas. THATS danger.

      Objectiveness is key.

      (AOL-TW-Microsoft-Oracle-KrogerCorp: All your neeeds. Period. If we don't make it, you don't need it. Sit, and Vegitate.)

      thought of the day:
      Do you think for yourself, or do you just think you think for yourself?

    3. Re:If.. by vondo · · Score: 5, Insightful
      I find AOL/TW less scary than MS, at least on a personal level.

      Sure, I watch CNN. Maybe I pick up Time occasionally, but I'm aware of who they are and what they are doing. If I want to avoid their media conglomeration entirely, I can. And if I do, it doesn't affect me. (Of course it affects the society around me.)

      Maybe I don't hear the incessant ads for AOL on CNN, maybe I have to use a smaller ISP. I think I can live without those things.

      Microsoft, on the other hand, by trying to extend its monopolies, is targeting my ability to communicate with other people. I can choose not to run Powerpoint or Word, but if 90% of the people around me only speak that "language" I can't see what they're saying. I can choose not to run IE, but if I can't read half the web because of it, I've lost. If I choose not to use Window's Media Whatever-its-called, I might not be able to hear the music I want to. And of course if I choose to run Linux, I can't even choose not to use all these MS products.

      When this happens, I've not just lost out on being able to use MS's products, but on a larger part of my world.

      AOL/TW is trying to control the content. MS is trying to control the underlying language. I find MS's intrusions more threatening to my lifestyle.

    4. Re:If.. by Pussy+Is+Money · · Score: 5, Interesting
      Nice post.

      I think basically you are saying that when Windows' technical deficiencies disappear (which in itself makes the dubious presupposition that one size might fit all), there is no longer any reason why we should oppose them.

      This presupposes that such is the case right now; i.e. that we are opposing Microsoft because their code is supposedly so horrible.

      But that's bullshit. I have to admit I don't know myself where all the folklore of lousy Windows performance and lousy Windows stability came from. Sure their software can run slow. But have you looked at GNOME recently? And as for security, granted their track record is very bad. But at least they don't ship with telnet, right? Besides there is nothing like designing security for a piece of software that runs on 95% of the desktops in the world.

      So it's all relative. In any case, I'll tell you the real reason why we should oppose Microsoft: because whatever business you are in right now, if you're successfull, it will be Microsoft's business next week. That's why we need to oppose Microsoft.

      --
      Pushin' 'n dealin', shovin' 'n stealin'
    5. Re:If.. by mjh · · Score: 5, Insightful
      If microsoft can, by some complex reorganization of their development and review process, make their code have the same, or less, incidence of critical issue as, say, Linux ... What would we do?

      Declare victory. I think Linus once said, "If Microsoft starts producing good software, we've won."

      Personally, I think this is the goal: to get good software. I enjoy the fact that currently the best software around doesn't cost me any money to obtain. But I'm not going to maintain some sort of religious fanatacism about it. If better software comes along that costs money, I'll buy it.

      How many of you play only free games on your computers? Me either. I play Q3A or SimCity. I paid for them. Why? Because they're better than the free stuff. I'll pay for an OS too, if it's better than the free stuff.

      --
      Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
    6. Re:If.. by leshert · · Score: 1

      And as for security, granted [Microsoft's] track record is very bad. But at least they don't ship with telnet, right?

      Actually, Windows 2000 does ship with a telnet service, but it's not enabled by default.

    7. Re:If.. by FFFish · · Score: 1

      What really sucks is when you have to pay for an OS, because the apps you need are only available via that route. I'd love to use Linux... but it doesn't have the applications I need. :-(

      --

      --
      Don't like it? Respond with words, not karma.
    8. Re:If.. by Ian+Bicking · · Score: 2
      This is an important issue. For the Free Software movement, this does not that troubling -- if you value Linux (or, GNU/Linux) for the freedom it provides, then Microsoft is incidental. Microsoft's efforts are unlikely to substantially effect the quality of GNU/Linux -- they might manage to retard growth, but they cannot take anything away from us that we already have.

      For the Open Source movement, this could be deadly. The philosophical underpinning of Open Source is that it leads to a technically superior piece of software. If Microsoft were to create a technically superior product, then Open Source would really be something of a failure. And while you can make the (valid) argument that having the source available gives you more power over the product, and thus the product is intrinsically more powerful (well, empowering) -- MS can counter with its Shared Source, which provides no freedom, but does address this criticism from Open Source.

      Slashdot has generally sided with OSS in philosophy and terminology. Not surprising -- OSS is the weaker argument, the easier path to follow, and avoids offending anyone.

    9. Re:If.. by andrewski · · Score: 1

      "Just because you disagree with me does not make me a Troll, nor does it make my post Flamebait."

      Unless one happens to be a Moderator!!!!

      HA!!

    10. Re:If.. by Anonymous Coward · · Score: 0
      Personally, I say good for microsoft. Microsoft, right now, is an intergral part of so many organizations, and admittedly they have security problems; They could use the positive PR.


      Yes, if we would all care a little more about the big guy we could all come together to a common ground.
      Unfortunately, they have PR problems and have to iron them out no matter how much it costs, whether it be MSDN meetings or press releases. Haha, when I was there, how I loved when the sweaty bald guy says "developers" about 30 times in a row. It's so funny. I laughed along with the rest of my geeky friends. Who was that??
      The good news is they have 36 thousand million dollars in the bank!
      That's a lot a reassurance for me! I am sure we will see valid steps being taken, instead of media spin until it quiets down. Phew! Thanks is due the coders at Microsoft, I feel better already! You programmers are my brothers. Except for the fact that you like Outlook and use Office every day to send useless .DOC files that no one wants to read. Why don't you use .txt?
    11. Re:If.. by PotatoHead · · Score: 1

      Good question.

      Pretty hard to escape the evil empire moniker at this stage, for me at least.

      Being forced to use their products as they stand today is worse than being forced to use their potentially good products they might produce tomarrow given this change in vision, so in that respect we all might be a bit better off. Either way I would like to see this. It is what they should be doing.

      What incentive do they actually have to keep this up over the longer term? Lets say they perform for a couple of years and keep Linux at bay while eating up some more UNIX marketshare. Stockholders get hungry, some part of their market gets mature and they need to grow again.

      Given the tighter control they would have at that point, why not just release what is needed, then fix things later? Who is going to argue? Would things need to be goverment regulated, what happens to open code? Will it be legal to develop it? Kind of a dangerous road to travel right now --for both sides. I just don't see it happening.

      I am saying that we need alternatives, if only to keep MS somewhat honest. I also say that there is no one solution to computing that is going to make everyone happy at this stage. Maybe later, but not now. Forcing things is not going to help. Building a healthy marketplace that rewards innovation will help. Polishing up an old act will not in my book and for now this exactly what this is about. PR, nothing more, nothing less. They only care because they have lost some deals, not because it is the right thing to do.

      For me personally, the most 'evil' thing about this whole mess is the software as services model. Renting software that performs mature tasks really is just milking the cow one too many times. I am willing to pay for innovation, but not repackaging. Maybe there are those out there that would enjoy having a machine that basically runs by the month. I don't. It is important for both choices to be there however.

      So if they wise up a bit and improve security, great. We all win. But don't expect the evil empire stuff to go away totally because it is a business and control issue, not totally a code issue.

    12. Re:If.. by Rooktoven · · Score: 1

      Just because microsoft can pay enough people to troll slashdot and mod-up posts that praise microsoft for things they haven't done yet, doesn't mean they don't.

      --

      Acquiescence leads to obliteration
    13. Re:If.. by Sloppy · · Score: 2

      Not disagreeing with your main point, because you're right. But there's something I'll be happy to rant^H^H^H^Hexplain...

      I have to admit I don't know myself where all the folklore of lousy Windows performance and lousy Windows stability came from. Sure their software can run slow. But have you looked at GNOME recently?

      If you want to understand why Windows has a "folklore" of being slow, don't compare it to Gnome, because Gnome is just as bad. Instead, compare it to BeOS or QNX Neutrino. Even compare it to a ten year old Amiga. Then you'll understand why Windows slowness isn't really just folklore; it is a very tangible and real experience.

      I used an Amiga in the 1990s and when I had to go to work or client sites, I was appalled at the performance of Windows. People were actually waiting for their computers to do things. It got better right at the end of the 90s when the hardware speeds shot through the roof and finally overcame the software problems, but that doesn't make up for the dark decade that I saw, or the occasional incident where I have to use someone's machine that is "only" 200 MHz.

      The stability "folklore" is similar. When you compare NT 4 (I haven't tried 2000 or XP yet) or Windows 9x to, say, OS/2, it isn't folklore anymore. I've been using OS/2 at work from 1994 to present (this year (perhaps even this month) I will finally kiss it goodbye as I switch to Linux 2.2.x) in an office where everyone else was using Windows. And you know what? Those people reboot ten times as often as I do.

      I guess you just don't notice these things if you don't have anything good to compare it to, so it's easy to call it folklore, but it's not. I can understand why Linux users wouldn't notice that Windows is slow, but I'm surprised they wouldn't notice it's unstable. Oh well. End of rant.

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    14. Re:If.. by RedWizzard · · Score: 3
      What will everyone here do if microsoft ceases being the evil empire? What if they can pull this off, and find some middle ground with the government?
      We'll move on. I know some of you MS apologists think the majority of Slashdotters' hate of MS is irrational but it ain't. They earned it. But if they manage to change (and personally I don't think it'll happen until Gates is long gone and the culture he has fostered has changed considerably) we'll find a new target. After all IBM was the Evil Empire once.
    15. Re:If.. by evilpenguin · · Score: 3, Interesting

      I can't believe I'm falling into answering this, but what application do you need that you don't have? (Sincere question -- I write software; might be fun to fill in a gap).

      Unless, of course, this is the classic (I need "Word" because everyone else has "Word.") What amuses me about this is how quickly we forget. Just 7 years ago Word was the upstart. WordPerfect was the defacto standard. Word 6 was the first version of Word that wasn't a joke and Word95 was the first to make major inroads.

      An earlier post ask why Microsoft is so reviled. The simple answer is that they use a monopoly in systems to extend a monopoly in applications. At this point, Office is a monopoly in itself. They are positioning themselves to be the monopoly media platform, net service platform, etc.

      After seeing them do this enough times, you start to have Capt. Kirk's feelings about Klingons (be sure to add the excessively dramatic emphasis Shatner adds when you read this): "DON'T belive them! DON'T trust them!"

      I'll be very happy if I never have to do another thing in a Microsoft OS ever again. I don't right now. When people send me things in Word format, I politely inform them that I don't use Windows. I'll do the best I can with OpenOffice to read and use their stuff, but maybe they should consider using RTF or HTML, since these are open standards.

      Wow! Not only did I get dragged in by a troll (intended or not), but I slipped off into a rant! Why should I be any different frm the average slathering slashdotter...

    16. Re:If.. by Paul+Komarek · · Score: 4, Insightful

      Microsoft has a lot to overcome to stop being the Evil Empire. The problem is that there is nearly no good will, benefit of the doubt, or trust left for Microsoft. They've screwed everyone multiple times. That includes business partners, OEM customers, end-users, you-name-it.

      Ballmer said they have a "popularity bug". It's no bug, it's by their own design. They've earned their place in the hall of shame. They want to win everyting, regardless of what's good for the people around them. Some people call that "hardball", but I call it antisocial.

      The question, then, is why should we believe Microsoft is really going to change anything? Why isn't this just another publicity stunt? They've lied to everyone many times, including falsification of evidence in a US court of law. If Microsoft magically transfigured themselves into a perfect company today, it would still take many years before I would trust them.

      -Paul Komarek

    17. Re:If.. by Pussy+Is+Money · · Score: 1
      1990 is twelve years ago. BeOS wasn't around back then. Neither any kind of graphical QNX. The Amiga, yes, it was fast. But it relied heavily on custom ASICs for its speed, so this has little to do with OS speed. Also the Amiga OS lacked features such as virtual memory or a somewhat coherent UI (which Windows 3.1 got as early as 1992 in Windows). So twelve years ago, a heavily hardware assisted and very minimal OS was faster than Windows on low-end (to match the Ami pricepoint) PC hardware? I'm not convinced.

      Stability-wise, NT 3.51 was pretty good. It became a little worse IME with NT 4, but Windows 2000 was better again. Now before I'm quoted as saying "NT 3.51 is stable", that needs some qualifications. The NT series of Windows has always been relatively (more or less) stable, in the sense that it does not crash very often. The rub, however, is that Windows is still not very reliable, because you still need to reboot too often (which means you cannot very well run multiple services on a single machine, which in turn means more machines to take care of).

      OS/2 and QNX and perhaps BeOS may be slightly better than NT where it concerns the number of crashes, but this needs to be contrasted to the sheer number of devices and usage scenarios that are supported under NT.

      Finally even if OS/2 is vastly more stable than NT (which I do not think it is), then how much does that really win you on a platform so flakey as x86? Going with OS/2 is more costly than going with Windows because of network effects. While you are spending money, why not forget about x86 altogether and go for some nice IBM or Sun hardware?

      So it doesn't add up. The good old days were good. But Windows is better.

      --
      Pushin' 'n dealin', shovin' 'n stealin'
    18. Re:If.. by jedrek · · Score: 2

      I can't believe I'm falling into answering this, but what application do you need that you don't have? (Sincere question -- I write software; might be fun to fill in a gap).

      * Professional raster graphics package - GIMP doesn't cut it.
      * Professional vector graphics package - Corel Draw is a joke.
      * Sound editing program.
      * Sequencer.
      * Flash animation and programming package.

    19. Re:If.. by SacredNaCl · · Score: 1

      I wouldn't worry too much about that happening. One only needs use a trial of their internet service to see how ingrained in their philosophy security isn't. This is the same service which forces you to download scripts marked "not safe for scripting", cookies, for parts of their service information across domains, ....and on and on...

      This is the same company that took 5 years to fix a backdoor in their browser where the contents of your hard drive could be viewed (with ..or...without...file sharing being enabled), only to break it again with the next patch they released.

      The examples go on and on.

      I'll tell you what I believe: Some of these errors are unintentional. A great many others are intentional, and put it at the request of the people in charge, and their marketing partners.

      --
      Freedom is merely privilege extended unless enjoyed by one and all.
    20. Re:If.. by Sentry21 · · Score: 2

      Honestly, and not trying to troll. What will everyone here do if microsoft ceases being the evil empire?

      Hey hey hey, let's not get hasty here. They said they were going to stop shipping swiss cheese, not turn into a fairy godmother. Just because they're going to try to make software that isn't holier than the pope doesn't mean they're not going to screw you over, it just means that they and their corporate partners are going to have exclusive rights to do so.

      They'll still want to control every aspect of your life, track your movements, sell your children, monopolize your chequebook, and sell you out whenever there's a buck to be made, they just want to be your first choice for getting screwed, used, abused, and refused.

      --Dan

    21. Re:If.. by Anonymous Coward · · Score: 0

      "objectivity."

      "vegetate."

      thought of the day: do you think AT ALL?

    22. Re:If.. by Sentry21 · · Score: 1

      thought of the day:
      Do you think for yourself, or do you just think you think for yourself?


      Conversely, did you write that yourself, or did you hear it somewhere before? ;>

      --Dan

    23. Re:If.. by Tony-A · · Score: 2

      The thing to watch is diversity. If AOL/TW is a threat to such as CSPAN and PBS then it's time to be concerned. If senior management is convinced that diversity is a "Good Thing", particularly when it dissents from the "corporate view", there is less to be concerned about. Things like Turner Classic Movies. I don't know if it's run at a profit or a loss. I expect that Ted Turner doesn't even care much, as long as he can afford it.

    24. Re:If.. by GypC · · Score: 2

      Hmmm...

      slather (slthr)
      tr.v. Informal slathered, slathering, slathers
      To use or give great amounts of; lavish: slathered gifts and attention on their only child.

      To spread thickly: slather onions on the steak.
      To cover with something spread thickly: bagels slathered with cream cheese.

      n.
      Slang. A great amount. Often used in the plural: slathers of jewels.

      Interesting choice of words. Perhaps you meant slavering? Unless, of course, you were admitting that you were thickly layering on the bullshit...

    25. Re:If.. by ArhcAngel · · Score: 1

      "(AOL-TW-Microsoft-Oracle-KrogerCorp: All your neeeds. Period. If we don't make it, you don't need it. Sit, and Vegitate.) "

      This reminds me of a great nation some years back...... what was it called again?....Ah yes, I believe it was Rome. Except they called it bread and circuses

      --
      "A person is smart. People are dumb, panicky dangerous animals and you know it." - K
    26. Re:If.. by AnalogBoy · · Score: 2

      I pulled it out my head. How it got there, I don't know. I'd wager it isnt an original thought.

      To address one of the below posts, with a touch of classic wisdom and humor:

      "Anyone who can only think of one way to spell a word obviously lacks imagination." - Mark Twain

    27. Re:If.. by jeff13 · · Score: 1

      If I behaved as M$, I'd be in jail for the rest of my life. Defending criminals who have created chaos within a medium so beloved by a young generation is like saying you think Hitler would be OK if only he didn't kill all those Jews.

      You're a real moron you know that?

    28. Re:If.. by ethereal · · Score: 1

      I always heard that as "It's a damn poor mind that can only think of one way to spell a word." Not sure who to attribute that to, though.

      --

      Your right to not believe: Americans United for Separation of Church and

    29. Re:If.. by ethereal · · Score: 1

      I think in this case OSS might be off the hook, though - Microsoft has a giant war chest full of essentially ill-gotten gains. It's not fair to say that OSS has failed because it couldn't compete with an adversary who has almost unlimited funds for development. Nor does such a loss mean that OSS isn't still a better solution than most of the commercial software out there which doesn't come from giants such as Microsoft.

      --

      Your right to not believe: Americans United for Separation of Church and

    30. Re:If.. by FFFish · · Score: 1

      What he said, plus a professional page layout program. And TeX doesn't cut it: it's powerful, but a P.I.T.A. I want WYSIWYG.

      --

      --
      Don't like it? Respond with words, not karma.
    31. Re:If.. by mjh · · Score: 2
      I can't believe I'm falling into answering this, but what application do you need that you don't have?

      Perhaps you misunderstood my post. I use free software right now for just about everything. At work this isn't true, but on my own time and my own computers I use free software (in the RMS sense of the word) whenever I can. I do this because right now, the free software is better. There is some sense of using it because it's also morally correct, but that's not the primary driver. I use it because it's better. But I've bought non-free games. Why? Because they're better.

      If a non-free OS comes along that is better than what I'm currently using (Debian GNU/Linux) then I'll use it. By better, I mean that it does a better job of meeting my needs. I'm quite happy with free software right nowN (except for games) so I use it.

      Wow! Not only did I get dragged in by a troll (intended or not)

      I don't think my post was a troll. I said that free software, right now is better than non-free software. So the fact that I'm trying to meet my needs as best suits me, and the possibility that non-free software might meet my needs better, that makes my post a troll?

      I hope that you don't really believe that. Because then you're saying that free software is not really free. It's an edict. More than that, it's an edict that's above reproach. I'm not allowed to even think that non-free software might meet my needs more than anything in the free software world?

      Like I said, I hope you don't believe that.

      --
      Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
    32. Re:If.. by mjh · · Score: 2

      Whoops! It looks like you weren't responding to my post, but to someone elses. I didn't see that there was one stuck in there. Sorry for the harsh words. Thought you were talkin' to me.

      Move along folks. Nothing to see here. Just some idiot trying to gobble some crow. Go back to your homes.

      --
      Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
    33. Re:If.. by Anonymous Coward · · Score: 0

      Poor performance history comes from the millions of machines that roll off the line everyday that have less than optimal resources for the Win OS. Up until about 6-12 months ago, MOST low and middle level systems were dreadfully low on RAM. How many of us have used a Win 9x machine with 16 meg? Or even a whopping 32 meg? Nearly all of us and it is painfully slow. Not long ago I ran an experiment from my junk bin with a 64 and 128 meg ram, AMD k6-2 300 and dual HD's. OS, win98se.

      First install, default win98 at 300Mhz, 64 meg, single HD.

      Second Install:
      I underclocked the cpu to 100Mhz added 64 meg and second HD. Fresh install of win98, I then stripped the OS, of every cycle hog/memory resident crap and applied every tweak I know of, like putting the swap(permanent) on the outer tracks of the second HD on it's own controller channel, killing animation, multi partitions to keep the apps away from the OS, vcache tweaks, stripped the registry, etc, the list is endless. I will tell you however, that the base, stripped win98 partition, 1 gig was using about 155 meg. It started at nearly 400 meg.

      I did not run benchmarks, that was not the point. The experiment was in user perception of responsiveness. I let my wife try both configs without telling her what I did to it. She did not realize that it was now running at 100 Mhz. She said it felt faster than before. Windows Explorer popped up cleanly, menus snapped open, etc.

      Her end perception was that a highly optimized win98 at 100Mhz w/128 meg felt faster than a typical untweaked win98 install at 300 Mhz w/64 meg.

      CPU speed is nearly irrelevant in 99% of cases if the system has adequate resources and does not have to rely on VM tricks to provide functionality. Win 98 on a 1GHz PIII will suck dick with 64 meg of ram and a single HD. Typical udma 33/66 HD's can only sustain about 25 meg/sec across thier platters with a totally sequential file access. When your swapping for space and trying to load an app with any fragmentation, performance goes south in a hurry. The CPU speed cannot help that, and it is hanging around for millions of clock cycles waiting for data, PERIOD! Smallest data pipe in the plumbing problem.

      Windose stability. Well, that's another case. Win just has piss poor memory/FS management. Memory leaks galore, FS fragmentation and bundling user space apps into the kernel is just a DUMB thing to do. When you let a user space app like IE tie directly into the kernel you are going to have problems. There is no way to protect kernel space when common apps are part of it.

      So M$ has bought their own funeral from a stability standpoint. They want to bundle apps into the OS to maintain their monopoly. The tradeoff is instability. An OS is there to control the hardware and provide methods for user space apps to request servicing and nothing else. User space apps are there to let the human interact with the OS, and transparently to the hardware. YOU DON'T let a user space app control anything. If billy gates wants to dominate the world using this tactic of kernel/app bundling, then windows will always BSOD when a bundled app hickups.

      In a layered OS, GUI's, browers, media players, cd burners and rippers, etc are user apps. You can remove these things an the OS still functions. The tradeoff in layered OS's is perceived speed however because no user app can control it's own destiny. Commands like NICE in *nix can help with perceived speed/response.

      All my apps in Linux have a Nice value from startup. Interactive apps like a browser get more priority than number crunching like graphics apps. If I am rendering a large 3D scene, the render software runs in background Nice to +10, while the browsers runs at Nice +5. I keep the interactive feel while letting the render have any clock cycles I am not using. CD rippers and burners need near realtime priority, so they get nice 0. I want good rip's and burns, so I sacrifice the interactive feel in a brower when I do these things. My system handles massive app and ethernet load with mutliple users on remote xSessions with total grace. It has really killer hardware too(sarcasm). A cu celeron 566 with 192 meg of ram. A totally stock Dell gx100($359) with an extra 128 meg of ram. 4 Users(3 remote) at once all running different apps and it keeps on chugging. Oh, and lets not forget the OS cost me 24 bucks. Try that with XP on the same hardware. XP just running itself on a 700Mhz celeron with 128 meg seems rather dogged out to me.

      Gnome and KDE can be perceived as performance killers because they are nothing but a user space app and no matter what these apps need, the kernel is still only letting them have their fair share of time slices. Linux newbies tend to let everything run at nice 0. A cycle hog will have just as much priority as the mouse driver and you get stutters. Try running setiathome at default nice 0. The system runs like crap. MP3's skip, mouse jumps, etc. Nice it to +19, the system runs perfectly and seti still uses 99.9% of clock cycles. KDE/Gnome cannot get the advantage that a Win GUI has of being tied into the OS unless KDE/Gnome decides to release their own special version of Linux that accomplishes this. No one would buy it either.

      MHO in the end, Linux is vastly superior to Windose, however, as any OS, it can be misconfigured or in most cases not optimized for the users use patterns and desires. The Linux advantage is in flexibilty of Configuration. Try to build a LAN firewall with Win XP on a 486. Try to build a http server with Win98 on a pentium 100. Try to build anything on Win3.x.

      This was long, so
      That's my $1.29 worth.

    34. Re:If.. by weinerdog · · Score: 1

      Honestly, and not trying to troll. What will everyone here do if microsoft ceases being the evil empire? What if they can pull this off, and find some middle ground with the government? I said before, in a much earlier post, that most religions have an antagonist; What happens if we lose ours? Will /. topics get more sensational?

      Microsoft isn't the Evil Empire because it makes bad software. It has earned this monicker because of the way it systematically and inexorably crushes alternatives, restricts choice, invades privacy, treats its own customers as borderline kleptomaniacs, and makes pronouncements about what is good for us, rather than taking the time to find out what we really want. When the day comes that Microsoft gives us more *meaningful* choices than it takes away, then it will stop being the Empire.

      The fact that its software is usually (though not always) significantly behind the state of the art just rubs salt in the wound.

      --
      There's no such thing as Scotchtoberfest!
    35. Re:If.. by flez · · Score: 1

      I can't believe I'm falling into answering this, but what application do you need that you don't have? (Sincere question -- I write software; might be fun to fill in a gap).

      Dude, it goes beyond just the 'Office' products. Those are about the ONLY things you can find replacements for in Linux.
      I can't run linux at home anymore 'cause the GF uses my computer for her VPN to administer an NT Interwoven shop. Java script rarely works correctly, even in Konq. Games are scarce. When in Linux, she can't do about 50% of what she needs to do. I used the Gimp when I was in Linux, but always went back to Photoshop to finish the job. Now I boot over to Linux, about once a month when I'm bored and just want to tinker.

    36. Re:If.. by maxpublic · · Score: 1

      Well, I suppose if you're a complete fuckwit you just might think that Windows is stable and secure. Or that the stability/security in any way compares to Linux. But this presupposes the 'fuckwit' premise, which pretty much invalidates any observation you might claim.

      Of course, an apologist, Microsoft employee masquerading as a slashdotter, or a BillyG "I want to blow the Big Geek" fanatic would deliberately make false claims for a variety of reasons. An asshole, on the other hand (say, some 19-year-old loser with the handle "pussy is money"), might do so just because they're arrogant little twits with no practical, real-world experience in the industry servicing Windows and Linux machines year after year. Those of us who do have experience with thousands of machines over a decade or so would laugh our asses off at the claim that that Microsoft doesn't write shitty, buggy software as a matter of course, and that in terms of stability and security any OS they put out couldn't hope to compare to Linux.

      Hey, but when do real-world facts and experiences ever bother assholes? Especially young assholes?

      What's really funny is that there are enough MS employees moderating on slashdot at the moment that you were jacked up to a score of '5'.

      Max

      --
      My god carries a hammer. Your god died nailed to a tree. Any questions?
    37. Re:If.. by Bert64 · · Score: 1

      Well, windows and macos didn`t have virtual memory initially, and amigaos did support it via an addon when running hardware which was capable of handling it (no mmu on the lower end m68k cpu`s) However, you shouldn`t need virtual memory on a general purpose desktop machine, many amiga users ran just fine for years without, sure you could turn it on.. but the performance loss when it started swapping was just unacceptible. Same for windows 3.1, if you disabled swap.. the whole system ran a LOT faster.
      The custom hardware in the amiga was aimed at games primarily.. but it did provide some graphical acceleration to the os layer, much in the same way as most modern display cards do, There were amiga "clones" such as the Draco.. which ran amigaos, but contained none of the custom hardware. The OS and programs under it ran fine, but it was useless for games, which mostly program the hardware directly.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    38. Re:If.. by Pussy+Is+Money · · Score: 1

      Maxpublic, I will remember you as an argument in favour of euthanasia.

      --
      Pushin' 'n dealin', shovin' 'n stealin'
    39. Re:If.. by evilpenguin · · Score: 2

      Nope. I meant slathering. As in slathering on the BS. Just as you suggest. I post on slashdot from time to time. But the S/N ratio overall is poor. Nor do I suggest that mys posts raise it any. I was asking a sincere question: What does Linux lack? I was looking for a sincere answer. To the person originally posting, it looks like what is lacking is multimedia applications. For raster graphics, I've not tried anything that I couldn't do with the GIMP, but then, I'd hardly claim to be a graphics guru. For vector graphics; I've never done any -- can't speak to it (well, a little bit of povray, but just playing). For sound editors and sequencers, they exist, but I'll admit they're difficult and crude at this time. As for flash/shockwave tools, you can't expect open source tools for closed, patent protected non-standard technologies.

      I do have something of an exclusive attitude towards open source, in that I believe people are using the combination of perfectly sound intellectual property law (I've got nothing inherently against patents or copyrights) and the fact that compilation is tanatmount to encryption (data is provably lost in compilation; especially in compilers with optomization) to create an artificial shortage of technique. This creates an artifically inflated market.

      The true open market doesn't depend on secrets. You can take apart a car engine to see how it works. You can then try to use this knowledge to make an engine of your own. You can't do that with software. I think you should be able to.

      To argue the other side, I do think you should be able to copyright your code so people can directly steal pieces of it. The GPL itself uses this legal principle. You should be able to patent truly unique and novel inventions (my complaint with patents these days is patents are being given out on what I would consider non-novel ideas -- that's a problem with the process, not the principle).

      Aside; Why are these so many people who think they are the only souls with a dictionary? Try this one:

      pedant
      Pronunciation: 'pe-d&nt
      Function: noun
      Etymology: Middle French, from Italian pedante
      Date: 1588
      1 obsolete : a male schoolteacher
      2 a : one who makes a show of knowledge b : one who is unimaginative or who unduly emphasizes minutiae in the presentation or use of knowledge c : a formalist or precisionist in teaching

    40. Re:If.. by GypC · · Score: 2

      Ha ha. Touche'.

    41. Re:If.. by evilpenguin · · Score: 1

      And if anyone actually cares, I, of course meant "you should be able to copyright your code so people can't directly steal pieces of it."

      So I can't type...

  41. And I'm going to focus on making a trillion bucks by nate.sammons · · Score: 1

    ... but there's no way either plan is going to get anywhere.

    -nate

  42. Some how i dont belive it. by BenTheDewpendent · · Score: 1
    Bill Gates announced to employees Wednesday a major strategy shift across all its products to emphasize security and privacy

    Windows Media Player allows websites to universally track users, and Microsoft does not consider it a security problem.

    it may not be a security problem but a privacy problem...

    MS foot in mouth again? didnt they try security already... this could be interesting.

  43. this is a good thing by smash · · Score: 2, Interesting
    Don't get me wrong, I'm no fan of Microsoft, however concentrating on security will have other benefits - the auditing their code will receive will likely fix many stability problems as well.

    Other than security problems and product activation, I have to admit, that XP is actually a nice product. I may not agree with a number of its design decisions (stuffing things into kernel space that don't need to be there, building the GUI into the kernel, Microsoft ASCII text,etc), but it IS very feature complete for the average end user.

    I still won't run it by choice (FreeBSD baybeee), but having to *support* the platform will be a lot less hassle...

    just my US0.01c (damn pathetic aussie dollar...)

    smash

    --
    I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
  44. How to get the word out by maggard · · Score: 1, Troll
    Ironically half of the reporters recieving this email couldn't read it as their Outlook SP2 had declared the attachment potentially unsafe (unlike the official MS formats riddled with problems) and so wouldn't release it to them. The other half of the reporters found their copies already infected when Outlook promptly ran them and began sending out more infected copies to everyone in their address books.

    Luckly a kind 14 year old took pity, broke into one of their Hotmail accounts and resent a plain text version to eveyone.

    --
    I don't read ACs: If a post isn't worth so much as a nom de plume to its author then I wont bother either.
    1. Re:How to get the word out by irony+nazi · · Score: 0
      That's not ironic. Actually, it just sounds stupid.

      Sorry maggard... maybe you should just go to bed and get some extra sleep for tommorrow. It's been a rough day, hasn't it?

      --

      Bringing irony to the Slash-masses
    2. Re:How to get the word out by p3d0 · · Score: 1
      Anonymous Cowards filtered. If their words aren't worth so much as a nom de plume why should I value them any more?
      Does anonymity always make an opinion worthless? Do you believe in secret-ballot elections? Isn't it beneficial to allow people to express controvercial opinions with no threat of repercussion?
      --
      Patrick Doyle
      I mod down every jackass who puts his moderation policy in his sig. Oh, wait a sec....
    3. Re:How to get the word out by Anonymous Coward · · Score: 0

      The reason is most probably that he thinks he's special because he logs in and we don't.

  45. Is this like internet day? by vondo · · Score: 5, Funny

    Is this in the same vein as the day Bill Gates ordered everyone at MS to stop what they were working on and concentrate on how the Internet would affect their products?

    Of course, by that I mean Microsoft finally understanding something several years after the rest of the world "gets it?"

    1. Re:Is this like internet day? by tswinzig · · Score: 2

      Of course, by that I mean Microsoft finally understanding something several years after the rest of the world "gets it?"

      Your jibe would carry more weight if only you could surf the internet without using Microsoft internet software in some way, be it a browser, streaming media format, or web server.

      Microsoft, like any huge company, is often late in 'getting something.' But once they do, they have a remarkable ability to use their [monopoly] power to dominate in that area later.

      --

      "And like that ... he's gone."
    2. Re:Is this like internet day? by vondo · · Score: 1
      Your jibe would carry more weight if only you could surf the internet without using Microsoft internet software in some way, be it a browser, streaming media format, or web server.

      Hardly. For one, I do exactly what you say. Microsoft has, as you say, used their monopoly power to dominate the net. And, of course, they've done a great deal to popularize it too. Would the .com explosion have happened without them? Maybe, we'll never know.

      However, they haven't innovated anything:

      Browsers? First there was Mosaic, then Netscape, then IE.

      Streaming? First there was Real, then Windows Media Player

      Servers? First there was NCSA and Apache, then IIS. (And here Apache and to a lesser extent Unix (not Windows) play a more important role than MS products in providing the internet "experience.")

      Java and Javascript? Again, not MS innovations.

    3. Re:Is this like internet day? by tswinzig · · Score: 2

      Hardly. For one, I do exactly what you say.

      You do? You don't visit any sites that use Microsoft IIS for their webserver software?

      As for the rest of your argument, I never said they innovated. Just dominated.

      --

      "And like that ... he's gone."
    4. Re:Is this like internet day? by jslag · · Score: 1
      You do? You don't visit any sites that use Microsoft IIS for their webserver software?


      Is this really so hard to imagine? Maybe 10% of the sites I visit repeatedly run IIS at some point or another (I'm thinking Ebay's frontend), so it's not hard at all to imagine that someone else might not visit any IIS sites.

    5. Re:Is this like internet day? by Rooktoven · · Score: 1

      I get the idea that it's not a matter of not getting it, but rather noticing that profits could be affected.

      Does anyone doubt that microsoft sees nothing as a problem unless it affects their bottom line?

      --

      Acquiescence leads to obliteration
  46. Example #1 by arothstein · · Score: 0, Funny
    int passcheck(void)
    {
    char username[8];
    char pass[8];

    fprintf(stdout,"enter username (8 char max please, otherwise you might corrupt the stack): ");
    fscanf(stdin,"%s ",username);

    if (strncmp(username,pass) != 3) return 1;

    }

  47. privacy? by Anonymous Coward · · Score: 0

    privacy, like .net??? My wallet? Sounds good!

  48. It a press release! by DAldredge · · Score: 1

    All they did is issue a press release!

  49. They're serious about fighting Open Source by eric434 · · Score: 3, Insightful

    They're doing their best to attack open source; from buying SGI patents to kill OpenGL to this new intitiative to cut off the age-old argument that open source is more secure (at least on the PR front...) and all the rest. I guess they really do see open source as the number one threat...

    What I really hate to see, however, is that we're not doing too much about it. In fact, the only new thing is Lindows, and I sincerely hope they live up to the hype. Unfortunately, Microsoft has realized that Joe Average Consumer *dosen't care* about anything that is not the easiest way to go; even in the server market the PHBs will stick to MS until they see something like the Gartner Report or the FBI declaring Windows XP to be insecure (or whatever).

    IMHO, a good part of the Open Source world needs to focus on making Linux a real competitor on the desktop market; such as idiot-proof install programs that need *NO KNOWLEDGE OF PARTITIONING* (and just ask, "do you want to install Linux on separate hard drive, or should I resize your Windows partition to X gigabytes and install it on this hard drive) and autodetect hardware (X Windows configuration is a *REAL* pain in the derriere if you don't know much, if anything about computers, for example) and whatnot. In order for Linux to be a real competitor for the computer of Joe AOLuser, it should take advantage of almost (or as much or more) autodetection/idiot proof default settings as Windows.

    Now I know, I know, we aren't after Joe AOLuser, but in order for manufacturers to keep making Open-Source compatible hardware, THEY NEED MARKET DEMAND. It's far easier to cave in to Microsoft if it means losing 5% of sales (to hardcore geeks) than if it means losing 50% of sales (to Joe Average User). And yes, I just pulled those figures out of my hat, but I wouldn't be surprised if they were true.

    --
    This .sig temporary until a better .sig can be constructed.
    1. Re:They're serious about fighting Open Source by ZxCv · · Score: 4, Informative

      Last time I installed Mandrake 8.1, it automatically partitioned my drive, and auto-detected and properly configured every piece of hardware in my laptop (including my 802.11b card). There are still applications out there that could use some usability enhancements, but the major obstacle (installation) is pretty much out of the way. The only thing Linux needs to be a true competitor on the desktop is applications. These days, the desktop-oriented Linux distros are just as easy, if not easier, to install as Windows. It is the lack of applications that is holding back any progress Linux might make on the desktop.

      --

      Perl - $Just @when->$you ${thought} s/yn/tax/ &couldn\'t %get $worse;
    2. Re:They're serious about fighting Open Source by eric434 · · Score: 1

      True, Mandrake is the *only* distro I've seen that does that. Unfortunately, I never got a chance to do anything with it since it screwed up so badly configuring X for my dual-head system that it was unusable(I couldn't even get to a text console) and I slapped an old copy of SuSE 7.1 on it and am making do with one monitor. Of course, *very* few people use Dual-head, so I guess I can't gripe too loudly. But for any OS that's been around this long, these issues should be *long* fixed. Oh well...

      (I think I should shut up now. The mods seem to be rather sensitive of anything vaguely like Linux-bashing; my original comment has already been marked as a Troll.)

      --
      This .sig temporary until a better .sig can be constructed.
    3. Re:They're serious about fighting Open Source by FastT · · Score: 2

      Lay off the crack before posting, please. No Linux distro I've seen is anywhere near the ease of use of Microsoft products. Fine, installation may be easy, but you only do that once, then Grandma has to use the thing day in, day out. What apps there are generally suck in terms of usability; there're no desktop standards; etc., on and on. Please don't do a disservice to Linux by saying the work is already done in making it ready for the desktop--the work has barely begun.

      --

      The only certainty is entropy.
    4. Re:They're serious about fighting Open Source by ZxCv · · Score: 2

      No crack here, though you've obviously been tokin' it up a bit lately.

      I never once said that it was completely ready for the desktop. In fact, I said the same thing you did-- that is is badly lacking in useable applications. The *only* thing I did say was that the part of Linux that was once considered the obstacle to its adoption--the installation--has pretty much been tackled. No, not all distros are as easy to install as everyone would like, and yes, even the easiest ones to install can stand a few more refinements, but compared with the install processes of past distros, its a major step. Now that the major obstacle to further Linux adoption seems to be a truly useable desktop, the work needs to focused on creating one.

      Which is essentially what I said the first time. You oughta lay off the crack and perhaps read the post a little closer before hitting Reply next time.

      --

      Perl - $Just @when->$you ${thought} s/yn/tax/ &couldn\'t %get $worse;
    5. Re:They're serious about fighting Open Source by FastT · · Score: 2
      I understood your original point as exactly what you said below. If you meant something less sweeping--and I hope you did--don't blame me for reading this quote and going off:
      ...the major obstacle (installation) is pretty much out of the way. The only thing Linux needs to be a true competitor on the desktop is applications.
      First, I'm shocked to hear you or anyone else claim that installation is or ever was considered the major barrier to adoption to Linux on the desktop. Installation is/was one barrier, but it's just one part. The desktop is far more than installation, and more than applications that use the desktop. It's a usability pardigm that programs adopt; it's all the glue that underlies the user's experience with the computer. It's where and how files are stored and identified. It's how the user configures the machine and works with the hardware. It's how the user thinks when using the machine. It's a consistent vision of what the machine/OS/application union is.

      Great, installation is out of the way, but there's so much more to do, and it's beyond just a little tweaking here and there. Contrary to some opinions, the UNIX/Linux way of doing things is not easy compared to the Windows or Mac way of doing things. Despite the fact that these OS's and computers in general are unintuitive, Linux is definitely even less intuitive.

      For example, how does improved installation address the mounting of a Zip drive or the addition of other hardware (all this after initial installation)? How does it help users manage files, or understand what a man page or a command line is, or any of those other things that Linux/UNIX users are comfortable with, but the average user isn't? How do you explain why the user shouldn't be logged in as root, or what the conventions of the UNIX filesystem are, or what they're for? How does a user install and configure the latest version of Quake to run with his badass new video card? I guarantee it's nowhere near as easy as running a Windows or Mac installer and just double-clicking the icon on the desktop.

      I think you must be grossly overestimating the the sophistication of the average computer user to think that these sorts of things are below the level of user consciousness, and that any issues in these areas disappear because the user has usable apps. It's almost the opposite--these are the things that are foremost in user's minds, before they ever get into an app. The rest follows after.

      In the end, if the user has to do anything besides live entirely inside a single application that's always running, Linux is NOT ready for the desktop. I mean, this should be obvious, just put them side by side. Mac OSX is the only viable desktop UNIX around, and Linux in my wet dreams isn't even close to that.

      I'm all on board with the improvements in installation you've described, but that's...that's just not nearly enough to support your premise that given some usable apps, everyone could be running Linux on the desktop. I'm all for being a fan of Linux, but that's just too much to swallow.

      --

      The only certainty is entropy.
  50. Could this be the death of Linux?? by eggstasy · · Score: 2, Funny

    Oh my God, if Billy actually means what he says, what are we going to do now? We've always had a major advantage in security and stability with Linux. Our arguments have always been based on the fact that M$ windoze is a bloated hacker haven.
    Linux and the open source movemnet will most certainly never die, but I would really like to see a day where mom, pop and granny all used Linux, most games and popular software ran natively on it, and windows was a weird "fringe" thing like Macs.
    I honestly believed we could pull it off in 5 years, 10 tops. But with the full resources of a gigantic monopoly turned to focus on what has always been our strong point, dear lord, what are we going to do now???
    Worse than that, what if ole Billy also decides to make it a lot faster? What if the deepest pockets in the world turn to actually making windows a decent OS?

    1. Re:Could this be the death of Linux?? by Legion303 · · Score: 2
      Our arguments have always been based on the fact that M$ windoze is a bloated hacker haven.

      I know plenty of bloated hackers who run linux.

      Worse than that, what if ole Billy also decides to make it a lot faster? What if the deepest pockets in the world turn to actually making windows a decent OS?

      Then I'd start using it. Linux is best suited for servers. That may change in the near future, but for now Windows has the desktop market and isn't going anywhere soon. If MS actually does manage to improve Windows security and stability, the end-users can only benefit.

      -Legion

    2. Re:Could this be the death of Linux?? by smash · · Score: 1
      Worse than that, what if ole Billy also decides to make it a lot faster? What if the deepest pockets in the world turn to actually making windows a decent OS?


      then, if it is appropriate for what I want to do, I'll use it :P


      Use the correct tool for the job...


      the only worry i have is with hardware manufacturers - they should provide example pseudo code for controlling their hardware at a reasonable cost (if not free with hw purchase) ... but thats another issue.


      smash

      --
      I run: Windows, OS X, Linux, FreeBSD. Just because you have a hammer, doesn't mean everything is a nail.
    3. Re:Could this be the death of Linux?? by barole · · Score: 1
      For me as a sometimes-windows, sometimes-linux, sometime-unix user, what makes me dislike windows is not just the security aspects.

      First, as others have said is the potential for spying in closed-source software compounded by their questionable reputation for caring about the consumer. Maybe they spy, maybe they don't, but I have no way of knowing.

      However, I am one of those people who doesn't like the windows environment. I have used unix for many years and prefer the command line (with a good shell - I personally like tcsh).

      I don't like the fact that microsoft does not adhere to common standards. I like ascii text files, portable API's, etc.

      So, in short there are many things I don't like about windows. If they fixed all the security problems, I still wouldn't enjoy using it.

    4. Re:Could this be the death of Linux?? by Anonymous Coward · · Score: 0

      You also like little boys! Get a life you perverted homo.

  51. Thoughts by cascino · · Score: 5, Interesting

    First of all, it truly scares me that Bill Gates's announcement that Microsoft will "empasize security and privacy over new capabilities" is considered, in his own words, to be "a major strategy shift." Any reasonable developer knows that security is an inherent part of every feature - not a feature in itself.
    Second of all, it can't be said that this is the first time a company has put forth a gung-ho effort (if that is even the case) to secure their products - Oracle's Unbreakable database is clear evidence of this. To me, this seems Microsoft has placed itself further into the security spotlight, and that more holes will be exposed as a result.
    Finally, above all else, one has to admit that this announcement seems like the reactionary brainchild of Microsoft's PR department. On /. alone, this is the third article in 24 hours (not including the "Unbreakable" story) with direct relevance to Microsoft's security (or lack thereof). The case can be made that there is a low likelyhood that Microsoft would pay that much attention to the /. community - but on the other hand, I'd think they'd listen to this.

    1. Re:Thoughts by aka-ed · · Score: 2
      One reason MS may be making these noises right now is their commitment to produce a "slim" version of their current OS. Roped into this by the anti-trust settlement, any excuse to delay this can help prevent too much damage to XP's market saturation.

      OTOH, a slim XP that's been rbuilt with security in mind may actually be kinda schweet.

      --
      I survived the Dick Cheney Presidency 7 to 9 AM 7-21-07
  52. I can see it now... by Tadster · · Score: 2, Funny
    Your Microsoft Windows XP has detected a security violation

    A)bort R)etry I)gnore

    =tad=

    1. Re:I can see it now... by *xpenguin* · · Score: 1

      i always thought it was:
      Abo(R)t (R)etry Igno(R)e

  53. hahaha by xg0blin · · Score: 1

    microsoft = security, that's a better one than military = intellegence. A new oxy moron to add to the list.

  54. Security risk? by Speare · · Score: 4, Insightful

    Meanwhile, Richard Smith notes that the Globally Unique Identifier in every installation of Windows Media Player allows websites to universally track users, and Microsoft does not consider it a security problem.

    It's not a security problem. It's a privacy problem.

    If it posted the user's passwords, executed arbitrary code, or removed network firewall configurations, then it would be a security problem.

    --
    [ .sig file not found ]
    1. Re:Security risk? by informer · · Score: 1

      What does security attempt to do? Keep private information out of the hands of unauthorized people?

      Well probably most people wish to guard information about their browsing habits?

      I think there is a fine line here and I would say it is at least very close to a security problem!

      - Adam

      --

      If a penguin dies in the woods, and nobody is around to hear it, what sound does it make?
    2. Re:Security risk? by dbarclay10 · · Score: 2

      (With respect to the Globally Unique Identifier in MS Media Player to allow tracking a user):

      It's not a security problem. It's a privacy problem.

      Well, three things. Firstly, I more or less agree with you. At least, that's just my opinion. However, the statement you made is highly subjective.

      Secondly, I bet you ask "Why?" :) Well, for many people, having their photo ID card lost or stolen is considered a "security" issue. Heck, look at it this way. Somebody identifies you by name and address. Now they can sell that information and flood your mail box with spam and leaflets. An attack of sorts, really. So it *can* be considered a security issue, and will be by some.

      Thirdly, we really have no idea what somebody could do with this. What if they can associate one of these UIDs with a hotmail account? There are obviously a number of holes in hotmail that have yet to be reported ... etc., etc..

      Okay, I'm a bit sleepy .. if what I said didn't make much sense, then ignore it ;)

      --

      Barclay family motto:
      Aut agere aut mori.
      (Either action or death.)
    3. Re:Security risk? by jayed_99 · · Score: 3, Insightful

      You're thinking about "computer security" (passwords, arbitrary code, etc) which is a subset of "information security".

      Information security is the protection and preservation of any data/information about or in the possession of an organization. One way you protect your information is through good "computer security". However, good IT security departments are also concerned with (among other things) backups, contacts with law enforcement and press agencies and legal issues. None of which appear to fall into your definition of security.

      It is common for system administrators and developers to view "security" in the context of "computer security." Paranoid IT security trolls [TM] usually adhere to the second view.

      Privacy is also a subset of information security -- think about the relationship between privacy, information and social engineering for a minute.

      I'm not saying that in this particular case that this privacy breach is an invitation to massive social engineering. I am saying that privacy issues are security issues.

    4. Re:Security risk? by Publicus · · Score: 1

      For a lot of users, a breach of privacy is a breach of security. I do desktop support, and I end up hearing a lot of passwords, and a lot are based on their birthday, phone number, maiden name, mother's name, you name it. With the users I support, personal information is a giant leap toward cracking into the domain.

      I should add, this is despite strict policies about this kind of thing (perhaps poorly thought out, though). Users are told never to write down their pw, forced to change them every 30 days, are given tips to use characters such as $ for S and 0 for o, etc... It just doesn't work.

      So, to make a long story short, upon immediate examination, your correction is accurate, but in the hands of a deviant with time, personal information can be easily used to circumvent security measures.

      --

      My Karma was at 49, then they switched to words. All that work for nothing!

    5. Re:Security risk? by Anonymous Coward · · Score: 0

      Computer and information security is not just hacking into someone's system. It includes three major areas:

      Integrity
      Availability
      Confidentiality

      I would say users' privacy definitely falls under Confidentiality, no?

    6. Re:Security risk? by Technician · · Score: 2

      This is the same risk as an addressable cable TV box or Dish TV box. It has the same use. If you have a subscription, you get content coded to your box and nobody else. If you take your unmodified cable box and dropped it on someone elses system, it will send it's number (2way system) and be denied service. On a one way system (DISH) the number has to be phoned in. Then they have personal inoformation. The billing department requires it. Remember to not connect your Microsoft Cable box (computer) to any service you don't want to see your ID number (internet).

      --
      The truth shall set you free!
    7. Re:Security risk? by BCoates · · Score: 1

      It's not a security problem. It's a privacy problem.

      And barely one at that. It's not like web browsing is anonymous; the server knows who you are, and there's nothing you can do to stop it from telling anyone else.

      Pretending there is such a thing as anonymity in web browsing is just delusion.

      --
      Benjamin Coates

    8. Re:Security risk? by Tony-A · · Score: 2

      Identity forged by forged Globally "Unique" Identifier in Windows Media Player. Could be more effective that forged IP return addresses.
      If this post is any indication of the resources Microsoft will bring to bear on the problem, ... backup your data. Offline.

  55. Cool, what's new? by Penguinoflight · · Score: 1

    The security guy at infoworld, a guy who isn't really a open source freak, said something about this on XP. Looking back, the more Microsoft hypes security, the more security flaws they release.

    Maybe microsoft should just change platforms. :-)

    --
    "And we have seen and do testify that the Father sent the Son to be the Savior of the World"
    1 John 4:14
  56. Open security issue on their site... by slashkitty · · Score: 2, Interesting

    I've had an open security issue on their site for months. [ http://www.devitry.com/security.html ] They don't seem to be too concerned with it, even though they are running the Passport system. Will this Gates email change their minds and get their butts in gear?

    --
    -- these are only opinions and they might not be mine.
  57. MSFT: "You wouldn't want any hackers too..." by IgD · · Score: 1

    Microsoft enters the security busines...

    "How would you like some insurance to go with your operating system? I mean you wouldn't want any hackers to break in to your system would you?"

  58. Two questions by Chris+Johnson · · Score: 5, Interesting
    Two questions. One, it's all very well to talk about this but isn't it like rewriting Netscape from the ground up? Isn't it either totally meaningless or an announcement of a complete energy sink at Microsoft which will immobilize them?

    Two, to what extent is this an agenda for obliterating any shred of interoperability with other commercial products in the name of 'security'? Isn't it an open invitation to claim that total and complete lock-in is the only way to be 'secure'?

    1. Re:Two questions by Anonymous Coward · · Score: 0

      It's most likely going to result in things like not enabling UPnP or IIS by default on systems. Dead easy to do, but you need a shift in focus from "ease of use" to "security" to do so.

    2. Re:Two questions by Anonymous Coward · · Score: 0

      "...like rewriting netscape from the ground up..."

      well if they really wanted to, they could build their secure OS starting with one of the BSD's like Apple did...

      it's probably more efficient to make one of the secure BSD's windows (a la Lindows?), than to make Windows secure?

  59. Link by vondo · · Score: 1

    Here's a link to discussion of "Internet Strategy Day," but all archived info on MS's sites is missing. Did they forget to save it, or did it seem dated?

  60. I'll believe it when I see it... by dido · · Score: 2

    We all remember Jim Allchin saying that XP was "the most secure Windows ever." And everyone here knows about the UPnP bugs that were discovered the day XP was released. Their other recent announcements lambasting the process of full disclosure by Scott Culp also show that they have no real commitment to providing decent security in their products. Well, if this word from BillG is supposed to mean anything, we ought to see it in action. Unless "trustworthy computing" is supposed to mean trusted computers (a conceptual fiction) for use with digital rights management...

    --
    Qu'on me donne six lignes écrites de la main du plus honnête homme, j'y trouverai de quoi le faire pendre.
    1. Re:I'll believe it when I see it... by Anonymous Coward · · Score: 0

      Thge ONLY trustworthy computer runs each process under VM, like IBM does it.
      Does this mean MS will release it own VM Manager

  61. Subject by Legion303 · · Score: 2
    Microsoft to Focus on Security

    It's about fucking time.

    In other news, why does this story have a Borg logo on it instead of the Monty Python foot?

    -Legion

  62. It's not a security problem. by Anonymous Coward · · Score: 0

    It's a privacy problem.

  63. Bugs vs. Features by gillrock · · Score: 1

    Has Big Bad Bill finally learned? Does ne now realize that customers are VERY interested in Microsoft fixing bugs, not adding new features?

    --
    "...the shortest distance between two points may be straight line, but it is by no means the most interesting."
  64. Paying for results... by peterdaly · · Score: 2

    <QUOTE>Compensation plans of Microsoft product engineers, such as raises and bonuses, will also be tied to how secure their products are.</QUOTE>

    If you know anything about managing people, that is probably the #1 way to get people who don't really want to do something to get results. Sounds like while it may be in part a PR stunt, it really is a serious push by Gates.

    -Pete

    1. Re:Paying for results... by Merry_B.Buck · · Score: 2, Interesting

      The plan to base product engineers' raises and bonuses on their code's quality will encourage programmers to write better code...but it's not enough to lead to safer Microsoft products. The problem is that manager / executive bonuses at M$ are still based on product profits, and are generally given as stock options.

      This means the managers will still target profitablity over security.

    2. Re:Paying for results... by Anonymous Coward · · Score: 0

      Yes, you are more than right.

      Anyone thinking this is a marketing gag should remember the last time Gates wrote such an email - thats when they decided to make internet, and now MS is the most successfull COMMERCIAL platform for this - web server (no, apache is NOT commercial), browser - they basically wiped competition.

      MAYBE they do the same thing now with erros? MS has a wonderfull ability to get the whole company behind a defined goal and then push this trough.

  65. LOL LOL HAHA HAHA LOL LOL by superpulpsicle · · Score: 0

    My stomach's killing me from laughing so hard. Quick! Call a doctor...

  66. Don't get carried away... by Nick+Smith · · Score: 1

    Sure, they're having a 'Focus on Security' this week. Next week it's 'Focus on Thai Cuisine...' with free larb gai for all senior managers...

  67. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    How many normal end users would actually care in the first place?

    It's the same with anything implemented for privacy - encrypted e-mail, anonymous proxies, firewalls, etc. How many people actually use these things? Very few.

  68. Security hurting M$? I doubt it. by codewolf · · Score: 1

    Microsoft has known for years that one of their major flaws is the
    "security" that it's products offer. This statement by Bill is just a
    campaign to cover up the problems that exist and quell the fears of some of the
    major corp. consumers that are "on the edge". Microsoft has a sold
    foundation in many companies and will continue to do so for many years. However,
    the recent public "discoveries" of the down side to the lack of
    security in Microsoft products is putting a damper on Microsoft's rapid takeover
    of many market segments.


    This (the "new" public awareness, and "new" anti-M$ press
    coverage) should be viewed as a blessing to those that use Microsoft products as
    well as those that wish they would just die a horrible death. Press coverage
    that actually tells the truth, instead of just covering the bells and whistles
    added onto an insecure product, will help make large companies realize that they
    can not continue to put crap products out once a year, and do much more to help
    the growing usage of more secure, less-known OS's (linux, x-BSD, etc.).


    On the other hand, this "security problem" is not really a
    major flaw, 99% of people using M$ products have many, many, other ways of being
    tracked using products like Outlook Express in the default settings. Just
    viewing an e-mail with default settings in OE will allow spammers to know your
    address is valid (with the right embedded code).


    People (the average consumer) will never wise up and start using more secure
    products, it will take bad press, and cash flow changes to make companies stop
    creating insecure OS's.

    --
    http://www.codewolf.com - Just good stuff to waste time
  69. Learning from examples by piyamaradus · · Score: 1

    I'm guessing Mr. Gates has been watching the Enron/Arthur Andersen news and realizing how important it is to be able to keep investigators from reading your documents -- so now, privacy and security are important :)

    1. Re:Learning from examples by johnnyb · · Score: 2

      Speaking of Microsoft and Enron, how many people have read this:

      http://www.fool.com/portfolios/rulemaker/2000/ru le maker000217.htm

      Kind of makes you wonder, doesn't it?

  70. Why not? by idiotnot · · Score: 1

    FWIW, I submitted this story and it was rejected....

    But, that's not my point. What incintive does MS have to add new features now? They've eliminated all the commercial competition for desktop OS's, so even with users clammoring for more features, users are stuck with Microsoft.

    What about Linux?

    Okay, yes, sure. And Linux (and BSD) are more secure than Windows, but in many respects aren't as feature-rich yet (flame away, but I'm a confirmed Linux user). So, Microsoft's stands fast on features while it brings its security up to speed, and hopes that alternatives don't surpass Windows, feature-wise.
    And how many users do they lose in the meantime?

    Not many.

    1. Re:Why not? by asyncster · · Score: 1

      but in many respects aren't as feature-rich yet
      Well, as the operating system is concerned, Windows has nothing on Linux or *BSD. FreeBSD, for instance, is working on revolutionary features for their 5.0 release. Highlights include improved threading, SMP, process migration, etc... Nobody really knows what Microsoft is doing to Windows, but XP is basically a flop. Windows research publishes a whole lot of papers about OS design which never get incorporated into Windows. Its a shame more people don't realize how cool and powerful FreeBSD is.

  71. The New PR Spin by Alien54 · · Score: 2
    Typically, the way that I imagine Bill to handle this is to redifine security according to Microsoft Specs. I am reminded of the old joke of MS defining "Dark" as the new standard when the lightbulb goes out.

    Some people think Bill invented the Internet. Now is his chance to invent the Microsoft System for Secure Computing (TM), which will include all of thosde features that MS wants first, and maybe a few that you feeel are important as well.

    Microsoft Planet here we come! =8~|

    --
    "It is a greater offense to steal men's labor, than their clothes"
    1. Re:The New PR Spin by Anonymous Coward · · Score: 0

      I thought Al Gore invented the Internet?!?

    2. Re:The New PR Spin by mysidia · · Score: 1

      "Emphasize security" could just as easily mean take efforts to obscure the issues.. a shift in focus towards security might mean slightly more secure software while most of their "security" efforts get focused on trying to destroy the idea of "full disclosure" on security problems in their software under the guise of improved security.

      Who knows, this could all be part of a PR plot to paint the software company as the "good guys trying to keep things secure" and the full-disclosure people as "the bad guys trying to punch holes in their software"

      Heck, they've already got the linux kernel people suppressing all information about possible security issues from kernel ChangeLogs resulting
      in people using that software being less-likely
      to upgrade because they don't "know what's wrong"... by obscuring all security holes, they will seem more secure.

    3. Re:The New PR Spin by garf · · Score: 1

      "Typically, the way that I imagine Bill to handle this is to redifine security according to Microsoft Specs. I am reminded of the old joke of MS defining "Dark" as the new standard when the lightbulb goes out."

      Huh? Damn, M$ could enter this 'Dark' state into some arty competition...maybe they'd win?

      --
      H&Ks Garf
    4. Re:The New PR Spin by drik00 · · Score: 1
      Microsoft Planet here we come!

      Remember those shots of Coruscant in Episode I? how much would it suck if that whole damned planet ran WinME, and you had to reboot the planet every couple of hours...

      that would suck. M$'s security is similar to living in your house with all the doors and windows wide open all the time, when someone breaks in, M$: "no they didnt, its a hardware problem."

      --
      Beer, now there's a temporary solution -- Homer Jay S.
    5. Re:The New PR Spin by nixnixnix · · Score: 1

      Brilliant. I think you've got it: hit the nail on the head. It's a tactic to prevent the long term efforts in "full disclosure" which would undermine their hegemony. I concurr with you observation.

  72. I feel bad for Bill by global_diffusion · · Score: 1

    He's the geek who's responsible for the world's shittiest software. He can never get respect from his peers. How sad is that?

  73. This is exactly the point by Mdog · · Score: 1

    You're right. If you just look at it as a run-of-the-mill MS announcement, it isn't extraordinary at all: They are refocusing on the buzzword that makes them the most money. It just so happens that this buzzword has a negative connotation in relation to MS.

  74. Ruh roh by Anonymous Coward · · Score: 0

    Time to uninstall Media Player. I'm just tired of companies sneakily trying to track my browsing/purchasing habits without disclosing it. Enough.

    1. Re:Ruh roh by Graspee_Leemoor · · Score: 2, Informative

      " Time to uninstall Media Player. I'm just tired of companies sneakily trying to track my browsing/purchasing habits without disclosing it. Enough."

      Why not try unchecking the big friendly "Allow media sites to uniquely identify my player" box instead?

      graspee

  75. If it actually happened.. by evilpaul13 · · Score: 1

    If MS actually puts some work into security, besides their "veteran programmers" feeling a lack of job security, it could be a good thing. I don't know whether or not they will.

    That being said, I thought everyone knew to uncheck the "Uniquely Identify My Browser" and "Protect Content" in WMP7?

  76. ummmmm... ok by Anonymous Coward · · Score: 0

    People criticized Microsoft for treating security breaches as a public relations problem, so Bill Gates sent this email out to the Associated Press to prove them wrong

    so to prove them wrong he sent out more PR... gotta love it...

  77. In an unrelated story... by djrogers · · Score: 1, Offtopic

    Adult film star Ron Jeremy announced that in the future he would be focusing on dialog and plot development in his future projects...

    --
    Think outside the... Hey, where'd the friggin' box go?
    1. Re:In an unrelated story... by Anonymous Coward · · Score: 0

      Industry insiders wish he would focus on shaving his back, it is reported.

    2. Re:In an unrelated story... by Dave_bsr · · Score: 1

      Well, I think it's funny.

      Ok, since someone doesn't get it (right now i see Overrated=2),
      Porn star concentrating on plot. Microsoft concentrating on security. Both would be amazing turnarounds, but are _extremely_ unlikely and would be slightly ironic. Hence, humor. I don't think it would help Ron Jeremy's career any, but we'll see what happens to good ol' MS.

      - dave

      --


      Who is this Anonymous Coward character, how does he post so much, and why is he always such a whore?
  78. Microsoft's focusing on security? by acceleriter · · Score: 1
    What happened? Did they steal some security ideas from a smaller company, run them out of business, and incorporate the ideas into the next version of Windows?

    ~~~

    --

    CEE5210S The signal SIGHUP was received.

  79. They'll do it too. by Slime-dogg · · Score: 1

    M$ brand of security: Change the name "Administrator" to "Root."

    It's more difficult to obtain root than it is to get Administrative permissions.

    --
    You need to restart your computer. Hold down the Power button for several seconds or press the Restart button.
  80. "Trustworthy Computing" is an Innovative Term by guttentag · · Score: 4, Insightful
    Gates referred to the new philosophy as "Trustworthy Computing" and called it the "highest priority". ... Meanwhile, Richard Smith notes that the Globally Unique Identifier in every installation of Windows Media Player allows websites to universally track users.

    "Trustworthy Computing" doesn't necessarily mean "secure computing." Microsoft wants you to think that, though, just like they want you to assume "we're innovating" means "we're making products better for you." (Incidentally, MS's definition of "innovation" means "finding new ways to solidify our market position.")

    Anyone remember Bill Gates's deposition in the MS antitrust trial? His version of the English language is so far out of whack he spent most of each session professing to have no understanding of common words and terms.

    In this case, "Trustworthy Computing" means "convincing computer users that they don't have to wory about security... that they can trust MS."

    1. Re:"Trustworthy Computing" is an Innovative Term by LaTeXninja · · Score: 1
      Gates referred to the new philosophy as "Trustworthy Computing"...

      So we should just trust him? I don't want to have to trust anyone! I want security!!!

    2. Re:"Trustworthy Computing" is an Innovative Term by johnnyb · · Score: 3, Insightful

      Actually, what will happen is that Bill Gates will act like he invented the concept of secure computing. And the media will believe it, just like they believe he invented the browser, email, the internet, and web services.

      Have you seen how much hype has gone into web services, with Microsoft acting like they were the first ones to the table? Arg.

    3. Re:"Trustworthy Computing" is an Innovative Term by Dave_bsr · · Score: 2, Interesting

      Please someone explain to me what this means (from the first document), Bill is answering:

      15 Q. Do you use a computer at home?
      16 A. Yes, I do.
      17 Q. Do you use that on work-related
      18 matters?
      19 A. Some of the computers I do and some of
      20 the computers I don't.
      21 Q. Do you know whether those computers
      22 were searched in connection with a document search in
      23 this litigation?
      24 A. Those computers don't have storage.
      25 Q. But you don't know whether the hard
      8
      1 disk was searched for any material that might be
      2 there that --
      3 A. You should understand it's a portable
      4 computer, it moves back and forth. That's the
      5 computer with my e-mail, it moves back and forth. So
      6 it's the same computer in my office as at home.
      7 Q. I see, okay. And I assume the computer
      8 in your office was searched for relevant e-mails; is
      9 that your understanding?
      10 A. Yes.

      No storage? Huh? Back and forth? It's late...anybody make sense of that?

      - dave

      --


      Who is this Anonymous Coward character, how does he post so much, and why is he always such a whore?
    4. Re:"Trustworthy Computing" is an Innovative Term by guttentag · · Score: 1
      Perhaps I was a little melodramatic in my post... you'll have to forgive me, I had just finished watching a classic Twilight Zone episode:

      Codebreaker: We've only been able to decipher the cover of the book the aliens left behind.
      Mr. Chambers: Well, what's it say?
      Codebreaker: "To Serve Man"
      Chambers: I'd say that settles the question of their intentions.
      ---
      Codebreaker: Mr Chambers! Don't get on that ship! The book! "To Serve Man"... it's a cook book!
      Chambers: Hey, let me off of this thing. Let me go!
      ---
      Alien: Come now, Mr. Chambers. Eat. We wouldn't want you to lose weight.
      Chambers (to the camera): How about you? Are you still on Earth or are you trapped on this space ship with me. I suppose it doesn't really matter. Soon we'll all of us be on the menu. All of us.

      So in my mind, I suppose I was thinking:

      CmdrTaco: We've only been able to decipher the name of Gates's new initiative.
      Slashdot Readers: Well, what's it say?
      CmdrTaco: "Trustworthy Computing"
      Slashdot: I'd say that settles the question of their intentions.
      ---
      CmdrTaco: Don't get on that bandwagon! The initiative! "Trustworthy Computing"... it's a cook book!
      Slashdot: Hey, let me off this thing. Let me go.
      ---
      Gates: Come now, Slashdot readers. Buy some food with your Passport account. We wouldn't want you to starve to death.
      Slashdot (via MSN Messenger): How about you? Are you still using Linux or are you trapped by these Windows like me? I suppose it doesn't really matter. Soon we'll all of us be behind Windows. All of us.
  81. I want... by Anonymous Coward · · Score: 0

    Microsoft to secure MY private parts!

  82. Microsoft's First Security-Focused Meeting by long_john_stewart_mi · · Score: 1

    Bill Gates: "Okay! We need to talk about security. The bad news is that this could take a while. The good news is that we get to have one big pizza and pop party!"

    --
    ...oOOo..'(_)'..oOOo...
  83. You should be afraid... by tswinzig · · Score: 5, Insightful

    The last time Bill Gates was widely publicized for announcing a major strategy shift to his employees was back in 1995, when he sent out a memo saying they were going to focus on the internet.

    I bet I wasn't alone in laughing. The first version of MSIE that was out at the time was a JOKE. Netscape reigned supreme. RealAudio was king of streaming. Third parties actually had a shot at selling a Windows web server.

    How long did it take them to: (a) Kill Netscape with MSIE, (b) maim RealAudio with Windows Media, (c) shutdown 3rd-party Windows webservers with IIS, etc.? Not long.

    Extrapolate amongst yourselves.

    Goodbye ZoneLabs (makers of ZoneAlarm). What other big Windows security players will have their security software crushed within 3 years? McAfee? Symantec?

    Unix users laugh at the inherent security problems with Windows, just as I laughed at MSIE 7 years ago. I haven't been laughing lately. Will you still be laughing a few years from now?

    --

    "And like that ... he's gone."
    1. Re:You should be afraid... by djrogers · · Score: 5, Insightful

      Adding functionality to an OS is much easier than adding security. There's nothing magic about building a web server or browser, and giving them away/bundling them makes it quite easy to gain marketshare. Note that everything you mention in your e-mail has been involved in HUGE security holes...

      --
      Think outside the... Hey, where'd the friggin' box go?
    2. Re:You should be afraid... by inerte · · Score: 1

      No system is 100% secure. TRUE (I hate when people say PERIOD ;-)). It's IMPOSSIBLE to design a complex software without security flaw.

      The system that have the large userbase will get most of the attacks. As long Windows does, it will.

      Sometimes I think people forget what drive crackers. It's not most of the time a pure criminal act, but a social behavior. You want recognition, and you do it.

      Perhaps we need to stop worshiping IT figures?

    3. Re:You should be afraid... by tswinzig · · Score: 1

      Note that everything you mention in your e-mail has been involved in HUGE security holes...

      As have all their competitors' products.

      --

      "And like that ... he's gone."
    4. Re:You should be afraid... by Bob9113 · · Score: 1

      How long did it take them to: (a) Kill Netscape with MSIE, (b) maim RealAudio with Windows Media, (c) shutdown 3rd-party Windows webservers with IIS, etc.? Not long.

      (a) 2 Years. Netscape was closed source at the time, and the company was severely disfunctional. Now that it's open, it's almost back in the lead (if you haven't used Mozilla 0.9.7, use it as your primary for one week before you respond).

      (b) 5 Years. RealAudio is closed source.

      (c) Are you high? Haven't you heard of Apache? Granted, there was a ~12 month period when IIS first came out that Apache/Win32 was more black art than science, and IIS is still preferred 10 to 0 by people who use the server that comes with Windows, but I hardly consider that "shutting Apache down".

      I'm not saying Microsoft is incapable of putting up a fight. Fearing them is healthy, particularly if it drives us to greatness. But they are not the irresistable juggernaut you portray.

    5. Re:You should be afraid... by 1010011010 · · Score: 3, Funny

      I suppose that Microsoft will have to re-think things like ".exe" at the end of a filename meaning "run me" to the OS.

      Until then, I for one will keep laughing.

      --
      Napster-to-go says "Fill and refill your compatible MP3 player", which is a lie. It's not MP3. It's WMA with DRM.
    6. Re:You should be afraid... by mike_sucks · · Score: 1

      How long? About three or for years.

      The situation is slightly different here, however. When MS missed the Internet boat, their core business wasn't in danger. It wasn't like they were going to lose anything, the only problem was that their growth wasn't going to be as good as they wanted. Netscape was seen as a danger to the Windows platform, as was Java, but web applications aren't perfect for every situation, so there was always going to be a need to a "native" platform. And that could just as well be Windows. So, no hassle there.

      The problem MS faces at the moment is one which will actually drive people away from their products., on which if left unchecked, might not even slow but, gasp, reverse their growth. Tha is the real issue here.

      Now, it's not likely that in the three or four years it may take to ramp their security up to something approaching decent that they'll go down in flames, but their reputation will be harmed, a lot. If only from all the unpatched instances of Windows that are running out in the wild. The issue will be whether or not someone can present a decent alternative before then, and use MS's tarnished image to get a foot in the door.

      I guess it will come down to a) how much they can improve their situation and b) how good a spin their PR can put on the situation in the meantime.

      Mike.

      PS, I'm still laughing, especially at the poor bastards who have to use Windows all day long. Heh heh heh!

      --
      -- "So, what's the deal with Auntie Gerschwitz et all?"
    7. Re:You should be afraid... by Llywelyn · · Score: 1

      Yes.

      The reasons that they "won" against all of those things (I'd argue (c) and (b), but someone has already done so for me) dealt largely with that they through features (i.e., "products") at them and locked into into an exclusively Windows OS.

      As the now famous quote goes: "Security is a process, not a product"

      This is a new field for Microsoft--MSIE was still attempting to provide a product that could outmanuver anything else on the Windows platform. This is a great deal simpler than it sounds, particularly when you are an established monopoly.

      It took them months just to get a buffer overflow patched. I somehow doubt their claims now are anything more than PR.

      --
      Integrate Keynote and LaTeX
    8. Re:You should be afraid... by Ars-Fartsica · · Score: 3
      Netscape was closed source at the time, and the company was severely disfunctional. Now that it's open, it's almost back in the lead

      On what planet? Netscape is sitting around 8% of the browser market.

      RealAudio is closed

      And so is the software MS used to kill it. Your point??

      Haven't you heard of Apache

      He said servers on Windows and he was right.

    9. Re:You should be afraid... by Anonymous Coward · · Score: 0
      ...just as I laughed at MSIE 7 years ago
      I think you need to calm down... by the time IE 7 ships, mozilla will also be able to take the OS down when it crashes
    10. Re:You should be afraid... by Anonymous Coward · · Score: 0

      RealAudio sucks.


      Oh yeah, and shut up.

    11. Re:You should be afraid... by gtaluvit · · Score: 0

      ZoneAlarm is already dead. For your average user, its "yells" at you too much and makes you all worried that some ICMP packet may be a hacker. Windows XP, all you have to do is check one checkbox, and it asks you if you want to do it in setup.

      Of course, it'll still be one more iteration before microsoft nails down the firewall so it doesn't block everything period (like ident) but compared to using ZoneAlarm, its friendlier.

      --
      - gtaluvit (prnc. GOT-tuh-LUV-it)
    12. Re:You should be afraid... by Advocadus+Diaboli · · Score: 1
      Goodbye ZoneLabs (makers of ZoneAlarm). What other big Windows security players will have their security software crushed within 3 years? McAfee? Symantec?

      I'm sorry, but if things like ZoneAlarm are gone its not a great loss. Those sort of "personal firewalls" do not really add security to a system. The reason for this is simple:

      You have on piece of closed source software (Windows) of which you don't know exactly what it is doing. And now you want to feel better by adding another piece of closed source software (personal firewall) of which you also don't know what it is doing.

      As a Unix user I really laugh about MS and their security problems. And of course if they will have better security in a few years I won't laugh, but that's not a problem. The goal is not to make some people laugh, the goal is to have secure computersystems.

      And Microsoft has actually realized that they don't have them, but their competitors from the Unix world do. And they have realized that the customer is going to be concerned about security now. So if they want to sell their products in the future they have to improve security a lot.

      But I'm more afraid that this is more a sort of vapoware announcement. To prove their security they have to make Windows open source and I doubt that they will do it.

    13. Re:You should be afraid... by Anonymous Coward · · Score: 0

      I'm still laughing... at your stupid pseudo-insightful post.

    14. Re:You should be afraid... by Sloppy · · Score: 2

      You've got to be kidding. In the internet example, just because Microsoft was able to kill off some competitors, doesn't mean I ever stopped laughing. if you've stopped laughing at Microsoft's approach to the Internet, then you have an impaired sense of humor.

      Remember: this is the company that has a web browser that will download and execute native code without a sandbox. They call this feature "ActiveX."

      This is the company that sells Outlook.

      You're not laughing?!?

      BTW, when I look at all the companies you mentioned that they killed with their new internet focus, I see something in common: they were all Windows developers. There's a pretty simple lesson in that.

      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    15. Re:You should be afraid... by Weezul · · Score: 2

      Yes, Bill can really turn heads when he wants, but I'm not shure that security really matters to MS's consumers. A strong case can be made that focusing on security is a bad buisness decission.

      Anyway, if MS makes it's software more secure what have they gained? Shure, they have wiped out the super expencive compeditors like Oracle, but these people focus on a minority market. I don't think killing a few compeditors in the server industry is worth the money.

      Ok, lets focus on your classic security companies like Stmmantec and McAfee. Clearly, MS gains by entering this market with stand alone products which it can sell to the truely security minded, but I think the competition would be fierce, for a small market.

      Ok, MS descideds it wants to win so it bundles a virus scanner with Windows. Big mistake! MS could afford to lose the revenue stream from IE since IE had amazing leveraging potential. Virus scaners just don't offer that potential. MS has killed their compeditors by wiping out the market, so no one makes any money. Built in security features are even less profitable since you can't sell them seperatly.

      Ultimatly, I just don't think security is profitable unless you are selling it only to the people who care. The majority do not care about security so you need to sell cheap security and then you lose the revenue from the people who were willing to pay through the nose.

      Bill is a control freak so he would never do this, but I think MS's best bet security wize would be to lissence Oracle, Symmantec, etc. to create their own secured versions of Windows.. with the requirment that (a) all rights revered to MS within 3 years, (b) they had to charge full sticker price for the modified Windows (i.e. no OEM version), and (c) MS got most of the money anyway. The paranoid security folks would get their product (whose biggest feature would be disabling stuff by default), MS would be protected from anti-trust laws, and MS would walk away with the cash, rights, and market leverage.

      --
      The Christian religion has been and still is the principal enemy of moral progress in the world. -- Bertrand Russell
    16. Re:You should be afraid... by scrytch · · Score: 2

      How long did it take them to: (a) Kill Netscape with MSIE, (b) maim RealAudio with Windows Media, (c) shutdown 3rd-party Windows webservers with IIS, etc.? Not long.

      Netscape and Real Networks self-destructed. Real is still trudging along, making their player more and more obtrusive, obnoxious, buggy, and resource-consuming, but at that rate they'll deservedly become a footnote. Netscape was the only one that managed to market a decent webserver for windows, but well, see above.

      So MS integrates what was once third-party software into the OS. Some even cry to the DOJ about their disappearing "market" (the idea that there was a "web browser market" was dubious at best). I have about as much sympathy for companies that attempt to ride on shinier versions of the Same Old Software they sold ten years ago as I do for Trumpet (makers of a TCP/IP stack) and the makers of buggy whips. No one has a god given right to keep selling the same product to the same market forever. If MS raises the bar, I'm happy to be left with companies that can jump it.

      --
      I've finally had it: until slashdot gets article moderation, I am not coming back.
    17. Re:You should be afraid... by Dave_bsr · · Score: 1

      a) - You are right - IE still crashes my systems (in windows, of course...), but mozilla, when it crashes, leaves windows alone just fine...and it's laughable to watch me try and middle-click to open a new page in IE. I still curse that little move-thingy. arg. Mozilla is awesome for win, and in linux it's pretty good too.

      b) - streaming audio - does it really matter? everyone I know who needs audio uses p2p. Internet radio is dying. what else is there? seriously, I just don't know, and i'm curious if there is anything.

      c) - A friend of mine runs apache in win98. A lot of people use it. Wait until 2.0, or read this slashdot article if you don't believe me. I agree with the parent i'm replying to. MS hasn't done too much to impress me with their internet stuff. It's mostly bloated and insecure.

      - dave

      --


      Who is this Anonymous Coward character, how does he post so much, and why is he always such a whore?
    18. Re:You should be afraid... by MartinB · · Score: 1
      I'm not shure that security really matters to MS's consumers. A strong case can be made that focusing on security is a bad buisness decission.

      You can only make a strong case if you assume that MS's main revenues are from consumers. They're not. They're from business, who want, need, demand security. So far, MS has been able to convince them that their security is good enough. That's no longer the case.

      --

      The only thing you can accurately describe as "Scotch" is a sticky tape made by 3M. And it's

    19. Re:You should be afraid... by Bob9113 · · Score: 1

      On what planet? Netscape is sitting around 8% of the browser market.

      My understanding of the original post was that the poster was speaking to destruction by development of superior quality (which in the first two cases Microsoft did). In my post I was referring to the relative quality of the latest release of Mozilla, not market penetration.

      And so is the software MS used to kill it. Your point??

      That closed source versus closed source is not the battle MS is facing. Development in the cathedral is hard, particularly in the security arena. Microsoft will face greater challenges in the battle against Linux than they did in the battle against RealAudio. Therefore, their destruction of RealAudio is moot to this discussion.

      He said servers on Windows and he was right

      An interesting opinion. It goes without saying that those who require IIS features, like .asp, use IIS (just as those who require Apache modules use Apache), and those who simply accept the default server, use IIS (much as Linux users who don't care use Apache). I find it extremely hard to believe that there are more people using IIS than Apache on Windows who have made their decision based on their perception of server quality, and independant of the factors mentioned above.

    20. Re:You should be afraid... by Anonymous Coward · · Score: 0

      Hey, using filename extensions to indicate whether
      a file was data or code made a lot of sense 25 years ago, when personal computers were single-user, standalone systems.

      Besides, you won't have much luck executing an .EXE file unless it starts with the magic token 'MZ'...

    21. Re:You should be afraid... by Tony-A · · Score: 2

      Sure you will. Just rename a FOO.COM to FOO.EXE. Still works. A real .EXE file has to start with the magic token 'MZ', but it works equally well if it is renamed to .COM
      Depending on scripting languages and extensions, there are an awful lot of Run-Me running loose.

    22. Re:You should be afraid... by tswinzig · · Score: 1

      My understanding of the original post was that the poster was speaking to destruction by development of superior quality

      Nope, sorry, I was only talking about Microsoft destroying competitors when it sets it mind to it. It set its sights on the Internet, and destroyed competitors in the Windows market. Now its going to focus on security, and destroy competitors in that market, too.

      --

      "And like that ... he's gone."
    23. Re:You should be afraid... by tswinzig · · Score: 1

      You have on piece of closed source software (Windows) of which you don't know exactly what it is doing. And now you want to feel better by adding another piece of closed source software (personal firewall) of which you also don't know what it is doing.

      You may not know what it is doing, but I know what it is doing. It is blocking programs from using the network unless I specifically give them permission. I use this in addition to a hardware firewall to prevent intruders. (Also closed source software.)

      Sure, the source is not available, but I wouldn't examine the source even if it was.

      --

      "And like that ... he's gone."
    24. Re:You should be afraid... by tswinzig · · Score: 2

      To prove their security they have to make Windows open source

      Wrong. To prove their security to OPEN SOURCE fanatics, they have to open the source. To prove their security to me, they have to change the behavior of the operating system so that it is more secure. They have to eventually be able to go 6 months or a year without a new hack being found for Windows. They have to find a way to prevent the spread of viruses amongst Windows systems. None of this requires the source to be open.

      Just because an OS has its source open doesn't make it secure. Exploits are still being released for open source systems like Linux.

      Linux and OpenBSD are both open source. Why does OpenBSD have a better security record than Linux? According to your theory, they should both be equally secure, right?

      --

      "And like that ... he's gone."
  84. Re:MSFT: "You wouldn't want any hackers too..." by acceleriter · · Score: 1

    That racket's already taken by Symantec and McAfee, primarily.

    --

    CEE5210S The signal SIGHUP was received.

  85. He can talk the talk... by Jon+Abbott · · Score: 5, Interesting

    "Users should be in control of how their data is used" -- Bill Gates

    To that I say, put your money where your mouth is. Quit endorsing DRM. Quit using proprietary formats in your applications. Open your APIs. Include some decent text manipulation tools at the command line (like GNU textutils). Give the user some choice for a change.
    1. Re:He can talk the talk... by 2x4 · · Score: 0

      The user will use thier data Billy's way. "Users should be in control of how their data is used" means the users control how OTHERS use thier data, not themselves.

  86. Bill Gates, Microsoft CEO ??? by Handulschteim · · Score: 1

    So, my question is "where is Steve Ballmer?" This seems to be the type of decision that is supposed to be published by the CEO, not the chairman of the board.

    Probably what is happening is that Microsoft is using the Bill Gates brand to influence Microsoft's public image since the two are historically synonomous. Think of it. How much less attention would this announce get if Ballmer had announced it instead of Gates?

    Guess we know who wears the pants and who is the bitch in this relationship.

  87. Water to focus on being dry by sam_handelman · · Score: 2

    This is directed at legislators. As PR, it's pretty poor, and against form for microsoft - it admits that a problem exists (remember their old slogans about how windows was fast and reliable?) If they can convince legislators (who are, to some or extent or another, in MS' pocket) that they're doing something, than they can convince legislators to abandon the proposal to make software vendors liable for security failures, which could open up MS to unlimited liability.

    --
    The good and new comes from no quarter where it is looked for, and is always something different from what is expected.
  88. internal resistance. by Alien54 · · Score: 2
    Compensation plans of Microsoft product engineers, such as raises and bonuses, will also be tied to how secure their products are.

    Russ Cooper, a security expert with TruSecure Corporation, said the change occurred in part after a new security team assigned to attend every product meeting met resistance from product teams.

    I am not very surprised by this

    Customers could also see a downside, though. Other than fewer new features, product upgrades could come less frequently or could be pushed back.

    Somehow, this is not a drawback, and hopefully this throws the subsription thing out of wack.

    --
    "It is a greater offense to steal men's labor, than their clothes"
    1. Re:internal resistance. by borgquite · · Score: 1

      While what you're saying is going a bit too far, one good thing that Microsoft do do is inform the clueless user about what they're doing and the consequences. Whilst the information does tend to be intended to glorify Microsoft quite often, if you let someone know that 'This file is an attachment, don't run it if you don't know who it's from or weren't expecting it', it's *good*.

      So it might be nice if there was a generic Internet warning when you first load it up. We get annoyed by this sort of thing (maybe we need a 'turn off tips and hints' button), if users understood a little bit more about the Internet maybe there wouldn't be so many worms, virii, hoaxes and chain-mails-in-aid-of-dying-children.

      --
      ' Ore stabit fortis a fine placet ore stat '
      - found on a park bench
  89. Security for whom? For end users or... by SIGFPE · · Score: 2

    ...for corporations? I expect that increased security means making it harder for us end users to listen to our music and watch our movies whenever we want rather than protecting us from things like viruses and intruders - after all, that's where the money probably is.

    --
    -- SIGFPE
  90. Re:That GUID on WMP? Yeah . . . by blakestah · · Score: 5, Insightful

    Normal slashdot staff overreacting again. You can turn that ID off.

    The defaults are everything, Why do you think Microsoft has negotiated so hard for its icons to be on the Mac desktop(IE), and no other browser is allowed to be there ? Why do you think Microsoft has spent so much effort controlling system defaults for media players, and IE home pages, and startup icons ?

    This is standard user behavior - they do not change the defaults. Somehow it is the fault of the guy who installed NT server and NEVER WANTED IIS that he got broken into, and not Microsoft's fault for globally enabling IIS and asking the admins to turn it off.

    Giving the end user a chance to change a system default is a good way to ensure that 95% will use the default, and the company (Microsoft in this case) can blow blame aside by saying the user can change it.

    Now, you can argue users need to be more savvy, or you can accept that Microsoft KNOWS end user behavior and uses it to their advantage. Or both...

  91. Here it comes... by Anonymous Coward · · Score: 0
    The only way you can be secure on the net is to make sure you use the only protocols that make sure *all* your personal data is hand-delivered right to Billy's desk!

    Why, it's TCP/MS!

  92. All together now... by Broken+Bottle · · Score: 1



    AGAIN?!?!

    Please...

    If I had a nickle for everytime in the last 18 months Microsoft has said that they were "going to get serious about security" my home computer would be a mainframe. There was an interesting quote from an article in E-Week this week. To paraphrase:

    "Microsoft treats bugs like PR problems, not security problems."

    Why should we believe that this announcement is anything other than more spin doctor PR crap.

    chris

  93. The same? by Anonymous Coward · · Score: 0

    Isn't this the same as companies who clean up toxic waste simply because it makes them look better to take care of their waste then what they were used to and like to do - that is to dump it in a stream?

  94. Wall Street cheers! by Ldir · · Score: 2
    From the AP story:
    Compensation plans of Microsoft product engineers, such as raises and bonuses, will also be tied to how secure their products are.

    In related news, Wall Street reacted favorably to a report that Microsoft is slashing payroll expenses by 80%.

    Fire and brimstone market prices skyrocketed 72% on the news that hell had indeeed frozen over. Satan declined to comment.

    Internet search engine Google reports traffic up 17%, and that the word "security" has become the most popular search term, driven entirely by submissions from the microsoft.com domain.

    Film at 11:00.

    1. Re:Wall Street cheers! by Dave_bsr · · Score: 1

      nice touch with google - i had this imagery of a whole office full of Microsoft people frantically trying to come up with something about "security"

      ... on an interesting rabbit trail, how far down does it take to find "linux" in the google search for security? Both Microsoft and Social Security are above anything linux-ey...oh well. Those MS guys will just have to work harder.

      - dave

      --


      Who is this Anonymous Coward character, how does he post so much, and why is he always such a whore?
  95. Why Bill Gates should be KING! by rice_burners_suck · · Score: 0, Offtopic

    Microsoft's so-called products are CRAP . Here is the quantitative proof:

    You see, it's really quite simple. Bill Gates wants to be king of the world. What he's doing is amassing a great fortune that he will use to buy the government of a small country. Then, he'll take control of that country and run it like a huge business. In other words, like Microsoft, just much, much bigger. Then, he'll use his great fortune from that to purchase another country. And then another. Until he'll own a United States of Bill Gates. Then, he'll be able to buy really big countries, and several at a time... He'll just buy a whole continent at a time. He'll buy North America. Then he'll buy South America. Then Europe. Then Africa. Then Asia. Then Australia. And finally, he'll even buy Antarctica. Just for fun.

    Bill Gates will use his powers only for evil. He'll turn the entire world into a big piece of crap. All the buildings all over the world will be in ruins. The roads will be all smashed up. Nobody will have a job anymore, except to be Bill Gates' slave. People will haul big bricks to build enormous pyramids and palaces for Bill Gates. He will sit on a huge fancy throne, and everybody else in the entire world will go hungry.

    Actually, I'm just kidding. We all know that Bill Gates will use all his power only for good. Every person in the world will live in a huge palace and they'll have everything they ever wanted. Nobody will ever go hungry. There will be no more bad in the world. Bill Gates will just run around making everything good for everybody.

    Actually, that's not likely--I believe the first one better.

    But where the hell was I? Oh yeah... to make a long story short, oh well.

    1. Re:Why Bill Gates should be KING! by rice_burners_suck · · Score: 1

      Disclaimer: I'm really just kidding about Bill Gates. I think he's a good guy. A little greedy, I think, but he still donates millions of bucks to all kinds of good causes. (Probably just to take a tax deduction, but it still costs him the same amount of money, so what difference does it make?) So he's a good guy. I don't like his crappy software. But when he does become king of the world, I don't think everybody will go hungry. In fact, he'll run this planet like a big business and next thing you know, humans rule the entire universe. (Likely with spaceships that randomly crash into some moon or star, but we'll rule nontheless.)

      Oh well... Mod me a Metatroll if you want. It's just a joke. Get over it.

    2. Re:Why Bill Gates should be KING! by Peyna · · Score: 2

      You can only take a $2000 deduction currently for charitable donations. Since Gates probably pays income taxes on much more than that, I doubt he'd even notice. And it doesn't cost you the same amount of money. A $2000 deduction doesn't save you $2000. You just get to pretend like you made $2000 less than you really did.

      --
      What?
    3. Re:Why Bill Gates should be KING! by rice_burners_suck · · Score: 0, Offtopic

      And with Gates' tax bracket, that's like a needle in a haystack. He must be paying 50% of this country's taxes. Well, not 50%, but whatever it is, it's a pretty hefty tax bill. I don't envy him one bit. (Of course, he probably doesn't mind too much, otherwise he would have retired years ago.)

  96. Check out the last paragraph by bnenning · · Score: 3, Interesting
    ``Users should be in control of how their data is used,'' Gates wrote. ``It should be easy for users to specify appropriate use of their information including controlling the use of e-mail they send.''


    Ok, what the heck does that mean? Unless Microsoft plans on solving the trusted client problem, once I send you an email there is no way I can control how you use it. The only thing I can think of is letting users add a header to outgoing email, and if it was present Outlook would not allow copying or saving when the recipient viewed it. Of course anything like this is trivial to defeat, resulting in the illusion of privacy rather than actual privacy.

    --
    How to solve most of our problems: 1.Lots of nuclear plants. 2.Cure aging.
    1. Re:Check out the last paragraph by andrewski · · Score: 1

      It's obvious that all this hubbub is, at the root, about implementing MS's Digital Rights Management OS. I would speculate that MS is considering public-key encrypted documents as a sort of meta-file that could contain other digital datum. It's amazing what dribbles out of Billy's cake-hole sometimes.

    2. Re:Check out the last paragraph by MartinB · · Score: 1

      It probably means making Outlook do what Notes has done for a long time - integrate public/private key cryptography to give users the option to have their outgoing mail encrypted to specific recipients' keys, without having to d/l PGP.

      Of course, a recipient *can* just copy and paste...

      --

      The only thing you can accurately describe as "Scotch" is a sticky tape made by 3M. And it's

  97. Remember that visit from the FBI about XP? by coyote-san · · Score: 3, Interesting

    I don't think they're worried about a Gartner report, Microsoft has been slammed on its poor security record for some time now. (Maybe not by the Gartner Group, but certainly in other PHB reports.)

    What probably got their attention was the recent visit from the FBI. Something most people forget is that one of the primary responsibilities of the FBI is counterespionage, and it doesn't take a genius to figure out how much damage a subtle virus could do on government computers. (Esp. after other countries had sensitive documents leak out with that "I write you for your advice" virus.)

    We'll never know what the FBI told them... but we can guess based on what we now know. Every group must explicitly consider security issues, senior management remindning the troops to take it seriously. Maybe this is my one cynical-free day each year, but I really don't see this as an ploy to attack open source software such as Samba. I think they finally understand that they have a serious problem.

    But, ironically, I'm now concerned that they don't have enough experienced security people. The corporate culture just hasn't encouraged development of the right skills. Any semi-decent programmer can check for buffer overflows and the like - even automated tools can do that in many cases now - but true security comes from an ability and willingness to challenge the most basic assumptions, to question the most sacred code, etc.

    --
    For every complex problem there is an answer that is clear, simple, and wrong. -- H L Mencken
    1. Re:Remember that visit from the FBI about XP? by Anonymous Coward · · Score: 0

      Yes.

      There is a reason why I and all of my co-workers are going to security training classes and reading books on how to write secure code before we can touch another line of product code. After that, we take a significant chunk of time to do nothing but security.

  98. Speaking of control of data... by shnarez · · Score: 1
    ``Users should be in control of how their data is used,'' Gates wrote. ``It should be easy for users to specify appropriate use of their information including controlling the use of e-mail they send.''
    ... and the email gets leaked to Associated Press. I guess it's a little too early before we can control who can and who can't read our emails.
  99. Re:Example #2 IE Code by Mr+Thinly+Sliced · · Score: 2, Interesting

    This is an extract from the ie.c file that I managed to pilfer during that source code steal from Microsoft year before last. Revealing it is.

    The lameness filter won't let me post it, so I'm linking to it instead.

    Of particular interest is the peer review process, ensuring quality standards, and upping the end user experience.

  100. Security? by elbles · · Score: 1

    Hmm . . . they say that they're going to improve security, and yet that e-mail leaks out. I am the only one who finds this ironic? ;-) And, before I get flamed, I realize the release was, in all likelihood, intentional, but it still doesn't leave me with a good feeling about this, nor does it make me willing to trust Microsoft. This is exactly what they shouldn't be doing. If you say you are going to make things secure, well, practice that with everything, including e-mail!

  101. Just great! by zulux · · Score: 2

    Now some talking paperclip is going to say to me "It look like you've been R00T3D" and a security 'wizard' will pop up to teach me (in five easy to follow steps) how it unplug my Windows BS Professional box from the network in order to make it secure.

    --

    Moneyed corporations, non-working 'poor' and criminal prisoners are turning productive citizens into tax-slaves.

    1. Re:Just great! by matrix29 · · Score: 1

      Now some talking paperclip is going to say to me "It look like you've been R00T3D" and a security 'wizard' will pop up to teach me (in five easy to follow steps) how it unplug my Windows BS Professional box from the network in order to make it secure.

      And then it will ask you to reboot and connect to the network to see if there is a security update available (there won't be). AND... if you select "Cancel" it will force you to reboot anyway and run you through the identical script.

      --
      "Face it, a nation that maintains a 72% approval rating on George W. Bush is a nation with a very loose grip on reality.
  102. Statistics Avaliable? by Splat · · Score: 1

    Given the recent onslaught of IIS, XP, any Microsoft product holes, has anyone produced charts/statistics detailing the number of holes? Off the top of my head I can immediately think "ok, there's another Microsoft screwup" but I'm curious as to the total number of problems in the last 6 months.

    What I'm really looking for is there a website out there that details the number of holes in IIS vs Apache? The pointy-haired folks at work are looking at webservers and I could use some hard-cold statistics to convince them once and for all IIS is a mistake. Pretty graphs would be really good to show a comparison between the two.

    So.. does anyone know of a site that keeps track of "total" number of holes for any given product (Microsoft AND Open-Source solutions?)

  103. secure vs usability? by Alien54 · · Score: 2
    Other sites have info on the story:

    InfoWorld

    And there is this old item from a security mailing list:

    The reason trusted systems are not being used right is because the way they are written they are UNUSABLE. Only someone who is forced to use them would even consider touching them!

    (seen at: http://www.geocrawler.com/archives/3/90/1995/7/0/4 18940/ )

    Granted, it is old, but is the point still valid?

    --
    "It is a greater offense to steal men's labor, than their clothes"
    1. Re:secure vs usability? by sir99 · · Score: 1
      I don't know the origin, but how about,
      If you design a system easy enough for a fool to use, only a fool will want to use it.
      --
      The ocean parts and the meteors come down
      Laid out in amber, baby.
  104. Poll by Anonymous Coward · · Score: 0

    a. Bill Gates
    b. Steve Jobs
    c. Dubya
    d. Larry Ellison

    (Sorry, no option for Hemos/Taco/Cowboy Neal or George Lucas -- don't want to make things too easy.)

    1. Re:Poll by Anonymous Coward · · Score: 0

      A. most egomaniacal. B. most interesting. C. most stupid. D. most ethically challenged.

  105. PR Problem - PR Vehicle by LaTeXninja · · Score: 1

    Incorporating features into products that aren't blatently obvious and have a lot of marketing value to joe-schmoe helpless user just doesn't seem like Microsoft's style. How are they going to sell security when most of their users won't perceive it?

    I can't see them doing anything different other than turning it from a PR "problem" into a PR "vehicle".

    Get ready to see Windows desktops with secruity-themed graphics and animation.

  106. Re:That GUID on WMP? Yeah . . . by big.ears · · Score: 3, Interesting

    The problem with your "nothing to see here" attitude is that you have to know its a problem in order to change the defaults. If nothing else, this story alerts /. windows users that someone may be tracking them, so that they can change the preferences. And, its ironic that Gates wants Microsoft to be synonymous with "Trustworthy", while at the same time stabbing his customers in the back. Sorry, but I won't trust them with my money or my information, when they are so eager to screw me over for control of my digital media (DRM is the apparent reason for these supercookies), to the point where they would let anybody out there track me.

  107. Beer by rice_burners_suck · · Score: 0, Funny

    Negra Modelo. Because Guiness sucks.

    Now THAT's a flaimbait if I've ever seen one! :)

  108. Mike by Anonymous Coward · · Score: 0

    Don't tell me Microsoft is no longer going to be sellign Operating Systems! I mean afterall if they say that they are going to make the operating system more secure the only way they could do that is to not use any version of MS Windows. Or maybe they are going to steal code from Novell or Unix and make it part of Windows and then claim they invented it!
    Either they will do something along those lines or maybe they will just track everyone on the net and send notifications to you of who just hacked your system and give you their home address so you can go beat the tar out of 'em:)

  109. not PR at all by fafaforza · · Score: 1

    This isnt as much a PR move, as it is a direct answer to a story posted on /. a few days ago about major companies shying away from MS software because of the numerous security problems.

    Sorry for not posting a link. It's late.

    And, yeah, I am sure it was hard to obtain a copy of that email.

  110. Get it right. What MS means is... by Zapdos · · Score: 2, Insightful

    That the digital rights management scheme will be uncrackable, and you will not be allowed to play that digital media stream more then once. Not that the machine will be more secure.

    Security to their customer base does not include you. Only large Coorporations who want money each time you listen/see/smell/touch/etc something.

  111. "Obscure"? by athakur999 · · Score: 2
    To block SuperCookies requires changing an obscure option in WMP which is barely documented.

    Tools->Options->Player->"Allow Internet sites to uniquely identify your player"

    Wow! I'd have NEVER known what it was for, seeing how obscure and undocumented it was...
    --
    "People that quote themselves in their signatures bother me" - athakur999
    1. Re:"Obscure"? by recursiv · · Score: 2

      In other news, to keep linux from being rooted, you have to "apply all kinds of patches and tweaks which are barely documented".

      --
      I used to bulls-eye womp-rats in my pants
    2. Re:"Obscure"? by Zapdos · · Score: 1

      apply all kinds of patches and tweaks which are barely documented?
      Why don't you tell the truth. Just turn off un-needed services. And stay current with your distribution. With redhat that is as simple as up2date to stay current. The book that comes with the distro walks you through service selection. MS's book included with the OS mentions the mouse.

    3. Re:"Obscure"? by minus9 · · Score: 1

      apt-get update;apt-get dist-upgrade

      There you go, now it's documented.

  112. Me don't agree by WildBeast · · Score: 1

    Windows is my desktop OS of choice because of it's handfull of features, ease of use and convenience. When I want a secure OS I'd use OpenBSD.
    If they want to make Windows more secure, they'll have to get rid of some features and make it a little bit harder to use.

    1. Re:Me don't agree by Anonymous Coward · · Score: 0

      I had that attitude too until my machine was infected with Code Red

  113. abandon all hope, ye who enter. by Erris · · Score: 0, Troll
    Maybe they should have thought of this BEFORE they rewrote the OS?

    Rewrite? What rewrite? The one that killed the last 16 bit code, again? When we have seen former M$ programers talking about the "wisdom" that age brings to old code, and then mentioning horrible kludges for device drivers under the awful variety of M$ muck. Their public versioning is nonsensical and makes you wonder if they were ever able to make consistent all of the code from all of the companies they swollowed and chewed up. There's a reason that the 98 souce code had more lines than it takes to run a space shuttle, and it was not useful features.

    Even if they had the desire to rewrite things, they could not. I doubt they have the resources to do so much as an audit. How many people do they have employed right now, a few thousand? How many lines of code are there, 100 million? Let's see if they can impliment something as useful as user ID's and file system permisions in the next two years. All of their sins will look down upon them and laugh as they strugle.

    If history is any guide, they will once again follow the Macintosh crowd and try to impliment a BSD with a "compatiblility mode". If they follow this path, Lindows, WINE, will be targeted for destuction or assimilation.

    --
    DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
    1. Re:abandon all hope, ye who enter. by Anonymous Coward · · Score: 0

      If the do go that rout, they will hid it so well, that you will never know about it....also, the APIs will be so nasty and the kernel so mucked up, that it will not be anything close to BSD.

    2. Re:abandon all hope, ye who enter. by Mark+Pitman · · Score: 2, Informative
      Let's see if they can impliment something as useful as user ID's and file system permisions in the next two years.

      Uh....what are you talking about? Windows NT, which Windows XP is based on, has had userids and file system permissions for years.

    3. Re:abandon all hope, ye who enter. by archen · · Score: 1

      100 million? If they're lucky. Remember it's not just windows we're talking about here, it's the entire MS integration empire. Once again MS's buisness practices come back to haunt it. It's not just the OS, it's everything that is INTEGRATED into the OS, and that is just about every freaking MS application. If MS wouldn't be so bent on integrating everything, it probably wouldn't be anywhere near as hard to secure. Now they'd have to look at breaking many of their major applications just to seal off obvious gaping holes in the system.

    4. Re:abandon all hope, ye who enter. by kiwipeso · · Score: 0

      The space shuttle runs on a 1983 processor.
      Now you could replace the computer with a PDA, each astronaut should have a PDA.
      If they did that, they'd be able to have multiple redundantcy points.

      Microsoft has US$40 billion in cash, they can afford anything, they could even buy a small country if they wanted to.

      File system permissions are not useful, my brother always manages to screw up when I'm logged in as root and make root the only user who can write.

      Apple is ready to do that to them, Darwin is FreeBSD which is made for i386.
      All Apple needs to do to take on microsoft is port Aqua and intergrate virtual PC into the OS.
      OS X intel would then run coccoa apps, windows apps and linux apps in 1 OS.
      Then microsoft would no longer have a monopoly on the intel platform.

      --
      - Kaos games and encryption systems developer
  114. Re:Bloated hacker heaven by Robber+Baron · · Score: 2
    Our arguments have always been based on the fact that M$ windoze is a bloated hacker haven.

    I know plenty of bloated hackers who run linux.


    Bloated hackers hacking bloatware...sounds like something out of Dr Seuss!
    --

    You're using her as bait, Master!

  115. Re:Today's porn count! by Anonymous Coward · · Score: 0

    This might have been a good gimmick, but you pale in comparison to The Turd Report.

  116. Hello, wake up and smell the coffee by Tomster · · Score: 1

    Anyone who believes they have security and privacy in today's world is either ignorant or in denial. Any black hat with a few scripts and a modicum of social engineering can get almost any information about you that's stored in some company or government database/file.

    If Microsoft is truly shifting focus to increase security and privacy, that's great news. There is an awful lot of effort put into recovering from and working around Microsoft products which are too easily exploitable. My guess is the "pain" of lost business due to these security/privacy issues is finally significant enough to justify the effort to address them.

    -Thomas

  117. The IT security community... by chuckw · · Score: 2


    should declare some degree of success. One of their aims was always to raise awareness of security issues. They should congratulate themselves for prompting a thick headed company like Microsoft to dramatically shift their focus. Congratulations people, your hard work has not gone to waste.


    Note: I acknowledge that it was only an e-mail that was sent. The true proof will be in the proverbial pudding.

    --
    *Condense fact from the vapor of nuance*
  118. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    Few months ago, I didn't even know really what this unique GUID was used for.. But I saw it while looking through my registry...

    I had set Windows Media Player to not "Allow Internet sites to uniquely identify your player." I didn't like this idea since I am somewhat a privacy nut (I don't accept cookies unless I specifically allow them from a domain, I use a local proxy to filter out identifying HTTP headers like HTTP_REFERER and HTTP_USER_AGENT.) However, I also notied that I was being branded with a unique ID, so I decided to get rid of it.

    Registry entry:

    [HKEY_CURRENT_USER\Software\Microsoft\MediaPlaye r\ Player\Settings]
    "Client ID"="{xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx}"

    The "Client ID" I changed to "" (null) and other times I have set it to "0". Not sure which is better, perhaps null?

    Anyways, if this is the GUID they are talking about, I wonder if this setting make me safe from being identified in the event that the "Allow Internet sites to uniquely identify your player" setting gets enabled?

  119. Bad For Open Source by deebaine · · Score: 1, Offtopic

    The post automatically assumes that Microsoft is doing this just for the positive publicity. But let's step back for a moment and assume that they're serious. After all, their commitment to features was real. Microsoft products are nothing if not overflowing with features (some of which even work!).

    Microsoft has the human capital to make good software--and secure software. They just don't. Their software is by and large unreliable and insecure. If they resolve these problems, open source is going to have a very difficult battle ahead convincing people that it is the better path. After all, to date, open source has been superior in functionality, security and reliability, while Microsoft has been the superior business. If Microsoft learns to do security (and reliability), open source is going to need to learn to do business.

    Let the flames begin...

    -db

  120. Reliability == security by mjh · · Score: 2
    Check out this reader comment from the January cryptogram. He's talking about liability as a tool for accountability and how that relates to insurance costs, and says, "Insurance costs are directly related to reliability. Show that your software is reliable before you release it, then your liability exposure is diminished." And hence, your accountability is diminished.

    This guy is right on the money. Making security a priority can only be accomplished through making good design and good code a priority. And those won't be a priority unless there's some sort of pressure for it. Lowering insurance costs is one pressure. Positive PR is another. But more powerful than both of those is the pressure to keep customers from switching to a viable competitor.

    And this, I think is exactly the thing we need: a viable competitor to Microsoft. Microsoft, of course, doesn't want this. Interestingly enough, this will also help deal with Rep. Rick Boucher's recent thoughts on the prevention of cyberterrorism. With all due respect to the many good ideas that Rep. Boucher has made, when he suggested enforcing product liability requirements on software producers, he assumed that was the only way to get better software. But it's not. Competition will be much more effective. "When Microsoft starts creating good software, we've won." - Linus Torvalds. Unfortunately, not only is Boucher's suggestion not as effective as competition, it's got a really nasty side effect: it would effectively kill the only potential competitor to Microsoft on the horizon: open source & free software.

    Competition will breed better software. If a competitive market place still produces unsafe products (as was the case with the automobile manufacturers of the '60s) then perhaps new laws make sense.

    The point is that the solution to both problems ("cyber-terrorism" and software security) is competition. If the government is going to do anything, let's encourage them to do something that opens up competition to the MS juggernaut. There currently is none, so make laws that produce competition. If, and only if, that doesn't work, then think about other ways to enforce accountability - like product liability for software producers. But don't put the cart before the horse.

    $.02

    --
    Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
  121. You deserve a -1 /nt by Anonymous Coward · · Score: 0

    So do I for that matter.

  122. Tradeoffs by dachshund · · Score: 4, Interesting
    If microsoft can, by some complex reorganization of their development and review process, make their code have the same, or less, incidence of critical issue as, say, Linux ... What would we do?

    The typical assumption (as I've heard it) has always been that Microsoft's poor security was a necessary side effect of their quick-to-market and add-lots-of-new-feature strategies. Though I don't think most people on this forum view those two strategies as a "good" thing, it appears that they've worked rather well for MS up until now.

    So the $50,000 question is, can Microsoft focus on security without falling behind on those other fronts? And if they have to slow down on their speedy rollout of new products and features, will they suffer in the marketplace?

    If MS can do security and still be as quick-to-market as they were before, they're probably going to be in a very good position. If, on the other hand, they are forced to make a tradeoff-- of speed and quantity for security, for instance-- then it might be a whole different ballgame. Worse yet, they might wind up compromising on both fronts.

    1. Re:Tradeoffs by Sentry21 · · Score: 3, Interesting

      The typical assumption (as I've heard it) has always been that Microsoft's poor security was a necessary side effect of their quick-to-market and add-lots-of-new-feature strategies.

      I think one of the problems at Microsoft (and this was displayed eminantly in a story my uncle (who works big time in multimedia) related to me once, but which I won't repeat in its entirety because I'm tired and lazy.

      In the story, though, there were a team of programmers at Microsoft working on a project (don't know which), and they gave a presentation to Bill Gates himself, telling him when it would ship. He responded by getting angry, and telling THEM when it would ship - bumping up the release date by a huge amount.

      Well, the programmers had to work their asses off to meet the release date. They worked overtime, some burned out, some dropped by the wayside, some quit. Seriously undermanned, they missed their new release date, but the program did eventually get released - on the day that they'd originally said it would get released.

      The only difference is, now they have lost several key programmers on the project, the ones they have like their job far less than they used to, and the code is rushed for no good reason.

      I don't know if this story is true, or, if it is, if that still goes on today, but I get the feeling that it is, at least in part, a good indicator. What reminded me was the mention of 'rush-it-out' philosophy PLUS always being late with their products, both of which are still true today (remember how Win2K/ME were supposed to be WinXP? Remember Win93? Win94?).

      Just my two bits.

      --Dan

    2. Re:Tradeoffs by Ayende+Rahien · · Score: 2

      I'm 99% cetain that this is false, MS isn't known for burning up one of its key resources.

      --

      --
      Two witches watched two watches.
      Which witch watched which watch?
  123. Re:Why Microsoft shouldn't care about security. by Anonymous Coward · · Score: 0

    Holy shit, that started out really hilarious, but all the stuff about billg was gay. Try harder next time.

  124. Tell me... by Wheaty18 · · Score: 0, Offtopic

    Where's the any key?

    1. Re:Tell me... by Anonymous Coward · · Score: 0

      d00d, you're l4m3r planetquake email address marks you as a tool, a homosexual, and an 41mb0t using c4mp3r.

      Shovel hot donkey shit into your mouth, chew thoroughly, swallow the steaming chunks of defecated corn, wash it down with homeless-guy-King-Cobra piss and follow up by gargling on shemale semen.

  125. call me cynical.... by Anonymous Coward · · Score: 0

    When I first heard that XP had a firewall in it, I figured that it probably was just dropping random incoming packets on the floor, and in typical microsoft fashion they said "thats not a bug, its a feature" cause technically it *could* block attacks

  126. security, programmers, human nature... by Chris+Canfield · · Score: 5, Insightful

    It's interesting to note how product teams resisted the security invasion. Now, while we know very little about how offensively these security teams were implemented, it does harken to a truism about coding.

    Properly securing products isn't fun.

    Implementing improved, automatic PGP hooks might be fun (hint hint), but slowly and methodically picking through all of your code to make sure that no buffers can overflow is just uninteresting and unglamorous. If we can't convince ourselves to sufficiently comment the code we write, even though we routinely curse ourselves for not having done it previously, security is going to be unfortunately naturally low on the list of things to do.

    Likewise, an ounce of glitzy new features tends to sell better than an ounce of better security. People are going to look down upon you if you encourage them to upgrade from the old software you sold them by pointing out the security flaws that it had. It's usually more marketable to say "Trust our products, we have new inline spell checking across all our platforms" rather than "Trust our products, we no longer grant root through tcp/ip overflows."

    All of this falls down like a rotten house if you allow your security to get too bad for too long, as is obvious to anyone reading this thread. You can let the support poles wear a little, and usually the cost of a *little* more wear is much less than the cost of fixing the whole thing properly. But unless you have that long-term vision, you'll be sleeping outside eventually. Microsoft didn't, and it is really starting to hurt them. The greatest threat to their monopoly has come from people being unable to use NT in critical applications. You don't want to force your customers to have to go to competitors.

    Microsoft has shown throughout history an ability to expend large amounts of money to get things done. IE... MSN... XBOX... WinCE/PocketPC... If they really do set their mind to security issues, I'm sure that they will be hammered out after several slow, unglamorous years. The press release would make it appear that they know that they are up against human nature on both sides but that the company needs to take action or they will lose their stability.

    --
    This Sig is a mnemonic device designed to allow you to recognize this author in the future.
    1. Re:security, programmers, human nature... by zbuffered · · Score: 1

      If they really do set their mind to security issues, I'm sure that they will be hammered out after several slow, unglamorous years

      But do you really think that they'll have the staying power to do this? Or might they decide 6 months from now that it was "secure enough for the time being" and start piling on more insecure features?
      The real question is, if they're going to do this right, and check all the code and eliminate most every security problem, and check all the code and eliminate most every virus problem(I'm convinced that they could take out Outlook virii in an hour, if there was market share in it for them), how long will that take? What would a secure Windows cost Microsoft? Would they have to start from the ground up in order to do this, or would they be able to insure the security of their existing code?
      I think it's more likely they'll do it half-assed, get it secure enough for Joe User, and say to hell with all-out security. There's likely more money to be made if it's just good enough than if it was nigh on perfect. You're right, if they get off their ass and do this right, a la IE, they'll have great security, and quick. But I doubt they have the motivation to go that far.

      --
      Synergy is your friend
    2. Re:security, programmers, human nature... by AdamBa · · Score: 2
      This part of the article made me laugh: One person with knowledge of the change said new products and features will be tested for security risks before going any further -- if they fail, the feature won't be included. "Things are going to have to go through a crucible, and the crucible will be security-first," according to this person, who spoke only on condition of anonymity.

      Yeah right. What crucible. A buffer overflow is not something a"security review" is going to find. You just have to write the code carefully.

      Compensation plans of Microsoft product engineers, such as raises and bonuses, will also be tied to how secure their products are.

      This gives hope however. Reviews at Microsoft are always just about the last six months, so nobody was ever dinged for a bug that turned up a year after they shipped. But now maybe that will happen.

      More here.

      - adam

    3. Re:security, programmers, human nature... by TummyX · · Score: 1


      Yeah right. What crucible. A buffer overflow is not something a"security review" is going to find. You just have to write the code carefully.


      VC++ 7 already supports automatic buffer overflow checking. More and more MS software will be written using .NET/C# so buffer overflows simply won't happen very often (if even at all).

      Microsoft has the money to make some kind of effect on their software quality. They've done it before. Much of the reason why 2K/XP are stable is because Microsoft went and bought up a code verification company for like 100 million. They ran all their NT code through the thing and found a shitload of bugs that they ended up being able to fix. Remember when the song for Linux was that it was heaps more stable than Windows? That is slowly becoming irrelevant. All mainstream magazines are now touting the stability of XP. Windows 2000 servers are having uptimes of months and potentially years (having to reboot to install some security patches is a fucking pain).

      Sure, no money in the world is going to make their software 100% secure, but their software would be in a much better state (security wise) then it is today.

    4. Re:security, programmers, human nature... by AdamBa · · Score: 2
      If you read the link I included to osopinion, you will see that I worked as a developer on Windows 2000 for Microsoft, and was involved in the security cleanup of the code for Windows XP.

      Anyway the core code is written in C and will stay that way. XP undoubtedly is the most secure OS they have released, but you have things like the UPNP exploit slip through. Not part of the main code, probably written by some college new hire, and no doubt checked in *after* the big security sweep was done (which was just when Windows 2000 shipped). Still that is the only exploit I have heard of in XP so far (excluding Outlook and IIS ones) and may in fact wind up being the only one, because most of the code *was* scrubbed pretty hard.

      But to really drive it home you have to tie it to salary/bonus/option grants because that is the real way people are measured at Microsoft.

      - adam

    5. Re:security, programmers, human nature... by Weezul · · Score: 1

      Dispite all the slashbot nay sayer you are correct that MS *could* fix their security if they wanted, but I don;t believe you when you say that lack of security is costing them money. Care to provide an anrgument for those lost customers? Or perhaps reply to my other post where I claim that lack of security is not costing them customers.

      As I see it Linux and Secure BSD conversions do not count since Linux is not that secure without a good admin and Secure BSD users are so paranoid that they would not run anything else anyway. You really should be looking at Mac and Oracle conversions.. and counting Oracle conversions will require close attention since their product is just so far superior to SQL Server in so many ways.

      --
      The Christian religion has been and still is the principal enemy of moral progress in the world. -- Bertrand Russell
    6. Re:security, programmers, human nature... by Andrewkov · · Score: 2

      Buffer overflows are only a minor part of the security problems. Not leaving ports open that give administrator privilages without a password comes to mind. Also, it seems that most Microsoft security flaws revolve around their scripting tools.

  127. Something I find interesting by Techi · · Score: 1

    It seems that this came at just the right time...Microsoft heard it was soon to be illegal to make stuff that isn't secure. As a public relations tactic, they make sure the public knows they are going to make security a top priority via the associated press. The stories about security being legally mandatory will start to hit television a few days later. To the normal, nonSlashdot person, this looks like Microsoft is taking the initiative, and the federal government is following suit by making such priorities legally mandatory. God, Bill is a business genius... Fortunately, there is still the Slashdot crowd who know what is going on...

    --
    "You think that's air you're breathing now?"
  128. They want you to feel really secure... by Anonymous Coward · · Score: 0

    ...that Winblows will crash.

    The check's in the mail! Oh no - I sent it through Outlook, and I didn't get around to downloading and installing those latest patches - so now all my contacts have my account information!

  129. Does this mean... by Edward+Teach · · Score: 1

    that the whole "Passport" idea is gonna finally disapear? And, will it take "Wallet" with it?

    We can only hope.

    --

    Setting his threshold to 5, Sparky eliminated most of the trolls on /.

  130. No intelligent life. by cornflux · · Score: 1, Redundant

    So far, even though there are plenty 5-pointers, I've yet to see one shining, intelligent, "wow, I never thought of it that way" comment about this subject -- including mine.

    Does anyone else get sick of the same old mantra?

    I'm thinking about watching TV, now... how bizzare.

    Whoa, what the hell did I eat today? Oh, well.

  131. Microsoft can do this if they want to by Animats · · Score: 3, Insightful
    Microsoft can do this.

    First, Microsoft has finally flushed the security-hopeless operating systems (DOS, Win3.5x, Win95, Win98, WinME) out of their product line. The current product line is Win2K and XP, both of which have reasonable underlying security machinery. It's not well-used, but it's there.

    Given a reasonable underlying OS, it's quite possible for Microsoft to arrange things so that all executable content executes in a "jail". More generally, a security distinction has to be made between what the user is doing and what external content is doing, and the OS kernel has to enforce this.

    If MS does this right, it won't matter if IE has security holes, because trouble will get no further than the current IE document.

    We're all going to be doing a lot more forking and IPC.

    1. Re:Microsoft can do this if they want to by Anonymous Coward · · Score: 0

      The benchmark scores are going to go down. Guess they'll just have to cheat or something.

  132. Funniest headline in a long time by Cainam · · Score: 1

    My whole dorm room laughed hysterically at seeing this headline. Shouldn't this be under "It's funny. Laugh."?

  133. New Security Chief? by insipid · · Score: 1

    Pure speculation:

    Is this a prelude to Microsoft losing one of it's security chiefs to the Bush administration? I've read a story or two about some security exec. at MS leaving to become an advisor to the president or some such.

    If MS loses this guy, perhaps they're planning to bring in someone who actually knows something about security.

    I think it's great that MS wants to focus more on security. It's about time.

    What's scary is that someone who influenced the security of MS' products in the past is now going to influence the president.

    Next, we'll put Little Boy Blue in charge of the security of our nation's livestock.

    --

    dp
    ---
    http://insipid.com
  134. I for one by ealar+dlanvuli · · Score: 2, Interesting
    see this as a good sign.

    If he is actually sincere about this, weither or not I choose to use WindowsOS (haha funny pun, ok mabe not /duck) for other reasons, an increase in general security of the Windows Operating System (desktop or server, whatever the diffrence is..) leads to me fretting less at work because some pinhead decided we would impliment such and such deparment using Microsoft products (yes, despite what you teenage idealists think, this DOES actually happen to professional IT people in real workplaces)

    I for one hope that he is really making a buisness decision, not a PR move (no, I'm not saying it dosen't sound like a PR stunt to me). In the past he has decided to turn his company completly on a dime before (internet company anyone?), and he has proven he is a very sucessfull buisnessman and can do such radical things, and come out millions of dollars in the positive.

    Before I get mass flamed, let me clearly state, I think Windows is the worst comercial consumer operating system in common usage, even if you dont include the real operating systems for guru's. But I also think Bill is a great buisnessman (weither or not hes ethical is a far diffrent question)

    Now that we have that cleared up lets look at the problems in WinXP (since I assume they are going to continue buildling from that instead of going back to Win2k, though I think it might be a wise decision for them to do so)

    • File Cache is memory hungry
    • A few suspected memory leaks here and there
    • huge memory overhead (if they didnt increase the current overhead in a few years it would be considered trivial)
    • some UI tweaks wouldn't be harmfull to anyone, just nothing radical (I don't want to spend time learning how to navigate a windows system in the rare situation I use one)
    • Could use some SMP work

    Other than that the majority of all complaints I could honestly extend are security related.

    It is my feeling that if they did a feature freeze on the UI and driver interface and the general configuration setup, and worked soley upon improvments and security (of corse with a small team doing new UI stuff to impress the drooling x-treme programer types), and developed office/IE to use only the documented API (with the API frozen) with both products focused upon security (office is plenty usable as it is, optimization and security would be the best, and the ability to create decent 'other filetype' exports) the OS would mature rapidly

    The things I really hate about using M$ products currently (not because they are closed source, I use plenty of closed source apps, I don't choose my software based upon politics, I choose it upon what works and gets the job done) is that I feel like I'm using a OS that has a lacking kernel, and whils't there are security exploits on my OS of choice (FreeBSD if your curious) they are generally quickly patched, and always workaroundable, not to mention the fact no software I've ever liked has had a major security flaw to my knowledge), there are far more security exploits for M$ windows (mostly dealing with Outlook, an app thats completly banned for use at our company, our daily bat file actually deletes the would be outlook folder if someone did install it, so they can call us up and complain about the errors caused and get promptly chewed out). While using my OS of choice, I feel that if there was a security exploit, it'd be all over everywhere, not sitting in some hackers mind (though that is possible, much less likley) whereas with M$ I feel that there might be a 9 month old exploit that hasn't even made SecurityFocus yet, that bothers me.

    In conclusion, I do think this sounds an awful lot like a nice PR leak, I hope that it isn't. If I liked M$, it would be great, even though I dont like M$, since I'm forced to deal with it on a semi-regular basis, it greatly effects me anyway. This isnt a *nix vs M$ discussion or anything, I'm just stating that in the scope of M$ development, them focusing on security would actually be a good thing in my eyes.

    (ps forgive the I'm sure numerous grammer/spelling errors in this post, I'm typing it while about to go to bed)

    --
    I live in a giant bucket.
  135. I wonder by pornaholic · · Score: 1

    If Gates just tries to make headlines that will make slashdotters stop attacking them for being so moronic.

    Boycot sigs!(DOH!, forgot about the boycott)

  136. Oh brother.... by Anonymous Coward · · Score: 0

    Funny how even when MS starts to focus on the area people (Slashdot) bitch about they still give them shit.

    You know honestly I have come to expect nothing less than biased reporting on issues on this site.

    The news is great, but if it's OS related I don't bother reading past the headline 9 times out of 10, because the last thing I want to do is waste precious time reading garbage.

    Just post the news and lose the opinions. That's what Comment sections are for.

  137. Security & MS Business Strategy by rlp · · Score: 2
    Microsoft has several problems with their business - they need to keep growing their revenue to get the stock price back up to it's pre-recession lofty valuations. In much of the developed world, the market for PC's is saturated. Even worse, people are getting off the upgrade treadmill - new machine sales are down, and XP ain't selling like it's supposed to.


    So, what to do? Switch businesses to a software rental model (stream of income) and get a piece of B-to-C and B-to-B E-Commerce (preferably a big piece). In other words .NET.


    But - for .NET to work, people have to trust Microsoft as an E-Commerce hub, and as an on-line repository of financial data. With all the press on security problems, Gates is watching this trust, and hence MS's chances of succeeding with .NET evaporate. That's what this "focus on security" is about.

    --
    [Insert pithy quote here]
  138. Compensation plans of Microsoft product engineers by Mike+McCune · · Score: 1

    "Compensation plans of Microsoft product engineers, such as raises and bonuses, will also be tied to how secure their products are."

    Hmmm Maybe this is just a way of cutting labor cost to conserve money for legal fees...

    --

    In a world that is Free and Open, who needs Windows and Gates?

  139. Is this just another sales trick? by myov · · Score: 1

    After all, WinXP was supposed to be the "most secure OS ever!", and we know how many holes it has. Plus, I'm sure it was Bill who said something along the lines of "Computer manufacturers have been trying to make software easier to use. The simplest way was to put a sticker on the box that said 'Now even easier to use!'". Will we just get a "Now even more secure!" sticker?

    --
    I use Macs to up my productivity, so up yours Microsoft!
  140. Magooooo by numbsafari · · Score: 1

    Microsoft will focus on security like Mr. Magoo at Coney Island...

  141. The email by Anonymous Coward · · Score: 0

    Every few years I have sent out a memo talking about the highest priority for Microsoft. Two years ago, it was the kickoff of our .NET strategy. Before that, it was several memos about the importance of the Internet to our future and the ways we could make the Internet truly useful for people. Over the last year it has become clear that ensuring .NET is a platform for Trustworthy Computing is more important than any other part of our work. If we don't do this, people simply won't be willing - or able - to take advantage of all the other great work we do. Trustworthy Computing is the highest priority for all the work we are doing. We must lead the industry to a whole new level of Trustworthiness in computing.

    When we started work on Microsoft .NET more than two years ago, we set a new direction for the company - and articulated a new way to think about our software. Rather than developing standalone applications and Web sites, today we're moving towards smart clients with rich user interfaces interacting with Web services. We're driving the XML Web services standards so that systems from all vendors can share information, while working to make Windows the best client and server for this new era.

    There is a lot of excitement about what this architecture makes possible. It allows the dreams about e-business that have been hyped over the last few years to become a reality. It enables people to collaborate in new ways, including how they read, communicate, share annotations, analyze information and meet.

    However, even more important than any of these new capabilities is the fact that it is designed from the ground up to deliver Trustworthy Computing. What I mean by this is that customers will always be able to rely on these systems to be available and to secure their information. Trustworthy Computing is computing that is as available, reliable and secure as electricity, water services and telephony.

    Today, in the developed world, we do not worry about electricity and water services being available. With telephony, we rely both on its availability and its security for conducting highly confidential business transactions without worrying that information about who we call or what we say will be compromised. Computing falls well short of this, ranging from the individual user who isn't willing to add a new application because it might destabilize their system, to a corporation that moves slowly to embrace e-business because today's platforms don't make the grade.

    The events of last year - from September's terrorist attacks to a number of malicious and highly publicized computer viruses - reminded every one of us how important it is to ensure the integrity and security of our critical infrastructure, whether it's the airlines or computer systems.

    Computing is already an important part of many people's lives. Within ten years, it will be an integral and indispensable part of almost everything we do. Microsoft and the computer industry will only succeed in that world if CIOs, consumers and everyone else sees that Microsoft has created a platform for Trustworthy Computing.

    Every week there are reports of newly discovered security problems in all kinds of software, from individual applications and services to Windows, Linux, Unix and other platforms. We have done a great job of having teams work around the clock to deliver security fixes for any problems that arise. Our responsiveness has been unmatched - but as an industry leader we can and must do better. Our new design approaches need to dramatically reduce the number of such issues that come up in the software that Microsoft, its partners and its customers create. We need to make it automatic for customers to get the benefits of these fixes. Eventually, our software should be so fundamentally secure that customers never even worry about it.

    No Trustworthy Computing platform exists today. It is only in the context of the basic redesign we have done around .NET that we can achieve this. The key design decisions we made around .NET include the advances we need to deliver on this vision. Visual Studio .NET is the first multi-language tool that is optimized for the creation of secure code, so it is a key foundation element.

    I've spent the past few months working with Craig Mundie's group and others across the company to define what achieving Trustworthy Computing will entail, and to focus our efforts on building trust into every one of our products and services. Key aspects include:

    Availability: Our products should always be available when our customers need them. System outages should become a thing of the past because of a software architecture that supports redundancy and automatic recovery. Self-management should allow for service resumption without user intervention in almost every case.

    Security: The data our software and services store on behalf of our customers should be protected from harm and used or modified only in appropriate ways. Security models should be easy for developers to understand and build into their applications.

    Privacy: Users should be in control of how their data is used. Policies for information use should be clear to the user. Users should be in control of when and if they receive information to make best use of their time. It should be easy for users to specify appropriate use of their information including controlling the use of email they send.

    Trustworthiness is a much broader concept than security, and winning our customers' trust involves more than just fixing bugs and achieving "five-nines" availability. It's a fundamental challenge that spans the entire computing ecosystem, from individual chips all the way to global Internet services. It's about smart software, services and industry-wide cooperation.

    There are many changes Microsoft needs to make as a company to ensure and keep our customers' trust at every level - from the way we develop software, to our support efforts, to our operational and business practices. As software has become ever more complex, interdependent and interconnected, our reputation as a company has in turn become more vulnerable. Flaws in a single Microsoft product, service or policy not only affect the quality of our platform and services overall, but also our customers' view of us as a company.

    In recent months, we've stepped up programs and services that help us create better software and increase security for our customers. Last fall, we launched the Strategic Technology Protection Program, making software like IIS and Windows .NET Server secure by default, and educating our customers on how to get - and stay - secure. The error-reporting features built into Office XP and Windows XP are giving us a clear view of how to raise the level of reliability. The Office team is focused on training and processes that will anticipate and prevent security problems. In December, the Visual Studio .NET team conducted a comprehensive review of every aspect of their product for potential security issues. We will be conducting similarly intensive reviews in the Windows division and throughout the company in the coming months.

    At the same time, we're in the process of training all our developers in the latest secure coding techniques. We've also published books like "Writing Secure Code," by Michael Howard and David LeBlanc, which gives all developers the tools they need to build secure software from the ground up. In addition, we must have even more highly trained sales, service and support people, along with offerings such as security assessments and broad security solutions. I encourage everyone at Microsoft to look at what we've done so far and think about how they can contribute.

    But we need to go much further.

    In the past, we've made our software and services more compelling for users by adding new features and functionality, and by making our platform richly extensible. We've done a terrific job at that, but all those great features won't matter unless customers trust our software. So now, when we face a choice between adding features and resolving security issues, we need to choose security. Our products should emphasize security right out of the box, and we must constantly refine and improve that security as threats evolve. A good example of this is the changes we made in Outlook to avoid email borne viruses. If we discover a risk that a feature could compromise someone's privacy, that problem gets solved first. If there is any way we can better protect important data and minimize downtime, we should focus on this. These principles should apply at every stage of the development cycle of every kind of software we create, from operating systems and desktop applications to global Web services.

    Going forward, we must develop technologies and policies that help businesses better manage ever larger networks of PCs, servers and other intelligent devices, knowing that their critical business systems are safe from harm. Systems will have to become self-managing and inherently resilient. We need to prepare now for the kind of software that will make this happen, and we must be the kind of company that people can rely on to deliver it.

    This priority touches on all the software work we do. By delivering on Trustworthy Computing, customers will get dramatically more value out of our advances than they have in the past. The challenge here is one that Microsoft is uniquely suited to solve.

    More discussion of our vision for Trustworthy Computing is in the internal white paper at [link deleted]

    Bill

  142. why this is a bad move for microsoft competitors by Anonymous Coward · · Score: 0

    in any large software project, there are four main goals:
    a) ubiquity - getting your product installed and used by as many users as possible
    b) usability - making the interface as easy to operate as possible
    c) security - keeping outside crackers from crashing the system
    d) stability - keeping the system from crashing itself

    in the past, microsoft has put most of its efforts into (a) and (b), and (c) and (d) have been put on the back burner. apple has focused on (b) and (d), and most *NIX systems have made (c) and (d) priorities.

    the reason that this is bad for competitors is that microsoft has $35 billion in the bank, and if they spend a fraction of that on auditing the maybe 5% of apps that are poorly designed from a security standpoint, they really could achieve what they started out 20 years ago.
    Not to mention the fact that an announcement like this is only good PR for them, especially since it comes from Gates himself.

    to be honest, i dont think it'll happen, but i do think it will stall the acceptance of alternatives, i.e. "Let's wait and see if Windows .NET is better."

  143. Just Like Ford... by ruiner13 · · Score: 3, Interesting

    except instead of "Quality is Job #1", it is "security is job #1". And if Microsoft's version of security is similar to Ford's version of quality, we will see massive recalls on M$ products. Only M$ won't have Firestone to kick around for their mistakes. I'm sure they'll blame Roxio, Sun, or Apple...

    --

    today is spelling optional day.

  144. It's also rather misleading by The+Cookie+Monster · · Score: 3, Informative
    From the WMP supercookie bug page:
    To block SuperCookies requires changing an obscure option in WMP which is barely documented.
    That is highly misleading at best, and complete bollox at worst.

    Now I'm someone who will cherily click past a click-through license agreement without reading it, but Microsoft still managed to draw my attention to the existance of this ID, then told me what benifits it gave, and then how to disable it (which I did).
    (They didn't mention the supercookie privacy bug tho :))

    When you install WMP7 it brings up a Privacy Policy dialog (and those words immediately make anyone who would actually care [about web pages being able to collate info about them etc] decide 'this is something I should read') which explains pretty much in bullet points every aspect of WMP that might violate your privacy, what advantge you get by having it on, and how you can turn it off (including the Content Rights Management). You then have to tick an "I have read the privacy policy" checkbox before you can continue the install.

    In that sense "an obscure option in WMP which is barely documented" is complete bollox. However, I imagine it's possible (now or soon) that you could buy a machine preconfigured from the store with WMP7, and not be provided with any information, or warning.

    Windows2000 (SP2) comes bundled with a much earlier version of WMP so no worries there, but I've not looked at XP.

    My question for anyone who has bothered to read this far...
    (I'll word the same question it 3 different ways)

    Is this just a bug, or would the only way to fix this bug defeat the entire purpose of the ID? / Can this feature exist without the side-effect? / Is it a side-effect or just the other side of a double edged sword?
    1. Re:It's also rather misleading by sconeu · · Score: 3, Informative

      Windows2000 (SP2) comes bundled with a much earlier version of WMP so no worries there, but I've not looked at XP.

      Win2KSP2 has WMP 6.4. It's in there.

      View => Options => Player => Allow Internet sites to uniquely identify your player

      Uncheck the box to fix.

      --
      General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
    2. Re:It's also rather misleading by xiangpeng · · Score: 1

      Well, realplayer has it long long ago.

      --
      You must defeat Sheng Long to stand a chance.
    3. Re:It's also rather misleading by The+Cookie+Monster · · Score: 1

      Well, I take it all back then. I guess unless you upgrade to WMP 7 then it is going to be rather obsure.

    4. Re:It's also rather misleading by jo42 · · Score: 1
      > That is highly misleading at best, and complete bollox at worst.

      Bullroar. WMP 6.4 doesn't even have an option to turn it off under NT 4.0

  145. As evidenced by DeveloperStore.com. by dbirchall · · Score: 2
    Microsoft's new focus on security is so intense that they've taken their own developer e-commerce site (developerstore.com) out of service temporarily, after flaws were discovered in the way it used ASP and SQL Server.

    Obviously, focusing on security is a Good Thing. After all, they've made these products and are selling them to all comers - it's good for them to know how to use them properly too.

  146. Somebody's Jealous by Wheaty18 · · Score: 1

    Yup.

  147. Correction: this email only went to Marketing by hoggoth · · Score: 2

    Associated Press- Correction:
    Bill Gates announced to THE MICROSOFT MARKETING DEPARTMENT Wednesday a major strategy shift across all its products to emphasize security and privacy over new capabilities. In e-mail to THE MARKETING DEPARTMENT, Gates referred to the new philosophy as "Trustworthy Computing" and called it the "highest priority".

    Development personnel who heard rumors of this were told go go back in their cubes and stop wasting time.

    --
    - For the complete works of Shakespeare: cat /dev/random (may take some time)
  148. Re:That GUID on WMP? Yeah . . . by Glonk · · Score: 1

    Of course the vast majority don't change the default. Conversely, the vast majority of people really don't care about this feature (honestly!). In general, the only people who care deeply about this issue are the people who would be clueful enough to disable it.

  149. Re:That GUID on WMP? Yeah . . . by alex_siufy · · Score: 1

    What? This is the same stupid mentality that thought the nasty "Smart Tags" thing was OK... "Oh, you can turn it off!".

    I don't care if it can be turned off, it's a bad idea in the first place, it shouldn't even exist!

  150. Security != Anonymous by Anonymous Coward · · Score: 0

    Yes, secure that you can NEVER be anonymous, and MS secure to KNOW they can track or BO you if they want. Important that they make their tracking software secure.

  151. Of course they're serious - they want to be a bank by Anonymous Coward · · Score: 1, Insightful

    Would you trust a bank that got robbed every week? Of course not.

    Microsoft wants to take a cut off every transaction on the web. They want to be a front counter to the banks and the insurance companies.

    People won't trust them to do this unless they are perceived to be secure. It'll take them years to get this right, but their future plans rely on this, so sure they'll start to do it. Their plans for hailstorm and .net rely on them being trusted.

    *offtopic*
    Once they are a portal for banks, this is what will happen. One friday afternoon MS will buy a small bank somewhere. That weekend all their customers will get a button on their bank login "Press this button to transfer your funds to MS bank for a 5% drop in your credit card rates". The banking industry will come into work Monday morning to find all their customers gone. The moral : never outsource your link to your customers

  152. Re:That GUID on WMP? Yeah . . . by kesuki · · Score: 1

    To block SuperCookies requires changing an obscure option in WMP which is barely documented.

    Does that mean I'm obscure? I've been disabling that option for 2 years since I stopped bothering to download 'AOL' winamp on windows boxes. I mean it's hidden right there in plain sight. Although most of my mp3s I listen to using xmms, since it's easier to control over telnet.

  153. Microsoft pays lip service to security by Anonymous Coward · · Score: 0

    The subject line was a false statement. MS will not focus on security, at least not to close it up. They will continue to focus on securiy in ways that they can destroy any sense of privacy and security, even to the extent of making their own products vulnerable deliberately, so that they can hijack tcp/ip and make themself the Internet gatekeeper. .NET certainly isn't about anyone's security, it's about MS trying to own the net, and I haven't seen any anouncement that they are abandoning it.

  154. How will we know if the new initiative worked? by bonch · · Score: 0

    Just a thought. If Microsoft has its way, we won't hear anything about bugs and security holes in its products because of its discouragment of disclosing such information. So, no matter what, Windows will seem more secure, because we'll hear less about its problems.

  155. Now now, be nice... by coupland · · Score: 2

    Guys this is not a case of "big bad company wants you to think they care about security but they really don't" as the posting suggests.

    This is unequivocally a case of "big bad company finally realizes their biggest PR nightmare and has no choice but to finally take security seriously."

    Don't think for a minute Gates' e-mail wasn't prompted by a genuine desire to improve security. M$ has finally realised the financial implication of crappy code.

  156. Here's what this means... by Polo · · Score: 3, Flamebait
    Robert X. Cringely has already predicted that this would happen in this article. An excerpt:

    Microsoft wants to replace TCP/IP with a proprietary protocol -- a protocol owned by Microsoft -- that it will tout as being more secure.
    1. Re:Here's what this means... by Anonymous Coward · · Score: 0

      By varying TCP/IP they possibly could make it more secure.

      Introducing their own proprietary transport protocol for internet communications could be one of many things to be called "security initiatives" by Microsoft.

    2. Re:Here's what this means... by Anonymous Coward · · Score: 0
      Probably even Nostradamus predicted it.

      It's easy to try to apply predictions, but I didn't see any mention of Microsoft working on an alternative to TCP/IP.

    3. Re:Here's what this means... by Polo · · Score: 2

      Hmmm... I wouldn't have thought Cringely's articles are flamebait.

      He continues this week with Well, then here's What's Really Behind Microsoft's New Commitment to Data Security

  157. No. by Anonymous Coward · · Score: 0

    A swing and a miss.

  158. Trolls by LS · · Score: 1, Flamebait

    A note to moderators:

    The recent trend is to rate poorly argued points as trolls. For instance, someone will make a statement without much thought, but is serious in all respects, and gets moderated up. When someone else comes along and smashes this person's argument, the first poster then gets marked as a troll.

    This moderation behavior serves to stifle dialog and downplay any positive points the first poster made.

    Remember, a troll is post which attempts to illicit responses from others under the pretense of discussing the issue at hand, not a poor argument.

    LS

    --
    There is a fine line between being a cultivated citizen and being someone else's crop. - A. J. Patrick Liszkie
  159. if they are serious..... by catbutt · · Score: 1

    What they should do is:

    Allocate $5 million a year (pocket change for them) for rewarding people who find security flaws. They can hire an independent 3rd party to manage the submittals and decide how to split up the money each year. Those who wish to collect have to go through a process of reporting the flaw that is official, and doesn't release it to the public before they have time to fix it and people have time to get the patch.

    The key is having the 3rd party really be independent. Maybe elected by a committee or something. Somebody could figure out the details....but this shouldn't be hard to do in a way that MS's corporate interests are not causing a conflict.

  160. Re:When... by Slak · · Score: 2

    This crowd won't ease off Microsoft GPLs its software. All of it. And issues royalty-free use of any of its patents.

    Interesting thought experiment, but don't hold your breath waiting for the reality to appear.

  161. Re:That GUID on WMP? Yeah . . . by Glytch · · Score: 1, Redundant

    End users are not the customers. PC manufacturers and server vendors are the customers.

  162. Microsoft's Acceptable User Parameters by i_am_nitrogen · · Score: 5, Funny
    "Users should be in control of how their data is used" -- Bill Gates

    Translation: [serious] Users should be made to think that our ideas of how their data should be used are also their ideas.

    -or-

    [humorous] Microsoft should be in control of how its users are used.

    Seriously, though, all those who fit Microsoft's definition of user already think they are in control of their data. They believe that Microsoft provides them freedom to do what they want. Look at those Windows XP flying commercials. People actually believe that stuff. Just a thought.

  163. Re:That GUID on WMP? Yeah . . . by chancycat · · Score: 1
    One of my main roles is security and being on top of the issues - and I missed this one. Doesn't say much for me. Damn.

    Just think of all the normal users who leave the defaults!

    --
    Evan - needs to hit preview before submitting
  164. What MS could do... by psych031337 · · Score: 2

    ...to take the main insecurities out of their operation:

    Breed a brother of clippy. Make it look like a string of barbed wire and name it, well, Barby (or appropriate alternative to avoid Mattel lawsuits).

    Bring in Barby every fucking time the user tries to do something potentially harmful (like choosing the "Remember password" function, opening an attachment, sending out more than 1k of data to the net, ...)

    That would at least teach people some sense of security about their system. Hell, most car manuals even remember you to keep your car locked at all times it's not in operation and to remove the key from the ignition NO MATTER WHAT. It seems all so logical to thinking people, but most people don't want to think. They want someone to remind them. Still, some people leave their cars idling when they jump into the 7-11, but there is always stupid morons. Those who strictly obey rules had them hammered into their heads or learned it the hard way. Same should apply to OS'es.

    --
    +++ath0
  165. Re:That GUID on WMP? Yeah . . . by whereiswaldo · · Score: 1

    I'd like to add to that. Should the default be changed, they often make it really, REALLY annoying to deal with.

    Best example: Change your Cookies setting to "prompt me" and visit any site that uses cookies. You will be prompted a million times to accept or reject a cookie.

    Another great example: Browser plugins. I don't want Flash 5 on my system. I don't need it. So, I keep saying "no" when it asks me if I want it. It asks me again and again, doing its best to drive me up the wall (or get it driven across the room).

  166. NEWS FLASH by karmaflux · · Score: 1
    Seventeen-year-old John Q. Slashdotter was recently tracked from www.google.com to www.everything2.com to www.persiankitty.com. The malicious advertising company who tracked him indicated they plan to destroy his very soul with the information they gleaned from his supercookies.

    No, wait, that makes no sense.

    Network users who irresponsibly allow websites to run whatever scripting they want may face privacy issues with ANY SOFTWARE AT ALL.

    Yeah, that sounds about right. Watch your back, or someone else will. This is nothing new.

    --

    REM Old programmers don't die. They just GOSUB without RETURN.

  167. Bullshit bullshit bullshit by freeweed · · Score: 2, Redundant
    `Users should be in control of how their data is used,'' Gates wrote. ``It should be easy for users to specify appropriate use of their information including controlling the use of e-mail they send.''

    This is precisely what led to Outlook Express being such a useless piece of *&*#& to use: allowing the SENDER to specify how email is used. Sorry Bill, but allow the RECEIVER to control this. Spam, 4MB attachments, and OE viruses/trojans/worms are all a result of the sender being in control.

    Just write me a damn email client that lets ME choose what to receive, and how to display it. Wow, amazingly 99% of the problems with OE disappear!

    --
    Endless arguments over trivial contradictions in books written by ignorant savages to explain thunder in the dark.
  168. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    > Best example: Change your Cookies setting to "prompt me" and visit any site that uses cookies. You will be prompted a million times to accept or reject a cookie.

    Um, duh. It's prompting each time the site tries to send a cookie. That's what you told it to do. A lot of sites are dumb and send dozens of cookies for no good reason. Run netscape and tell it to prompt you when you receive a cookie. You'll get the same thing. Perhaps you wanted to try enable/disable cookies on a per site basis instead of just prompting?

  169. Here's another spin... by hacker · · Score: 2, Insightful
    Has anyone actually thought of the Open Source implications of this? Before you mod me down, please listen.

    What if, by persuing this "Trustworthy Computing" avenue, the existing Microsoft customers begin to believe in Microsoft. They rally around the "vision", and start extending it.

    "Yeah, let's make sure all software has to be 'Trustworthy' too!"
    Now a committee is created to "audit" all released software (funded by guess who), and Open Source software will now be subject to "approval" by a committee, probably via a pay-only system of review applications. Now this slows the release of Open Source software to a crawl, or stops it altogether, because most of us do not get paid for our work, nor can we afford to submit our releases for review. If we can, we're going to be damn sure to close every hole, therefore slowing down the frequency of releases.

    I, for one, hope this is not their intent, but Microsoft has always had an alterior motive with every single action they've taken. Having Bill Gates declare it so publically and firmly, leads me to believe he has some other motive here.

  170. MSLinux a reality? by erroneus · · Score: 2

    This announcement has brought out all levels of commentary so far... some saying "not gonna happen" or "impossible." Some are saying "if they really want to do it, they can and they will."

    I sit in the second camp... mostly. But I tend the think that they will not be able to deliver on the promise for at least a couple of years.

    In order for them to deliver on the promise, they will have to radically redesign their OS from the inside out and I doubt they have enough of the original coders around who can remember what they did to mess it up in the first place.

    On the other hand, they can simply write an entirely new OS or build one from existing stable OSs. Making a BSD derrivative first comes to mind. And why not? Just do what Be did. Write up some support for NTFS, a little migration and throw up a really nice GUI interface that looks like Windows always has and they're 90% done.

    Is it possible? Very. Is it likely? I just don't know any more -- it depends on how serious they are.

    I'm a Linux fan -- I use it when I can and when I'm comfortable. I also use MS Windows for things too... especially Japanese language support. If they can deliver on their promise, I'll use the product. (Am I actually saying this?) Yeah that's right, I'll use it.

    But I guess they would have to satisfy my own expectations -- make it more Unix like. Quit using backslashes!! What's with the stupid A:, C: crap? You just limited yourself to 26 drives... freakin' brilliant.

    Okay, it's late and I'm tired. I actually hope they can pull this off but I have my doubts that it will be anything that benefits the consumer more than it benefits MS's own purposes... I hope they can deliver my dream OS, but I just can't believe in it yet.

    1. Re:MSLinux a reality? by bsartist · · Score: 1

      In order for them to deliver on the promise, they will have to radically redesign their OS from the inside out

      Yeah, that would be as hard as porting the Macintosh to a BSD personality running on a Mach microkernel. No one could ever do that.

      --
      Lost: Sig, white with black letters. No collar. Reward if found!
  171. You missed his point by FastT · · Score: 2

    You missed his point. Just as the personal data about ourselves should belong to us, Microsoft fundamentally believes that the music you listen to, the video you watch, and the software you run are not your data. They are other entities' data, who only grant you a limited license to use their data as they see fit.

    --

    The only certainty is entropy.
  172. Re:That GUID on WMP? Yeah . . . by Ilgaz · · Score: 1

    I don't get one thing. The self called security specialist Steve Gibson has effected many newbies not to install Realplayer, because umm... It has GUID _support_(by default, OFF)You will hardly believe what you read after this story http://grc.com/media.htm

    As I now see, Wmedia player comes with GUID enabled by default? Which sort of a non-techie end user would "touch something which is already working" (e.g. listening to his/her radio w/o any problems)?

    My point is, besides Grc being pointless and evilly conspires Realplayer for unknown/I don't care reason, he uses this argument to call people to switch to Windows Media, which, hardly you will find a native Linux/BSD version. So, here is your answer, GUID is importmant...

    Oh, btw, people seems to miss the point that GUID is used by broadcasting companies which broadcast, not by those application vendors.

  173. Take this seriously by bsartist · · Score: 1

    This should be taken seriously, folks. Think back - The WWW caught MS napping. They never saw it coming. And yet, in just a few years, Bill turned the company around to face the "threat," and now there is serious talk of a MS-dominated internet.

    There's an old saying that goes "familiarity breeds contempt." It's all too easy to dismiss MS as incompetent - easy and foolish. MS hires hordes of the best and the brightest programmers anywhere. The numerous security holes in current MS products are not the result of idiotic programming, they're the result of idiotic policies, dictated from the top, that emphasized features over security and stability.

    With the rising sentiment against "bloatware" and security problems, MS can address two customer demands at once here. MS has successfully made huge and abrupt changes in strategic direction in the past, and there is every reason to think that they could do so again.

    --
    Lost: Sig, white with black letters. No collar. Reward if found!
    1. Re:Take this seriously by I+The+Man+in+Black+I · · Score: 1

      If a house is designed/build by the best architects and builders... but in the middle of a swamp, the house will sink none the less.

      Tomas Beaujean (a.k.a. The Man in Black)

      --

      <sig>what-mib-says | mib2english</sig>
    2. Re:Take this seriously by SuiteSisterMary · · Score: 2

      I remember the same sentiment a few years back, when, after saying the Internet wasn't even a consideration, that they were turning their company around and focusing on the Internet. Everybody laughed, and didn't think it meant anything. They aren't laughing now. They all laughed when Microsoft said they were 'betting the company' on NT5/2K technology. Well, they did. 2K. XP. Xbox. It's all NT5 tech now. And now they're saying that they're going to turn around and focus on security. Well, a while ago they put out Internet Security and Acceleration Server, aka Proxy Server 3. And it was NICE.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
    3. Re:Take this seriously by frleong · · Score: 2
      Whether MS is doing this sincerely or not, billg fully recognizes that unless they fix their poor security records, their future is a deadend and their business will no longer be profitable.

      There are two ways I can think of:

      • Buy all the media and news agencies - security flaws will ever surface from the media. This is almost impossible (we have at least AOL Time Warner, which is not so MS-friendly).
      • Really improve their products so that they no longer be the frontpage of security bug news.
      --
      ¦ ©® ±
  174. Some moderators need a visit from the clue fairy by i_am_nitrogen · · Score: 0, Offtopic

    How is it that somewhat-well-thought-out, sincere, calmly worded posts get moderated as a Troll, while arrogant, conceited, poorly worded, angry posts are moderated as Insightful?

    Don't bother moderating me.

  175. Microsoft Focus by _Sprocket_ · · Score: 3, Interesting
    Honestly, and not trying to troll. What will everyone here do if microsoft ceases being the evil empire?
    Microsoft has a LONG way to go before they manage this. However, the company has turned on a dime before. If there is anyone who can do it, its them. But the changes will have to include technical and cultural shifts that go against years of activity that has defined the current Microsoft.

    But what would Slashdot do if Microsoft changes? They'll go on. Slashdot is not the anti-Microsoft site. There would be plenty of other news if Microsoft dropped out of sight tommorow. Microsoft just manages to do things often enough to become a prime subject of this community.

    Microsoft constantly stands out from their peers. The IT industry is full of large, powerfull corporations. They all put out products that could have their merrits debated. They all make marketing claims, promise things to their customers, and set company policy that impacts end users (including Slashdot readers). Yet somehow Microsoft manages to raise to the top.

    Sure, there is over-the-top bashing of Microsoft (ignoring Microsoft's own PR, reputation for FUD, and zelous proponents). But there are also lots of legitimate grieviences ranging from product quality to Microsoft's marketing tactics.

    Microsoft gets attention because they deserve it.

    When Microsoft changes its ways, they will fade in to the background with other industry leaders like IBM. And the news will march on with or without them.

  176. Re:That GUID on WMP? Yeah . . . by whereiswaldo · · Score: 1

    Before you go "um, duh" think about it first.

    I know what it's doing in the background. For each image it's also trying to set the cookie, too, probably because of automatic session handling on the webserver.

    Run netscape and tell it to prompt you when you receive a cookie. You'll get the same thing

    That's what my whole post was trying to say. I use Netscape 4.76, which I should've mentioned. There is no way to enable/disable cookies on a per site basis in that browser. Mozilla has a nice per site feature, but too bad the developers are still trying to get the "find" dialog working properly. :-/

    It cracks me up that Microsoft disabled Java support in XP for "security reasons". Probably removed the most secure part of their OS by doing so.

  177. If Microsoft is serious, privacy is doomed by phr2 · · Score: 2, Interesting

    If Microsoft is serious about security, they'll supply encrypted file systems and encrypted email that are easy to enable and use, and suddenly vast amounts of email traffic will go "dark" to eavesdropping and wiretaps. The FBI tolerates some geeks using PGP now, but will completely flip out if it's deployed on the scale of Outlook encrypting everything by default. Legislated, mandatory key escrow will be a done deal. Ashcroft will read our mail forever.

  178. Re:That GUID on WMP? Yeah . . . by wadetemp · · Score: 1

    It's also standard user behavior not to care if someone can ID thier media player. Caller ID ID standard users by phone number (which can be used against them in fraud), license plates ID the cars of standard users (which really sucks if you kill someone with your car.... they can find you!) and drivers licenses ID standard users themselves (again, for the same reason as license plates, this can suck.) Prove to me that everyone is against this "terrible" thing that MS is perpetrating, which is no different than placing IDs on millions of other common everyday things... then I will understand why this particular default is right up there with corporations losing millions of dollars because of NT servers being broken in to.

  179. Re:That GUID on WMP? Yeah . . . by prockcore · · Score: 1

    That's not true at all.. if you read the posts on bugtraq, then you would've seen that turning the GUID off barely helps at all!

    WMP generates a new ID not every use, but every session!

    It doesn't generate a new ID until you close IE and reopen it... so they can still track you until you close IE.

  180. GUID by Anonymous Coward · · Score: 0

    The GUID is a privacy problem, not a security problem.

  181. But people will believe him by bunhed · · Score: 1

    Perfect security is a joke. If it could exists, there would be no police. Of course Windoze has holes in it, so does Linux and any other software you can name. People are fallible and programmers are people (well most of them are ;) The thing that burns me up is that people will actually believe they are safe because of this tripe. Computers are not safe. Period. Never will be. If you have a door, it doesn't matter how many locks are on it, if somebody wants to get in, they will get in. Don't leave your valuables in your house. It's simple. All this natter on /. about what a goat f**k windows is does nothing to educate the saps who buy this stuff and don't know any better. Tell your friends, your aunts and uncles, computers are not safe for important info and never will be. Oh yeah, all your money is in some computer somewhere isn't it? I guess no one wants to hear this.

  182. Being afraid is the way to lose. by Rooktoven · · Score: 1

    Wary yes, but afraid? Fear leads to acquiescence. The only way to defeat a bully without principles is to defy that foe at every turn. Make no mistake, Microsoft is potentially the greatest threat to to the free flow of information in the world. Only in relentlessy, loudly, and repeatedly calling Microsoft to task for every attempt to control markets and information, and in supporting alternatives to the MS poison at all times can proponents of the free flow of information hope to succeed.

    No, it isn't a laughing matter. But believing a Microsoft victory is fait accompli is akin to collaboration.

    --

    Acquiescence leads to obliteration
  183. Re:That GUID on WMP? Yeah . . . by dcd · · Score: 1

    I had the option turned off and the demo tool
    still was able to extract a UUID code

  184. babblefish v.666 by Anonymous Coward · · Score: 0

    .NET = The Mark of the Beast

    I've been wondering if you will need your .net passport to get food and do business in the future. Could Gates be the antichrist? Signs point to yes.

    [HAIL GATES]
    I for one welcome our new master. jk.

  185. This is why i use Macintosh by obi-1-kenobi · · Score: 0

    What i don't know can't hurt me right?

    --
    "You win again Gravity!" -Futurama (Zapp)
  186. Microsoft's Different Challenge by _Sprocket_ · · Score: 2


    Is this in the same vein as the day Bill Gates ordered everyone at MS to stop what they were working on and concentrate on how the Internet would affect their products?


    Sure. But this isn't the same target.


    Microsoft went after the Internet in the same manner they targeted other markets. It was a simple matter of identifying the target and applying the same business tactics they had been honing on other products / markets.


    And it is some of these tactics that has caused the security issues they have today.


    Microsoft will not be able to rehash their usal bag of tricks to win this new target. It will take some fundimental shifts in Microsoft's philosophy and culture. This will greatly affect their development. It will blind-side their marketing.


    Microsoft began attacking the internet market by leveraging their name/reputation, new features, and quiet agreements (to name three). This fails in the current security environment.


    First, Microsoft have found themselves with a failing reputation. If they hadn't, they wouldn't be taking these actions. But now, Microsoft security issues are making headlines in tech journalism. Microsoft can no longer dust these issues under the carpet just because they're Microsoft.


    Microsoft's security woes have little to do with new features. If anything, it is their drive to add features without proper consideration towards security (and bug hunting) that has caused their trouble.


    Microsoft has already began trying to control their security problems with quiet agreements. But keeping major security companies quiet will not end their problems. The infosec industry is full of small groups and individuals who have numerous reasons to discover and publish vulnerabilities in Microsoft products. Sometimes these entities are doing what they consider a public service. Other times it involves making a name for oneself or business. But in any case, vulnerabilities will be found and the media will pick them up and report them as it makes a good story.


    If Microsoft is to be successful, it will require a major shift. A shift they have never done before, Internet or no Internet.

  187. Am I going to trust Microsoft? Ever? by warpeightbot · · Score: 4, Interesting
    To state the obvious, not no but hell no.

    Why?

    Because I know how Bill Gates' mind works, and if I can't see the code, I'm not going to run it. Yes, us Linux sysadms have a rep for being paranoid bastards. Yer damn right we are, and proud of it. That's what's kept me virus-free and crack-free the last five years, watching boxes powered by You Know Who drop like flies.

    Linux isn't perfect, no, but it'll take him a minimum of 2 years to get his codebase in order even with the army of people he's got.... and by then we'll have our world domination, and they'll be putting Linus' picture behind that Borg eye rather than Bill's. We might even get Mozilla to 1.0, who knows.

    But, seriously. Even if l0pht and friends were to publish with much fanfare, "holy penguins! I can't crack this thing!" I still wouldn't buy it, and not just because I'm opposed to getting on this $100 every eighteen months to upgrade kick.... Not when I can run a product I personally helped design if not build. And can look at the code and see that it is good... or fix it if it's not. And there's huge advantages to being able to talk to the guy that wrote it.

    Real-life situation, several weeks ago. I had a problem with the Mylex raid driver. Sent email to the guy who was listed in the headers for the source. A little email tag ensues. Eventually he sends me a patch. cut, paste, compile, init 6. Blammo. It worked. Total elapsed time, about 48 hours.

    You will never get that out of Microsoft. Ever.

    Then there's the principle of the thing. The Borg's stated objective is to take over the world and have it for his own. I'm not giving aid and support to that cause. I'm giving aid and support to another guy who wants to take over the world... and set it Free. I may be pagan, but there are some altars at which I will not kneel. Far more likely to torch'em.

    --
    Nuke'em from orbit.
    It's the only way to be sure.

  188. re: "We're finally concerned" Security Propaganda by Anonymous Coward · · Score: 2, Insightful

    This is most likely nothing more than the prelude to a new product line, imagine the possibilities...

    M$ Firewall Pro, M$ Firewall Enterprise,
    M$ Secure Server XP Advanced, M$ Antivirus,
    M$ Secure Outlook, M$ Secure Browser,
    M$ AntiHack Pro Deluxe, M$ IIS, Secure Edition

    On the other hand, probably not.. that would be an admission that their software wasn't secure to start

  189. Time flies... by Zeekamotay · · Score: 0, Troll

    Wow, is it April 1st already?

  190. Re:That GUID on WMP? Yeah . . . by Arker · · Score: 2

    Even in WMP6.x.

    Where? I'm holding onto 6.4, tried 7.x and really hate the GUI. I can't find this option anywhere. Can't find the registry keys either. There is a "user id" in there though.

    --
    =-=-=-=-=-=-=-=-=-=-=-=-=-=-
    Friends don't let friends enable ecmascript.
  191. Ha.. I just dealt with this the other day! by Anonymous Coward · · Score: 0

    I was at a client's site and they said everyone who was running Windows XP could not access shared network resources or share resources themselves. They said they were at their wits end trying to figure it out. Turns out each one of these machines had the *NEW* Microsoft Windows XP Personal Firewall enabled.

    Ha... It makes me laugh! They are not going to even be able to pull this one off without looking dumb!

  192. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    Random number? Turning the option off, I still get the same hexnumber every time on 16 of the 28 letters. 16^16=1.8*10^19 which is more than enough unique id's to track all computers in the world.

  193. Re:That GUID on WMP? Yeah . . . by doug363 · · Score: 1
    You can change the Client ID string to whatever you like. I changed mine to a string quite a bit longer than the original GUID. (You never know, it might even cause a buffer overflow or trigger another bug on some dodgy web server. Heh.)

    Of course, the best thing to do is for everyone to use the same ID. :)

  194. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    [HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\ Player\Settings]
    "Client ID"="{xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx}"

  195. And So The Story Goes... by istartedi · · Score: 2, Interesting

    PR Man (PR): I've just completed that study you asked for, the one on why the Slashdot editors hate us.

    Bill Gates (BG): Can you give me the executive summary?

    PR: It's because we don't place enough emphasis on security.

    BG: Fine. We'll do more about security.

    6 months later

    PR: I've just completed that report on why the Slashdot editors still hate us.

    BG: And?

    PR: It's because we place too much emphasis on security.

    --
    For all intensive purposes, "whom" is no longer a word. That begs the question, "who cares"?
  196. Link that works, no registration� by kiwipeso · · Score: 0
    --
    - Kaos games and encryption systems developer
  197. Right! by CaptainZapp · · Score: 0, Redundant

    And the earth is flat, pigs can fly and nuclear power is safe.

    --
    ich bin der musikant

    mit taschenrechner in der hand

    kraftwerk

  198. OT:How to get the word out by maggard · · Score: 1
    Wow - cruising along at +5 for 12 hours (Moderation Totals: Interesting=1, Funny=4, Total=5.) then 4 "Trolls" in ~30 minutes.

    Guess some antisocial weenie thinks he's clever for anonymously whacking someone, color me unimpressed.

    --
    I don't read ACs: If a post isn't worth so much as a nom de plume to its author then I wont bother either.
  199. Re:That GUID on WMP? Yeah . . . by istartedi · · Score: 3, Interesting

    The defaults are everything,

    Will you remember that the next time somebody installs a Linux workstation with every daemon in the world running?

    --
    For all intensive purposes, "whom" is no longer a word. That begs the question, "who cares"?
  200. Listen to Slave 4 U? by kiwipeso · · Score: 0

    I always watch that on channel V
    Damn, britney's hot!

    --
    - Kaos games and encryption systems developer
  201. Its a security problem by Nailer · · Score: 2

    It's not a security problem. It's a privacy problem.

    Pardon? Security is about protecting assets. Is a list of all the music, video, and web sites I view not an asset?

    I don't think so.

  202. Re:That GUID on WMP? Yeah . . . by Arker · · Score: 1

    Ok but how do you turn it off?

    --
    =-=-=-=-=-=-=-=-=-=-=-=-=-=-
    Friends don't let friends enable ecmascript.
  203. Timing is perfect... by Anonymous Coward · · Score: 0

    Don't you think they DO have the abilities and money to really make Win secure? And the timing IS good. As we see from Window's popularity, security is not the most expected feature of a system. MS has first made Windows popular, not bothering with such silly features as security - noone demanded it of them. And now, when people start to wake up MS will simply do what people want, i.e. they will make their system secure. It's so simple. Why shouldn't they actually concentrate on it now, that they are a monopoly? They can afford it...

  204. Bad for reputation by JavaPriest · · Score: 1

    I believe it is impossible to write a completely safe OS or other application: there will always be some way to break into a system. People can only make it harder to do so. Security is only a feeling...

    My real question is whether it will not terribly hurt Microsofts reputation when, after declaring their software "safe", somebody manages to break in. Look at Orcale, they declared their 9i suite "unbreakable" but in the meanwhile they have had their share of vulnerability discoveries (like here).

  205. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    it was the default that i stabbed a knife into you and killed you. if you asked me not to, surely i would have listened and not done it! LOL. hehehe. microsoft. heheheh.

  206. A slightly different view on this... by rediguana · · Score: 4, Insightful

    Look at it this way. Developed countries have a set of systems that can be defined as critical infrastructure. These maintain the operability of a nation on a day-to-day basis. If any of these systems break down, then society will follow down too.

    Some examples? Well... water, power, sewerage, welfare, health, emergency services, police and justice, banking, government, communications, and one of the latest additions would have to be IT.

    IT must been damn close to being critical infrastructure, if it isn't already. We all know MSFT is very dominant in Operating Systems. Their systems are being used within many of these critical services, which would tend to suggest that MSFT is already inextricably linked to the other critcal infrastructures.

    Already countries overseas are opting for alternatives to MSFT because of some of the risks that their products provide. Govt's of Germany, France, and others are looking for more 'trusted' IT products - partly for cost, but also because some of the systems are critical.

    MSFT didn't have any choice but to accept security, much as they had to accept the Internet in '95. If they didn't, they would see dwindling market share, and their products being dropped from IT solutions involved in critical infrastructure. So, they have to get on the 'trusted' bandwagon to maintain market share. Govt's do spend a bit of money on IT after all.

  207. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    Check the NTBugTraq archives, there was something considering that a few days ago.

  208. Re:That GUID on WMP? Yeah . . . by vrt3 · · Score: 2
    You can turn that ID off. Granted, they should make it default to off.

    According to what I read on bugtraq, Internet Explorer is vulnerable even if you don't ever use the windows media player. I always browse trough all options of programs I use, but I can not be expected to look trough all options of applications I never use, do I?

    --
    This sig under construction. Please check back later.
  209. Re:That GUID on WMP? Yeah . . . by ignorant_newbie · · Score: 1

    i will, for one. this is why my machines don't run linux anymore, either. see www.freebsd.org, www.netbsd.org, www.openbsd.org for more details..

  210. Somthing bad.. by Anonymous Coward · · Score: 0

    My bet is that they have found somthing really bad that effects all of their products and they need to take the time to fix it before someone finds it out and nails them to a cross..

  211. Re:That GUID on WMP? Yeah . . . by flerchin · · Score: 1

    Ok, I know you said 6.4, but since no one who has that version even tried to answer ur question i'll give it a shot even though I've got 7.01. Go tools-> options in the player tab uncheck "allow internet sites to uniquely identify ur player".
    Hope this helps!

    --
    --why?
  212. Along the same lines as... by jaavaaguru · · Score: 0, Offtopic

    Pope to support Atheism.

  213. the future.... by Anonymous Coward · · Score: 1, Funny

    Some disgruntled guy will assasinate Bill Gates and the world will celebrate....

    Will be replaced by someone who has Linux roots....

    Orders complete recoding of Windows, ease of use of Windows, Stability/Security of Linux...

    Years later, Windows LX is released, with praises coming from /. peeps...

    World enters a Golden age...

    *Me waking up* OH FUCK!

  214. MS launches Project Sphincter by JerkyFlake · · Score: 0, Troll

    I have it on good authority that this new thrust into the security realm has been code named Project Sphincter. It will pinch off any attempt to probe your ports. Hopefully they are putting enough muscle into this endevore to block access to the internals of Windows OS. 0->*

  215. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    Most distros don't install every daemon running anymore. Yes, they did in the past (particularly RedHat) - but the Linux world evolves rather rapidly, and Mistakes Get Fixed. There's no corporate pride or marketing image to worry about - we all know the old all-daemons way was a mistake, we admit we made it - we fix it ASAP, and move on.

  216. Story's moved by PhilHibbs · · Score: 4, Informative
  217. Security aint easy for MS by geoff+lane · · Score: 1

    First, bolting on security to existing products will fail. It's impossible to close up badly designed software.

    Secondly, MS relies on open (as in open door flapping in the wind) systems to rapidly deploy new innovations. As people have pointed out defaults rule and if the default is a closed system many innovations would get nowhere as few users would switch them on.

  218. I don't get it...... by CrabCakeJimmy2k · · Score: 0

    Most of you people have been bitching for years about MS products instability. So they worked on that problem and licked it. If any of you try and say that 2k or XP isn't stable, I'll call you a biased liar. I have been using 2k or xp for over a year and a half and have yet to encounter a problem that couldn't be fixed with the task manager. My 2k server has been up and running for 194 days without a restart (only 194, yeah, becausethat's when the last power outage hit). My XP install has been runnng for 34 days without a restart, and 4 different people use this machine (only 34 days, yeah, 'cause 34 days ago I had to replace a dead CDROM drive). So, in my opinion, the stability problem has been licked, and XP looks good too.

    Now they intend to focus on security, and what do you people do? You call it a PR move. Of course it's a PR move. What better way to get good PR than to focus on a problem and fix it? Honestly though, what I think you're all worried about is the fact that if they do focus on this and work this out, you people might have to admit that Microsoft makes a better product.

    I am expecting to be modded down, so I won't be upset if I am, it will just help prove my point. I'm not after your brownie points.

    1. Re:I don't get it...... by Anonymous Coward · · Score: 0
      I am expecting to be modded down, so I won't be upset if I am, it will just help prove my point. I'm not after your brownie points.


      That's alright diddums, I don't care either. We can pout in the corner together

  219. Take this seriously by lateral · · Score: 3, Insightful
    The /. community have been crying out for Microsoft to take security seriously for a long time. Now that they have decided to do just that you think the community might be pleased, or just a little relieved. Apparently not. It seems MS will get a bashing even when they do what we want.

    There seems to be a feeling that MS aren't doing this sincerely. Maybe not they're not but we can't possibly know that yet. I think there is every reason to believe they will go through with this. Does anyone remember what happenned when Bill Gates realised his company had taken its eye of the ball by ignoring the internet?

  220. Re:That GUID on WMP? Yeah . . . by Sentry21 · · Score: 2

    Will you remember that the next time somebody installs a Linux workstation with every daemon in the world running?

    In all the (four or five years of) Linux experience I've had, no one blames RedHat users (except arrogant jerks), but everyone blames RedHat.

    The difference between that and IIS is that when RedHat is installed as a desktop OS and still has a world of rootable daemons installed by default, that's stupid design. When Windows NT is installed with IIS by default on a desktop machine, it is, again, stupidity on the part of the company (in this case, Microsoft).

    When someone gets paid to install/admin a box and they leave security holes open by default, I'm inclined to blame the person getting paid - it is their duty to be aware of problems and fix them, and if something so simple as a stupid default installation is beyond their grasp, they should look for a new line of work. For someone who just wants to use the computer, however, I don't think they deserve blame, no matter what OS they chose (or not) to install.

    --Dan

  221. They will tie Passport to "Trustworthy" by flacco · · Score: 3, Interesting
    MS will clearly see this as a marketing and FUD opportunity for Passport.

    Vendors will have to use Passport in order to get a "Microsoft Trustworthy Computing" seal on their website (have they trademarked that fucker yet?).

    Users attempting to access Commerce sites without Passport integration will be warned with a big "THIS SITE NOT MS-TRUSTWORTHY-CERTIFIED!" messages.

    After all, every consumer knows you need a big, familiar, feel-good corporation like MS to ensure your Internet security and privacy...

    --
    pr0n - keeping monitor glass spotless since 1981.
  222. Re:That GUID on WMP? Yeah . . . by Tony-A · · Score: 2

    It cracks me up that Microsoft disabled Java support in XP for "security reasons".
    Even with Microsoft's broken "Java", it was too secure. Of course Microsoft removed it for security reasons. Microsoft didn't say it was to increase security, did they?

  223. It's All Relative by Sentry21 · · Score: 2

    I think the idea is that if all your personal information, music, videos, text, and so on don't belong to you, and your OS license doesn't bequeath anything to you but rather lets you use MS's OS for a while, then if someone breaks into 'your' computer, it's not your stuff they're deleting, so it's not 'insecure'.

    New in Windows Media Player: Digital Rights Management! Remember, 'If you have no rights, there's nothing to lose!'

    --Dan

  224. Re:That GUID on WMP? Yeah . . . by Tony-A · · Score: 3, Funny

    Stand in a parking lot with a clipboard and write down the license plate numbers of everybody that enters. ;-)

  225. Baby in a month� by kiwipeso · · Score: 0

    I think you'll find the open source movement is full of geeks who donate sperm.
    It's the only way they'll get it in a woman...

    --
    - Kaos games and encryption systems developer
  226. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    Yes, when a default in Microsoft makes the system insecure, it's Microsoft's fault. Yet, if a default in a Linux program makes the system insecure, it's obviously the admin's fault. Even Linux daemons run as root by default, right?

    Case in point, no default password in SQL Server 7.0 and prior get the governments attention as a huge security hole in the program. Scott Tiger doesn't think that is a programatic mistake, and neither does MySQL's root account.

  227. Thanks - WMP 6.4 by Arker · · Score: 1

    Thanks for the reply. Finally found it. No tools menu on 6.4, it's view-options-player. Looked at that earlier but I guess I just saw what I was used to seeing, on 6.1, which doesn't have that particular button.

    --
    =-=-=-=-=-=-=-=-=-=-=-=-=-=-
    Friends don't let friends enable ecmascript.
  228. M$ already own the technology to kill buffer issue by martin · · Score: 5, Interesting

    From the risks digest....

    Re: "Buffer Overflow" security problems (Baker, RISKS-21.84)
    "Nicholas C. Weaver"
    Sat, 5 Jan 2002 13:15:52 -0800 (PST)

    I agree with Henry Baker's basic assessment that buffer overflows, especially in code which listens to the outside world (and therefore vulnerable to remote attacks) should be classed as legally negligent.

    However, it seems to be nigh-impossible to get programmers to write in more semantically solid languages.

    There is another solution: software fault isolation [1]. If the C/C++ compilers included the sandboxing techniques as part of the compilation process, this would eliminate the most deleterious effects of stack and heap buffer overflows: the ability to run an attacker's arbitrary code, with a relatively minor hit in performance (under 10% in execution time).

    An interesting question, and one for the lawyers to settle, is why haven't these techniques been widely deployed? The techniques were being commercialized by Colusa Software as part of their mobile code substrate [2] in the mid 1990s. In March 1996, Colusa software was purchased by Microsoft and it seems effectively digested, thereby eliminating another potential mobile-code competitor, something Microsoft seemed to fear at the time.

    The interesting RISK, and one which is probably best left to the lawyers, is that as a result, for over half a decade, Microsoft has owned the patent rights and the developments required to eliminate two of their biggest security headaches: unchecked buffer overflows and Active-X's basic "compiled C/C++" nature, yet seems to have done nothing with them.

    What is the liability involved when a company owns the rights to a technology which could greatly increase safety, at an acceptable (sub 10%) performance penalty, but does nothing to use it in their own products? Especially when the result is serious, widespread security problems which
    could otherwise be prevented?

    [1] "Efficient Software-Based Fault Isolation", Robert Wahbe, Steven Lucco, Thomas E. Anderson, Susan L. Graham, in *ACM SIGOPS Operating Systems Review*, volume 27, number 5, December 1993, pp 203--216,

    [2] "Omniware: A universal substrate for mobile code"

    Nicholas C. Weaver nweaver@cs.berkeley.edu

  229. Privacy, not security issue by MartinB · · Score: 1

    I know that this article was punted as "MS discover security", but the full memo equally covers Privacy and Availability:

    Privacy: Users should be in control of how their data is used. Policies for information use should be clear to the user. Users should be in control of when and if they receive information to make best use of their time. It should be easy for users to specify appropriate use of their information including controlling the use of email they send.

    Now either this is A Lie (tm), or MS SneakWare will cease to be.

    --

    The only thing you can accurately describe as "Scotch" is a sticky tape made by 3M. And it's

  230. They will probably go the easy way by bockman · · Score: 2
    I don't know if they are going to run peer inspections of all their code looking for security hole. But there are a couple of things that could al least increase the (perceived?) security of the windows Oses
    • ship everithing with scripting engines disabled: if user enables them, put out a big security warning window. Not real security, but good for PR : "default windows installation is secure!".
    • Make stacks non-writable with something akin to the linux kernel patch shipped with OpenWallLinux. This would ensure some temporary security, until all current buffer overflow exploits are re-written. Again, PR people could again use this time to show off the improved security.
    They could make a different set of boxes (Windows XXP!) and make money out of it :-)
    --
    Ciao

    ----

    FB

    1. Re:They will probably go the easy way by Andrewkov · · Score: 2
      ship everithing with scripting engines disabled: if user enables them, put out a big security warning window. Not real security, but good for PR : "default windows installation is secure!".

      This is unlikely .. Microsoft has always gone to great lengths to make their software as easy to use as possible, and with as many features as possible. Non-technical users don't want to have to figure out how to turn on a feature so they can use it, they want everything to "just work".

      The servers, on the other hand, could really benefit from this. If IIS was turned off by default, Code Red wouldn't have been such a problem. I bet most Windows admins didn't even realise they were running a web server.

      Scripting is another issue. Scripting languages are very usefull, but why do the interpreters allow registry updates, file deltions, etc. If the scipting languages were limited so that it is safe to run untrusted scripts, that would be a big step towards a more secure system (if it is even possible to write useful scripts in such a limited environment).

  231. MS will benefit from this by jeorgen · · Score: 1
    It's very simple. Microsoft has huge resources. They can start to churn out very secure stuff if they put their mind to it. On top of that they can have agreements with their customers to reimburse them under certain conditions (like the credit card companies do today).

    They will then lobby for legislation to make this mandatory for all software companies. And then small companies will not be able to keep up.

    Mandatory security will slow development down and weed out small development companies. Is that what we want?

    /jeorgen

  232. How long will it take... by ignavus · · Score: 2, Insightful

    ...MS to declare that the major security threat lies in other vendor's software and other OS's? After all, they used Win95 to kill off DR-DOS ("it isn't really compatible with the special code we added to Windows")

    Then they will argue that they have to close up everything to bring about security: "Only MS products are really safe with MS Windows. Only MS protocols are secure."

    Then the Big Lie: "you are only safe with us"

    --
    I am anarch of all I survey.
  233. Security by Anonymous Coward · · Score: 0

    Security is not something you can add in at the last moment. Wave your magic wand and say, be secure! Its something you have to design in to the code. They can start patching and repatching the problems caused by the patches, but in the end to do this they will have to start over again. I don't see that happening after they just rewrote their operating system for XP.

  234. -1 offtopic... by gfxguy · · Score: 2
    corporations exist to make profit
    unions exist to help people
    Unions exists to make a profit at the expense of people they are pretending to help.

    Don't get me wrong, the philosophy of unions is fine with me, but so is the philosophy of democracy, and neither one works particularly well over time - both systems have been corrupted. Unfortunately, maybe it's just human nature, but whenever there is the potential for a system to be abused, it is abused.

    Name, for example, one government program that has the potential for abuse, but hasn't been abused? Now name one union that has been around for any length of time that hasn't been at least investigated for abuse or had an official fired or voted out (as a scapegoat) for abuse.

    --
    Stupid sexy Flanders.
    1. Re:-1 offtopic... by MrFredBloggs · · Score: 1

      you`re american, right? In Europe, Unions still have a pretty good name (better outside the UK though).

      I`m not bothered if unions have people kicked out for being crap. Thats a bit of a late 20`th century idea - "ooh boss, lets plant drugs on this guy, or find out if he`s gay or a communist`. Such events have no bearing on whether or not such a person can perform his job.

    2. Re:-1 offtopic... by Anonymous Coward · · Score: 0
      Name, for example, one government program that has the potential for abuse, but hasn't been abused?

      This sort of rhetoric is just crap. Let's turn the challenge on it's head: Show me that each government program has been abused.

    3. Re:-1 offtopic... by remande · · Score: 2
      I don't know much about European unions besides what I was tought in school in the early '80s, but my impression is that they fulfill a different function in the US than in Europe.


      The US has a more lassiez-faire economy than most European nations, so corporations have much easier hire/fire rules than in Europe. American unions exist to create collective bargaining by attempting to create monopolies of labor. This gives industry workers some (some would argue too much) leverage when hashing out contracts. Thus, if you need to hire a fleet of trucks, you won't be playing one trucker against another for the lowest per-mile rate, you'll be dealing with the Teamsters and playing by their rules.


      How close is this to the European model?

      --

      --The basis of all love is respect

  235. Re:That GUID on WMP? Yeah . . . by Ayende+Rahien · · Score: 2

    Hm, IIS is not installed by default on desktop version of NT/2K

    --

    --
    Two witches watched two watches.
    Which witch watched which watch?
  236. Re: 3 BSDs? by kiwipeso · · Score: 0

    Finally, I'm ontopic when I'm talking about KAOS, the operating system I'm developing.

    KAOS is based on OpenBSD, it has all of OpenBSD and KAOS runs on top.

    The kernel is different, it's an exokernel or system that does OS functions in the apps.
    This makes it run faster and more stable.
    The unique parts are agent applications, evolving code, samizdat censor resistance, demonic management and weapons grade cryptography.

    OpenBSD is more secure (no security flaws in default install since 1997) due to better testing.

    Add this to the first reply: KaosBSD.
    The secure Unix with the best GUI, kernel & programs yet.

    --
    - Kaos games and encryption systems developer
  237. OpenBSD provides web� by kiwipeso · · Score: 0

    server Apache which isn't part of windows like Internet Exploder.
    You can use mozilla on OpenBSD.

    --
    - Kaos games and encryption systems developer
  238. Windows XP achieves BS1 Certification.... by TheConfusedOne · · Score: 2, Funny

    For immediate release:

    Due to the current flurry of negative (and obviously biased) reports about XP's security of late, Microsoft PR 3.0 has created the following new security certification: BS1.

    Achieving this rating marks a milestone in the development of the Windows eXPerience. The most recent press release lambasting the "evil, commie, terrorist bastards" who dare to release exploit code challenging the "Security is Job 3.0" corporate mantra in Microsoft has successfully pushed XP into the BS1 certification category.

    BS1 is marked by the following:
    * 3+ Metric tons of press releases denying any and all problems.
    * 1GB+ downloadable "patches" and "enhancements" required for all new installations.
    * 100,000th "grass roots" letter of support delivered to Congress

    We would like to thank all of the people in Marketing and the good folks over at W&E for helping us reach this milestone in the Windows eXPerience.

    --
    --- I wish I could hear the soundtrack to my life. That way I'd know when to duck.
  239. Linuxville Founder's Email 'Leaked' by Anonymous Coward · · Score: 0


    So, What's GNU?

  240. You got the date wrong! by Doctor+High · · Score: 1, Funny

    Wrong day guys. This is NOT April 1st... Look at the date before you post the stories please?

  241. Re:Today's porn count! by kiwipeso · · Score: 0

    You may have heard about my porno password system I'm making as a part of KAOS the OpenBSD based system.

    If you really have that much porn, I think you deserve to get a copy of KAOS when it's done so you can test the Porno password.

    How does it work?
    At the login password, type "dutch miracle" the login will change to porno password. Then pick the pix you want in order to login.
    Another part is planned, the porno error.
    All errors will then popup as porn pix.
    (Imagine the "please insert disk" error pic...)
    And of course, the porno desktop.

    For the purposes of research I have about 6gig of porn (cable modem helps) and a CD burner.

    BTW, iPhoto is good for archiving as webpages. You can make index pages for each pornstar and then just run from a CD.

    --
    - Kaos games and encryption systems developer
  242. HA HA HA HA Good one, Bill! by silverbax · · Score: 1

    "Microsoft" and "security" in the same sentence! Comedic genius!

  243. Surf without MicroSoft? by kiwipeso · · Score: 0

    Netscape / Mozilla, Quicktime & Apache.
    All 3 are the dominant power in their areas.
    All 3 are on mac, OS X, windows, linux & BSD.

    --
    - Kaos games and encryption systems developer
  244. Sure... by opkool · · Score: 2

    Given Microsoft Corp. track of press announcements, vaporware and talks about "... the next version will fullfill this need.." I foresee this as YAMK (Yet Another Marketing Campaing).

    Come on. You do not need to be an expert in marketing tactics. But for a company that is expending $1 billion (that is, $1,000 million in Europe) just in advertising for the XP family... It just makes sense that, after having everybody talking about how much security is needed, Microsoft promises that it will deliver just that. Next version, of course.

    Microsoft has been making promises like this since it was created. It has hardly delivered... on time. The record is out there. Our money, in their bank accounts. And they still are saying that the next product will have this or that feature that we need right now.

    Come on! We can be naive! But not after 20 years of not delivering!

    OTOH, Microsoft Marketing Department would do great promoting the virtues of democracy around the world. In 20 years, everyone and their mothers would be triying to be a democracy.

    Ah! The power of Marketing!

  245. fa! by Anonymous Coward · · Score: 0

    The next version of windows will have the most secure blue screen of death of any single version.

  246. Corel Draw is a joke? by Anonymous Coward · · Score: 0

    You could just admit that you've never used CorelDraw.

  247. No, this is like a safety standown by joedoc · · Score: 1

    This reminds me of what the military (specifically in my case, the Navy) does after some horrible accident or plane crash. They call a "safety standown" for a day.

    Everyone in the fleet (including us civilians) would stop work for a day, discuss what happened, and listen to boring lectures and filmstrips on how not to spill fuel and hydraulic fluid, and how not to get sucked into the engine's intake, and how not to crack your melon against the wing's trailing edge flaps (which really hurts).

    You know, all the stuff you're supposed to know before you walk out to the filght deck.

    Like the way the code is supposed to work before it becomes Release Candidate 1.

    This is why I don't work with airplanes anymore.

    --
    Joe Dougherty, Florida, USA
    The words I thought I brought, I left behind. So, never mind.
  248. Throwing stones, glass houses, whatnot by m_evanchik · · Score: 1, Offtopic

    Interesting post on debianhelp.org, accusing some in the GNU community of acting like Microsoft with regard to community issues

  249. Re:That GUID on WMP? Yeah . . . by gimpboy · · Score: 1

    my father does. when i explained what cookies were, he didnt have a clue that such a thing exsisted. once i explained how they worked, he asked me how to turn them off.

    my dad is what i would consider a normal end user. he just got his first computer in december.

    --
    -- john
  250. Striped down version... by goldorak_dan · · Score: 1

    If their next os release doesn't come as an OS!!! With nothing more than solitaire and minesweeper, this article is b.s.

  251. Say that again? by ganiman · · Score: 0

    "...Bill Gates announced to employees Wednesday a major strategy shift across all its products to emphasize security and privacy over new capabilities."

    Security and privacy *ARE* new capabilites to Microsoft products.

    --
    geek n performer who performs morbid or disgusting acts, as biting off the head of a live chicken
  252. Paging Doctor Nick Riverra, Dr. Nick� by kiwipeso · · Score: 0



    FWIW, laughter is good for you.
    My uncle is a doctor in Australia, I could call him...

    --
    - Kaos games and encryption systems developer
  253. Re:That GUID on WMP? Yeah . . . by arkanes · · Score: 2
    There was a big debate over is to/is not last time this came up - I payed more attention when I reinstalled a while ago.

    It looks like it's NOT installed if you select "default" install. However, if you select a custom intall, it's checked by default. At least, thats how it was for me.

  254. Re:That GUID on WMP? Yeah . . . by pmz · · Score: 1

    ...a Linux workstation with every daemon in the world running?

    Perhaps OpenBSD would suit your needs better?

  255. This is total crap by jkeychan · · Score: 0

    This is such crap. It seems like there are two ways to get news from Microsoft: 1) A "leaked" employee memo with loads of incriminating stuff 2) An "e-mail from Bill Gates to employees" that is picked up by the AP. This is CYA at its best. Lipservice to the fact that they've fucked up royally on almost all fronts.

  256. What Microsoft says by PegQuin · · Score: 1

    and what Microsoft does are two very separate entities. Any announcement from MS should be questioned as subversive drivel. The security they're concerned about is in securing market share and driving away any competition. Bill Gates' favorite cartoon is Pinky and the Brain.

    --
    PegQuin--I've got a sneakin' suspicion
  257. No cigar. by Tony-A · · Score: 2

    Where are the userids and file system permissions for files on a FAT partition?
    How do I get a directory listing with owner and file permissions for files on an NTFS partition?
    Right-Click, Properties, Security tab, Permissions. File-by-file. Thousands of files. No cigar.

    1. Re:No cigar. by DNAGuy · · Score: 1

      C:> CACLS *.*

      What's so hard about that? And if you install on a FAT partition, well, I think you have a spacing problem (ie. the space between keyboard and chair. :).

      --

      BRENT ROCKWOOD, EST'd 1975

    2. Re:No cigar. by Fjord · · Score: 1

      for the second one, there are many command line tools, but if you want to use explorer, just select all of the files at the same time, right click, properties. If you want to do it recursively, then use the find function to find all the files under the directory.

      --
      -no broken link
    3. Re:No cigar. by Erris · · Score: 2
      So how does this take the place of having permisions be part of the file system? Why is it so difficult for them to make their kernel respect them by default, or even to have reasonable default permisions put on every file as it is created? Next they can try to put groups on, as the current junk they have makes no distiction between groups and users. What a mess it all is. That junky right click produces a mile long mixed user and group list in any decent sized company. It is not hard thing to add a few bytes to every file, maintain user and group databases and make the freaking kernel respect it all!

      The reason M$ does not do this is because they don't want your computer to be secure. If it were they would not be able to force adverts and upgrades on people.

      --
      DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
    4. Re:No cigar. by jo42 · · Score: 1
      > And if you install on a FAT partition

      'cept you know not to do that, I know not to do that, but does Bill-I-just-bought-a-computer-nit-wit know that?

  258. Ron Jeremy: In an unrelated story... by kiwipeso · · Score: 0

    rumors have it that Ron Jeremy will have liposuction and get his member enlarged with the fat from his belly.

    Ron Jeremy has stated that he wouldn't mind having to hide it in his sock if it reached.
    This would be better than covering it in his sock to make it look large.

    --
    - Kaos games and encryption systems developer
  259. Forcused on secutity since... by Spoing · · Score: 2
    1. Unix: Focused on security since 1972.

      Windows: Focused on security since 2002. Really, we're serious this time. Stop laughing.

    --
    A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
  260. Why they won't do it...even if they are serious by Spoing · · Score: 3, Interesting
    As anyone who has worked on commercial software knows, the release schedule drives the features list and the features list drives both coding and testing.

    Security is one of those things that is required to come at the planning stage of any product -- not as an afterthought during the coding and test stages.

    MS needs profits to buy new companies so they don't have to pay divedends. They need big profits so that the stockholders will be happy with the 'value' of MS as a whole.

    Yet, the software side of thier business is a stagnent market -- huge and captive but not growing as it used to. Because of that they need to retain customers and get them to upgrade on a regular basis (subscriptions everyone?).

    Then, we're back to the schedule and the features and security getting short shrift.

    Does anyone expect it to be any other way?

    --
    A firewall can not protect you from yourself. Turn off what you do not need. Do not use the firewall to do your work.
  261. Culture reflects the management's attitudes by D_Fresh · · Score: 2, Insightful
    Bill Gates' personality is clearly reflected in the behavior of MS as a corporation. Does not play well with others, extremely self-centered and competitive, paranoid, and more interested in dominating the marketplace than producing a quality product at the outset. Gates has always been late to "wake up" to what everyone was talking about (or criticizing MS for) because he is intellectually arrogant enough to believe that he's right all the time.

    What would MS have been like if a Gatesian personality had not been at the helm? Possibly not the MS we've come to love. Added attention to security now is obviously not any kind of move in the "right" direction, but instead just a CYA maneuver now that Bill's finally awakened to the fact that their security concerns could be enough to bring the whole house down unless they pay some attention to them. But he cannily waited until the problem was bad enough to be worrisome - had he been more community-minded he would have attacked this more seriously a long, long time ago.

    Kind of makes you wonder what will happen to MS once Gates has removed himself entirely. Will they begin to play more nicely with others? (Insert Ballmer monkey comment here.)

    --

    Was that out loud?
  262. Or... by schon · · Score: 2

    I don't use MS products specifically because of security concerns - and I think it's more like "better late than never."

    Any commitment focus on security is always a good thing..

    Of course, I'm still skeptical - considering MS's track record, the best attitude is "wait and see"..

  263. Time Warner spent nearly $7.5 million buying DMCA by yerricde · · Score: 2

    I find AOL/TW less scary than MS, at least on a personal level.

    At least Microsoft didn't spend millions lobbying both political parties to pass the Bono Act and DMCA like AOL(tw) did back when it was just Time Warner.

    If I want to avoid their media conglomeration entirely, I can. And if I do, it doesn't affect me.

    It does in the United States, where you can go to jail merely for watching a DVD.

    Microsoft, on the other hand, by trying to extend its monopolies

    Except AOL(tw) doesn't try; it succeeds in extending its monopolies.


    Updated!
    --
    Will I retire or break 10K?
  264. Re:That GUID on WMP? Yeah . . . by wilsone8 · · Score: 1

    I think it is also important to note that a GUID is NOT a security hole. That would be like saying having a MAC address on your network card is a security hole. It may be a privacy hole, but it does not effect the security of your system.

    --
    The real problem is not whether machines think but whether men do. - B.F. Skinner
  265. New link. by GoNINzo · · Score: 2

    They moved the link on us. It's now here.

    --
    Gonzo Granzeau
    "Nothing the god of biomechanics wouldn't let you into heaven for.." -Roy Batty
  266. Wow, how are you going to spin this? by Armand28 · · Score: 0

    Microsoft decides to focus more on security, which is the main complaint you /. folks have, yet you still find ways to bitch about it. How sad.

    --

    Armand28

    "-LINUX was a good OS, before it became a religion."
  267. Microsoft does not consider it a security problem. by 4of12 · · Score: 3, Insightful

    That part is really central to the problem.

    Microsoft has been the dominant player for so long now (what, about 15 years?) that it has become complacent and arrogant. They can say, with all credibility,

    "Standards? We are the standard."
    even if it grates on the ears of their competitors and users.

    There are definitely some brilliant people working in Redmond, but if they are managed by the same people that bred this culture of arrogance, then only rare glimpses of that brilliant work will be revealed to the world. Most of that good work will be muffled and warped beyond recognition under various business pratices such as supporting Windows, leveraging Office, promoting .NET or whatever the fad (cf, Trustworthy Computing) of the day happens to be.

    The sooner that megalithic company is split into smaller pieces the sooner it will have a chance to bring genuinely good products to the marketplace.

    --
    "Provided by the management for your protection."
  268. It is just me? by sirgoran · · Score: 1

    Or does this sound far too much like the old story about the Fox guarding the Hen-house?

    And I can just bet that with their stellar record of security practices that they will succeed in this move.

    Thanks, but I think I'll put my money in my sock and go live in a cave. Because the world is about to have a major security problem.

    Goran

    --
    Carpe Scrotum - The only way to deal with your competition.
  269. Re:Disabling GID by Ionizor · · Score: 1

    And speaking of people missing the patently obvious...

    You can turn it off with two clicks.

    --

    --
    Todd's Law: All things being equal, you lose!
  270. Re:That GUID on WMP? Yeah . . . by Mark+Pitman · · Score: 1
    - but the Linux world evolves rather rapidly, and Mistakes Get Fixed. There's no corporate pride or marketing image to worry about -

    So you are telling us that RedHat has no corporate pride and no marketing image to worry about?

  271. Re:That GUID on WMP? Yeah . . . by blakestah · · Score: 2

    Right.

    It is installed by default on NT Server.

    I still get pinged by dozens of locals machines that are rooted through that one.

  272. Re:That GUID on WMP? Yeah . . . by blakestah · · Score: 2

    Will you remember that the next time somebody installs a Linux workstation with every daemon in the world running?


    Remember it - I've had to live it. On two separate occasions I had to reinstall RH on machines with BIND. These were not nameservers. Since then I do regular audits of machines on which I might be asked to work.

    "netstat -al | grep LISTEN" and nmap -sT

    Secure by default should be the motto for default server installations. Redhat has learned from its mistakes. So have all other linux vendors. Debian and the BSDs never had such problems to begin with.

    But there are still several million Windows machines displaying the default IIS home page.

  273. Reputation is everything by bubbha · · Score: 1

    Look at Arthur Anderson... to recover their lost reputation...after screwing many thousands out of many millions of dollars...they fired a partner and told us things were going to change around there. The effect of untrustworthy audits and accounting practices cracks the foundation of investing in securities. In my mind, Bill Gates is the same kind of person. Make as much as you can, even if in doing so you produce software that puts the internet infrastructure, personal privacy, corporate security...all at risk...simply because you could get away with it. Now that you're caught up in this, we are supposed to say fine...fix your shit and don't do it again?

    --
    I want to be alone with the sandwich
  274. Ba-bom bom *KISHHHH* by jeff13 · · Score: 1

    Somewhere, a rim shot could be heard.

  275. Security? Stability? Insanity... by Quixadhal · · Score: 1

    Well, the phrase "Better late than never" comes to mind. Of course, they've already got the obscurity part written and debugged.

    Maybe M$ should try focusing on stability first... it's much easier to have a secure OS when it doesn't crash on a new mouse driver install....

  276. Really, you laughed at MSIE? by S1mon_Jester · · Score: 1

    I didn't.

    Microsoft controls the platform. So they can make/break any package that exists on that platform, but changing the platform. I knew Netscape was dead the minute Microsoft announced IE.

    Now, what I laughed at was then they said WinNT was unhackable. Now that was funny. I laughed my ass off when l0pht broke NT.

  277. Re:Am I going to trust Microsoft? Ever? by Unknown+Poltroon · · Score: 1

    . I may be pagan, but there are some altars at which I will not kneel. Far more likely to torch'em.

    Whuhu, i got me some matches!!!

    --
    All Troll + "offtopic" mods are meta moderated as "Unfair", because you abused the system.
  278. Not impressed by aoty · · Score: 1

    So now Microsoft announces that security is now a priority for them. That basically tells me that MS didn't give a squat about security during the development of their past products.

    With the release of every OS they make, they always create a big hoopla about how this is the "most secure and stable" yet.

    I take this announcement the same way I take everything else that comes from Microsoft, as marketing and hype. Because, in my experiences, that is all Microsoft is really good at.

  279. Re:That GUID on WMP? Yeah . . . by Cy+Guy · · Score: 2

    Also, knowledge of this feature is useful to administrators of systems where there is policy that the privacy of the users is to be protected.

    For example, it is illegal for any federal website to collect personally identifable information about any of their website's users without their explicit permission. While there is an exemption for the temporary collection of browser info and IP found in server logs, since these in and of themselves are not very reliable at identifying individuals (and there are regulations in place to prevent their use without judicial guidance), the level of individual identification allowed by this feature/bug likely would not be allowed.

    Without these privacy violations being widely announced, its likely that federal website administrators could unknowingly violate the privacy regulation.

  280. You got to be kidding? by Stackis · · Score: 1

    I know this will probably be redundant......but what a fucking joke! Nothing but PR......Micro$hit is, and will always be $hit!.....their products have been $hit from the get go! Now that the FBI, and the media is questioning the security of their products....Gates all of the sudden starts talking about security being the main focus........what a freaking joke!

    --

    "Look where we worship" -- Jim Morrison
  281. To quote a great movie: by Anonymous Coward · · Score: 0

    "This is like bolting the barn door after the horses have eaten your children."

    - "Saturday the 14th"

  282. Re:Am I going to trust Microsoft? Ever? by leifb · · Score: 1

    watching boxes powered by You Know Who drop like flies.

    Voldemort does software too? Man, you'd think he'd have his hands full with that Potter kid...

  283. In other news... by bruns · · Score: 1

    In other news, Microsoft announced it was leaving the software business and refunding all of the money it cheated people out of over the years. Bill Gates was shown on TV apologizing to the world for his actions and promises to never do it again.

    --
    Brielle
  284. They're right - it's not a security problem ... by Mr_Dew · · Score: 1

    Meanwhile, Richard Smith notes that the Globally Unique Identifier in every installation of Windows Media Player allows websites to universally track users, and Microsoft does not consider it a security problem.

    Of course not - it's a privacy problem. (rimshot!)

  285. not a rimshot! by Anonymous Coward · · Score: 0

    Dammit, people. that is not a rimshot. A rim shot is hitting the rim of a drum (typically the snare) instead of the head. What you're looking for involves a cymbal and has no name. Figure out what the hell you're talking about before you post your ignorance to the world. Geez!

  286. Don't rely on human nature, then! by alispguru · · Score: 2
    ... slowly and methodically picking through all of your code to make sure that no buffers can overflow is just uninteresting and unglamorous.

    But it doesn't have to be done manually! A simple Google search turned up lots of tools that eat raw C and C++ code and detect potential buffer overflows. Use of tools like these ought to be a mandatory quality control step for any organization that really cares about secure and reliable applications.

    And of course, all of this completely ignores the possibility of using other languages where buffer overflows and stack smashes are implementation problems rather than application programmer errors.

    In my opinion, shipping code written in unsafe languages without at least an automatic static check for potential security problems should make the shipper liable for damages.
    --

    To a Lisp hacker, XML is S-expressions in drag.
  287. Re:That GUID on WMP? Yeah . . . by Anonymous Coward · · Score: 0

    Normal Microsoft cheerleader underreacting again. Don't wander too far from your flock, little sheep. Baah. Baah.

  288. We should take this seriously by Books · · Score: 1

    You can laugh all you want, but soon M$ products are going have fewer security problems. When these guys set their mind on something they usually get it.
    BTW: Are plain old bugs considered "security problems"?

  289. makes sense by Magius_AR · · Score: 2, Insightful
    Such a shift makes sense, I was wondering when Microsoft would get around to it.

    They've dominated the market for years, mainly because they were there first, but also because of usability/convenience factors. People put such things above security (and most likely privacy). They want something that works easily with little effort or configuration that does what they need it to. Windows has always been that.

    On the other hand, no real OS of the time could really equal that level of user-friendliness and simple interface that Windows offered. As times are changing (and many people are figuring this out), a vast shift in many UNIXes has been towards developing a friendlier interface (Window's strongpoint). It only makes sense that Microsoft should shift its goals towards security and stability (UNIXes strongpoints). Basically, if Microsoft gets there first (stability, security, AND an easy UI) before any of the UNIXes gets more firmly cemented in the market, it will become _drastically_ harder to get people to switch over.

    Magius_AR

    1. Re:makes sense by pressman · · Score: 1

      Wow! Have you ever heard of MacOS? User friendly and secure since 1984. Now with a BSD core, you get high powered networking and stability. Security is now an issue on the Mac because it now has a command line that hackers can exploit.

      --
      Pooty tweet
  290. Ho! Ho! Ho! by Anonymous Coward · · Score: 0

    Doesn't this fall under one of those holidays...Oh wait, that's april fool's! He! He! He! ha! ha! ha! ha!

  291. pot-calling-the-kettle-black by Anonymous Coward · · Score: 0

    Bill Gates is Microsoft's Chief Software Architect. Security is an Architecture issue. So why is he aiming his comments at developers?

    I know that Bill doesn't draw up architecture documents for all (any?) of MS products but he should have, at least, been passing on the importance of security to his under-Architects.

    Sure there are things that programmers can do to make a product secure or not secure but I think it's largely an Architecture and Requirements issue.

    I'm sure the phrase, "how much security can we afford?" has been uttered around MS halls on more than one occasion.

    The bright light at the end of this tunnel is that when Microsoft changes its vision, big things happen. For instance, Microsoft went from dismissing the Internet to embracing it (to monopolizing it?) in a very short period of time.

  292. A couple of months early... by Muggin · · Score: 1

    Isn't it a little early for April Fools? This is like stinking up a bathroom and spraying air freshener with the hopes that it will destroy the smell, when in reality it only smells worse.

  293. "Trustworthy Computing" is not about -your- trust. by Chris+Burke · · Score: 2

    I think that this message may be a way of sneaking the Secure Execution Mode that MS is working on into the public awareness, and that is in fact one of MS' highest priorities. The capitilized phrase "Trustworthy Computing" is what tipped me off, because it is very much what they want, if you use a different context for "trustworthy" than what they want you to assume.

    The key thing to note about "Trustworthy Computing" is that it has nothing to do with you trusting them. It has to do with them not trusting you. Basically it's about preventing anyone without a logic analyzer from being able to tell what is in memory, as a way of enabling DRM that you can't (as easily) laugh at.

    So you're right. You have absolutely no reason to be reassured.

    --

    The enemies of Democracy are
  294. "What Ifs" are dangerous by epepke · · Score: 2

    None of the revelations about XP surprise me. I've known them for a year or more. So has every reasonably intelligent person who has paid attention.

    The problem is that an awful lot of people played "what if." They saw the promises that said that XP would be great and secure. They wanted it to be so, and as a result they believed the promises. Since the promises worked and ensured sales, they didn't actually need to do it.

    Microsoft seems obviously in love with their own PR. The problem is when people go along with the gag, which they've been doing for far too long. Now you want to play some more. As long as you play, get used to bending over.

    I also have a hard time understanding the idea of "middle ground." What, like Microsoft gets to abuse its monopoly on Mondays, Wednesdays, and Fridays? Being a monopoly is legal. Abusing monopoly power is. The government wants them to stop but won't do anything to make them stop. So, what exactly do you want?

    I'm also getting more than a little tired of this Linux As Religion stuff. Sure, there are zealots, but this is mostly a Beavis-and-Butthead-style dismissal. Most geeks like cool stuff. I've been a computer geek for about 30 years, and Microsoft used to be cool. Nobody cared that they monopolized the microcomputer languages field, because Microsoft BASIC was good. RTF and SYLK were good. The first version of Excel was good. Even MS-DOS, for all its primitiveness, basically worked. It isn't some sort of religious conversion that makes me dislike what Microsoft has been doing over the past decade; it's the fact that they've been doing bad.

  295. Coffee, Coffee, Coffee by shaunak · · Score: 1

    I just read that as "Microsoft to F*ck us on Security." No, I'm not using a hallucinogen.

    --
    -Shaunak.
  296. It's time? No. by Pitawg · · Score: 1

    This just strikes me as a result of his last board meeting.
    Not much on the new features list from the idea departments and therefore, "security could be a reason to force new upgrade revenue line for our software. That would give our idea guys some time to think on the next new feature."

  297. How may OSes before 2006? by allism · · Score: 1

    "But we're all out of nifty ideas for new features! What can we possibly do for our OS that will make it appear that we still need to keep cranking out a new OS every year, and that will make the customers keep buying them?"

  298. MS Security... no no no, your ALL wrong by MrIcee · · Score: 1
    NO NO NO... you ALL have it wrong... when that asshole Bill Gates says it's going to emphasis increased security... he means his companies FINANCIAL SECURITY... this has NOTHING to do with software.

    So... expect the next update to watch your every move... to report everything back to MS... so they can nail you on trumped up charges.

    Expect the next release to covertly install software you didn't pay for... so their software alliance can send the federal marshals to fine you hundreds of thousands of dollars.

    THAT is how they will increase security - and their bottom line.

    Face it folks... MS couldn't code their way out of an elevator without it crashing. What makes us think they can start now!

    MS is nothing but a marketing mafia... they do NOT know how to write quality code... and Gates saying they will start... is a bunch of hogwash.

    I still pray daily for Mt. Ranier to erupt and take out ALL of microsoft... their *coders* (hahahahahahahah) and Gates and his house.

    Throw out your PC's... your MS software... after all, there is nothing on it you need anyway.

    1. Re:MS Security... no no no, your ALL wrong by pressman · · Score: 1

      I still pray daily for Mt. Ranier to erupt and take out ALL of microsoft

      Unfortunately, Mt. Rainier erupting won't take out Redmond. It might damage Puyallup and maybe Tacoma, but Redmond is a long way off.

      --
      Pooty tweet
  299. Re:When... by lateral · · Score: 1
    This crowd won't ease off Microsoft GPLs its software.

    Alas I suspect that even then 'this crowd' would simply move on to complaining about how terrible the MS coding is, how the NSA backdoors have clearly been removed and how it should have been released under the BSD license.

  300. Trusworthy computing???? by Anonymous Coward · · Score: 0

    how about trustworthy business?

  301. MS Who? by Anonymous Coward · · Score: 0

    Microsoft who? Never heard of them.

    Linux=OpenSource=Freedom

  302. Gates the visionary by poirotsj · · Score: 1

    Bill Gates: a true visionary - imagine! secure computing! what a wonderful new idea!! I wonder when he'll invent open source?

    1. Re:Gates the visionary by Sj0 · · Score: 2

      Don't you remember? Bill Gates *created* open source!

      Keep up! It was at the last stockholders meeting! :)

      (The amount of bullshit tollerated in the corporate world is astounding.)

      --
      It's been a long time.
  303. Lessig in "The Future of Ideas" by gdyas · · Score: 2

    I'm finishing up Lawrence Lessig's latest book "The Future of Ideas", and one of his main points both in this book and in "Code and Other Laws of Cyberspace" is that the open, accessible by all with all being equal nature of the TCP/IP protocol is the central point around which the internet has grown, allowing anyone who wishes to use the internet however they wish.

    In this latest book he does a good if sometimes abstruse job of showing how not only computer companies but all kinds of businesses are trying to prioritize/demarcate/segment/control the net and prevent any more innovative uses ala P2P to occur because it threatens the old way of doing business. It's a good related read if anyone's interested.

    In other news, even if this is true, there's no reason us geeks can't continue to use our own TCP/IP & not use any new proprietary protocol. Who knows? Might be nice to have the spamming, virus-spreading masses that don't know anything about their computers all off on a different protocol & all. Remember too that AOL/Prodigy/Compuserve never volunteered to provide access to the 'net. They were forced to by customer demand for the content TCP/IP made it possible to provide.

    --

    The only tool you've got against psychosis is experience.

  304. Apparently ... by Anonymous Coward · · Score: 0

    Apparently the billg security memo was only meant to go out to 3 people but he had Sircam.

  305. Calendar must be broken by ocie · · Score: 2

    Is it April 1 already?

    --
    JET Program: see Japan, meet intere
  306. Email Contents by Anonymous Coward · · Score: 0

    So does anyone know of a website which has posted the complete text of his email?

  307. HA HA HA by Compulawyer · · Score: 2
    ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha

    [some filter defeating comments]

    ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha ha

    ....you get the idea.

    --

    Laws affecting technology will always be bad until enough techies become lawyers.

  308. I think this is very significant by soft_guy · · Score: 2

    I say this as a long time Microsoft detractor and Mac fan.

    This is a very significant change. I think it is as significant as when Gates decided that the company should focus on the internet. Since then, Microsoft has made efforts to improve their internet technology, integrate it into the OS, and evangelize it. I'm not saying their technology is always great, but their efforts have moved them to the point where they are a very significant player in areas where they weren't such as web servers (IIs sucks, but is a pretty widely used web server), browsers, web development, etc.

    I think Gates correctly recognized security as being a weakness that the competition can exploit. Their main competitors that can attack them on security being Linux, Sun, and IBM (I'm referring to both MVS and IBM's new Linux initiatives) in the OS space and Oracle and IBM in database space. There are others.

    Gates is definately a smart businessman and I think he's making a good call for Microsoft here. It's really about protecting their OS business and recognzing that Passport can't succeed without a perception that it is at least reasonable secure. The security holes they have had in the past have been very bad publicity for MS.

    Will this initiative succeed?

    I think Microsoft has demonstrated in the past that when they put their collective attention on a problem (such as internet integration), they can make significant progress in a relatively short time. However, security is harder and more runs counter to their corporate culture of keeping their costs very low and getting product out the door regularly and quickly. (Again, these terms "regularly" and "quickly" are relative to the rest of the industry.)

    In order to do what Gates wants, they are going to have to evolve to be more like IBM. I've worked at both Microsoft and IBM doing dev work on actual products. The differences between the two in terms of their overall development processes are very different. IBM's processes are more focused on producing quality products than are Microsoft's. My experience is that IBM is willing to spend more money and time on really getting a product "right" than Microsoft. Microsoft has a much greater degree of urgency about getting things done. For small software companies, urgency about getting things done is very important, but I think Gates knows that Microsoft has enough of an established business (understatement) to slow down a bit and concentrate more on quality.

    The good thing about the current culture is that they can respond to new innovative products somewhat quickly. Once they start caring more about security and quality, it will be harder for them to use their OS to squash competitors. If they can't integrate new technology into the OS at the drop of a hat, then the best they can do is have a product dev group create a competing application to whatever the new hot thing is and compete head to head. I think it will be easier for the third parties to win under this scenerio. What MS gets in return is a greater ability to compete effectively against competitors who have eluded them in the past such as Intuit, Oracle, and Linux.

    --
    Avoid Missing Ball for High Score
  309. Let me just say this about security at MS.. by jcr · · Score: 3, Interesting

    Hugh Daniel went up there some time last year, to do some interoperability testing between NT's IPSEC, and free S/WAN. He asked them, what crypto they'd implemented and could test. They told him that they'd only done 40-bit DES.

    He just left.

    Personally, I'm not holding my breath for MS to ever implement a securable system. They'll do things that let them check off the boxes in their product literature, but as for those features being truly robust, I wouldn't count on it.

    -jcr

    --
    The only title of honor that a tyrant can grant is "Enemy of the State."
  310. Fully secure M$ products might be a BAD thing by Reziac · · Score: 2
    ... because I just had this vision of their products becoming secure enough that they *can* lock the entire world into M$'s choices. I mean this literally -- you not only will be secure in using Windows, you won't be ABLE to not use Windows, because that's part of the security lockdown. Not because alternatives are "bad" but because -- well, a sort of software air gap is imposed as part of the security layer.

    (This isn't meant as a funny or trollish comment, but I can't seem to exactly what I want into words I know won't be taken for "M$ wants to stamp out alternatives". *sigh*)

    --
    ~REZ~ #43301. Who'd fake being me anyway?
  311. der! by Anonymous Coward · · Score: 0

    Let's put bars on the windows of our glass house!

  312. only time will tell by ryusen · · Score: 1

    i have my doubts, but if they can get their act together maybe i'll have a change of heart, but this assumes that they finally start writting better code and do it for a few years to prove to us that this isn't a one time thing

    --

    I believe sex is highly over rated... unless it involves me
  313. Yea, right, sure, Mr. Bill by Maxie+Bear · · Score: 1
    Yea, right, sure, Mr. Bill. Sending coders off to security school is going to make thing all better real soon. If you believe that, I have a bridge to sell you.

    Anyone sent off to training comes back knowing some new buzz words and maybe even understanding a couple new concepts. No one comes back cleansed of old habits. I'm reminded of the limerick the you can train a dog but you can't make it think.

    I think the problem you're facing is systemic, Mr. Bill. Detecting and eradicating security defects in your products is impossible. If it could be done, at best the effort such a feat would most likely cost many times that of developing and testing the products in the first place. Automated tools will help pick off the low hanging fruit, but won't get at the really nasty pathological connections. You seem to have made your choices early on Mr. Bill. There's no practical way to rectify them, except starting from scratch.

    Even starting from scratch won't fix the problem, Mr. Bill. The real culprit seems to be the corporate culture you've created. Getting a culture's head straight is a very difficult, if not impossible.

    Unfortunately Mr. Bill, the fundamental problem you're facing isn't an engineering one, but a human one. You may be powerless in solving it.

  314. Re:That GUID on WMP? Yeah . . . by jackbox · · Score: 1

    Now, you can argue users need to be more savvy, or you can accept that Microsoft KNOWS end user behavior and uses it to their advantage.

    Indeed - you never hear Bill Gates saying that computer users need to develop more tech know-how. The MS line is that the computer should take care of all this stuff for the users. Defaults are everything and Bill would just as soon people didn't know there was anything but defaults available.

  315. And Arthur Andersen is focussing on Honesty! by shanelenagh · · Score: 2, Insightful

    To quote from the 80's Wendy's commercial:

    "Where's the beef?!"

    Gee Willekers, Bill Gates is using his bully-pulpit with the press to announce that Microsoft is going to do something that all of there customers have been _wanting_ them to do for aeons. This is about as pressworthy as Larry Ellison advocating a gigantic national database -- running Oracle software.

    This "leaked" email is rather silly. The press should have more restraint in printing patently self-serving "inside scoops" like this. Microsoft is insanely rich -- make them pay for their marketing.

    Shane

  316. Re:That GUID on WMP? Yeah . . . by No+One · · Score: 1

    Uh, dude? You do realize that the same people who bitch about Microsoft's stupid defaults bitched loudly and frequently at Red Hat for their stupid defaults, right? And you do realize that Red Hat now ships their distro with significantly less stupid defaults, which is why they don't get bitched at as much anymore, right? And you do realize that Microsoft's defaults are only marginally less stupid than they were, which is why they currently get bitched at, right?

    Apparently not.

    --

    There is no sin except stupidity -- Oscar Wilde
  317. Re: Scripting by Tony-A · · Score: 2

    Unlikely. Now there's an understatement.
    An unsafe scripting interpreter is more powerful and easier to use than a safe scripting interpreter. To be safe, it probably easiest to run the interpreter in a sandbox where one does not need to trust the interpreter, let alone the script.

    (if it is even possible to write useful scripts in such a limited environment)
    Possible? Yes. Necessary? Yes. Easy? No.
    Gives an idea why Sun gets all uptight about people screwing around with Java. They aren't about to let anybody turn their baby into some sort of Viral Basic.

  318. Re:That GUID on WMP? Yeah . . . by wadetemp · · Score: 1

    I see what you're getting at, but that doesn't apply. Try this one:

    Hide in a 3rd floor window near the parking lot with binoculars, and write down license plate numbers of everybody who enters. Now who gives a damn? Are you going to start bringing binoculars when you drive so you can make a quick security check of the parking lots you stop in? :) There's a difference between doing something that is fairly benign in a flagrant way and doing something benign that no one knows about. When you're flagrant about anything, people tend to respond in an equally flagrant (and occasionally irrational manner.)

    Hey, MS didn't HAVE to provide a checkbox for you to turn it off...

  319. lol !!!!!! lmao !!!!!!! rofl !!!!!!!!!! by Anonymous Coward · · Score: 0

    lol !!!!!! lmao !!!!!!! rofl !!!!!!!!!!

  320. Re:Example #2 IE Code by Sj0 · · Score: 2

    That's gotta be a joke.

    If so, it's damn funny. :)

    If not, it's damn scary.

    --
    It's been a long time.
  321. Apache for Win32 by yerricde · · Score: 1

    He said servers on Windows and he was right.

    How is Apache HTTP Server not a "server on Windows"? Since around 1.3.12, Apache has worked fine on Win32 systems, even Win9x systems. Many people I know use it on their workstations for file-sharing and personal web pages. Of course, you shouldn't be running a Microsoft OS on a production server, but sometimes IE and Mozilla react slightly differently when retrieving pages from http://localhost than from file:///C/web (for example, you can use SSI and PHP), and in any case, you often don't want to be FTP'ing your files around all the time between the development box and the test server, or you can't afford a dedicated test server for the content creators.

    --
    Will I retire or break 10K?
  322. The real significance of Bill's email by Anonymous Coward · · Score: 0

    It's not coincidence that Bill's email was sent out on Tuesday. The release to manufacturing (RTM) of the .NET Framework and Visual Studio .NET came out at the same time.

    Bill's quote: "No Trustworthy Computing platform exists today. It is only in the context of the basic redesign we have done around .NET that we can achieve this."

    Bill knows better than to make rash promises he can't keep. This email is evidence of how deeply he believes that the .NET framework and Common Language Runtime (CLR) are able to deliver on his "new priority" and save Microsoft's reputation. These are not your average Microsoft products; they are potentially a new lease on life for Microsoft. It will take a while for these products to change the anti-Microsoft momentum that public opinion has gathered, but they will. Either that or Microsoft is going under. They've bet the company on this, and there's no going back.

  323. Re:That GUID on WMP? Yeah . . . by drik00 · · Score: 1

    why dont you get webwasher and block the flash domain....works great for x10, and all those annoying popups.

    --
    Beer, now there's a temporary solution -- Homer Jay S.
  324. Re:That GUID on WMP? Yeah . . . by drik00 · · Score: 1
    I've been running Slack for a while, because I have a general idea of the difference between my ass and a whole in the ground, when it comes to computers.

    That being said, if i was installing linux for a newbie, i sure as hell wouldnt use Slack, I'd use Mandrake. You have to pick the right OS for the users...I also use win2k, but my parents run winme. There's a reason different product lines are there.

    Now, that being said, its the same issue as "Guns dont kill people, people kill people"

    you cant blame the gun manufacturer for the dumbass user who blows away his coworkers.

    My point is that people should take responsibility for their own actions. Someone getting paid to sysadmin'ing should know to secure a box AFTER installation. But on the flip side, M$ has no business releasing an end-user aimed product that has more holes in it than a sponge.

    --
    Beer, now there's a temporary solution -- Homer Jay S.
  325. Re:That GUID on WMP? Yeah . . . by lcypher · · Score: 1

    Yeah! It's obvious that the normal guy on the street doesn't give a rat's ass about his privacy, or he wouldn't be on the street!

  326. OpenSSH by Free+Bird · · Score: 1

    The ssh problem was solved years ago, by the OpenSSH team...

    1. Re:OpenSSH by Dahan · · Score: 1

      "Years ago" is technically accurate, I suppose, but just barely... OpenSSH 2.3.0 was released around November 2000--1.2 years ago. And all of the holes I listed have been fixed. That wasn't the point though; the point is that OpenBSD has security holes just like every other OS.

  327. Could you explain exactly why Multics is so secure by Free+Bird · · Score: 1

    Because I haven't seen any proof yet...

  328. Get rid of the unique identifier in WMP by Shadowin · · Score: 1

    I went ahead and wrote a program for the people who want to get rid of the unique identifier in WMP. You can grab it here. Of course, it does change the identifier to a message for microsoft... can you figure it out? =)

  329. Re:That GUID on WMP? Yeah . . . by Tony-A · · Score: 2

    And when you discover someone in a 3rd floor window snooping with binoculars and writing down license plate numbers, ....
    What is benign about writing down people's license plate numbers?
    OK, MS provided a check-box somewhere for this. What guarantee is there that MS provides a check-box somewhere for everything affecting my privacy? Do I have any way of knowing if I have found all of them?

  330. What I really saw while reading Billy's email by King_of_Plow · · Score: 2, Funny

    blah blah blah Trustworthy Computing, blah blah, Trustworthy Computing, blah blah blah blah, Trustworthy Computing...

    --
    "Chiswick! Fresh horses!"
  331. MS websites and browser security ... by joe_citizen · · Score: 3, Funny

    So when will I be able to to visit any of the Microsoft websites with IE browser security set to High?

  332. Re:M$ already own the technology to kill buffer is by Oink.NET · · Score: 1
    You're right on, but with a slight twist: Colusa Software's techniques are an integral part of Microsoft's new security technology.

    See this for more info on the connection between Colusa Software and Microsoft. They mention a virtual machine based on Colusa's technology called CVM. This is now Microsoft's Common Language Runtime (CLR), recently standardized by the ECMA, and inspiration for the open source Mono project.

    They also mention Colusa technology involved in the COOL programming language. This is now Microsoft's C# programming language.

    More info on the .NET Framework security features can be found here. Especially interesting to note is how the CLR's "managed code" concept affects security. "Common vulnerabilities--such as buffer overruns, the reading of arbitrary memory or memory that has not been initialized, and arbitrary transfer of control--are no longer possible." Sounds a lot like Colusa Software's philosophies in action!

  333. Yes, M$ understood the internet. by Erris · · Score: 3, Insightful
    From today's New York Times,

    Microsoft executives said the memorandum resembled previous broadsides that have been fired off by Mr. Gates, the company's co-founder and chairman, when he thought that the company's strategic direction needed radical changes.

    In 1995, for example, Mr. Gates sent a companywide e-mail message exhorting employees to turn the direction of the Microsoft "battleship" and focus all the company's efforts on the threat of the Internet to Microsoft's business.

    They viewed the free comunications media that was growing as a threat. This is why they did not rush to embrace it, but fought to destroy or dominate it. Sure, billg made a vanity web page and company policy was to tell everyone that was all it was good for. I remember it from being there. They rolled netbios out on the majority of their victims and tried to hold off TCP/IP for freaking ever, or at least till winsock was ported from BSD for free and they could steal and sell it. Since then they have done everything in their power to cram their stupid propriatory formats over it by buying out companies and perverting them to spam sites. Like bolshivicks, they seek to disrupt the medium until they can control it. They are evil, and we have yet to see if the internet will win this one but freedom has a way of ignoring snake oil until there is nothing left but a fringe market for fools.

    Security on M$ platforms is impossible. There are no real user ID's, nor file permisions built into the kernel or the file system. The PNP hole on port 5000 iw a great example of this. Why did it take so long to find it? Where were the comercial firewall companies that so many trolls like to tout here? You would think that they would have spotted it and closed it if such things were possible on an OS that does not really keep track of all the processes that are running.

    As I lost two karma points for in an earlier post, the only M$ is going to be able to provide any kind of security is to follow the Apple example and dump Windows. I imagine they will roll a BSD and make some kind of WINE like compatibility mode. It's not going to work. They are far to behind, after all Apple bought up Next and it still took them years. They canned all their good VAX people and gutted the majority of their work as they shifted focus from their failed Unix killer, NT. I don't think so much as their mediocre korn shell made it to win 2000. The ridiculous proposition of a month long "focus" on security by all of their employees shows that they have an impossible task on their hands. Their sins are all looking them in the face and laughing. Had they spent as much time working with other platforms as they did breaking interfaces, swapping print methods and ruining other companies in general, they would be in a much better position today.

    --
    DMCA, Hollings, Palladium. What might have sounded like paranoia is now common sense.
    1. Re:Yes, M$ understood the internet. by matroid · · Score: 1

      Unlike previous changes in direction, Microsoft cannot blitzkrieg itself into a Secure OS. As the Security Community states again and again: computer security takes time. It takes line-by-line code auditing, careful design decisions, and years of testing and analysis.

      If Microsoft is serious about it, securing Windows is definitely a Good Thing (tm) for Microsoft, *nix, and the computing community at large.

      First, as Schneier et al. pointed out, good security in a Windows OS will take a complete redesign from the ground up. There's NO WAY they can hack on patches to Windows and claim that they're serious about operating system security. Furthermore, Microsoft will NEVER let the security community examine "trade secrets" from an already released copy of Windows (if only because they'd have too many fires to put out after bugs were found). And if Microsoft is planning to doall that Schneier et al. suggest, they won't be able to neatly build on existing NT/XP code. Thus, redesign seems like their only option.

      Why is a complete design of Windows a good thing for Linux/BSD?

      • An OS takes a lot of time to build. And if security is the focus, it will need an especially long development cycle. Linux/BSD can catch up during this time. We can add features (securely, of course) and fix our rather minor security/stability problems while MS has to start from scratch.
      • A more secure network OS is good for everyone. Less hacks mean less money lost to computer crime, more consumer confidence in online transactions, less work for System/Network admins, and more protection and privacy for Internet denizens.
      • Microsoft will need to make parts of the new OS public. Although the Open Source community may not be able to use these parts directly (many will probably remain propreitary), we can still LEARN from them, and from the Security Community's feedback about them. More information is never a bad thing.
      • Because MS will feel strapped for time, it will probably "steal" large parts of the existing BSD's in their new OS. Even if they do so unofficially, MS will probably need people familiar with Linux/BSD to modify BSD code for their needs. Over time, this could generate a more friendly relationship between the OpenSource community and Microsoft.

      Of course, all of this is pure speculation. Still, no matter what Microsoft does, at worst we'll be unaffected by Microsoft's new move toward a secure OS. But, at best, I believe the Open Source community could gain a lot.

  334. Re:That GUID on WMP? Yeah . . . by wadetemp · · Score: 1

    The point is, do you lose sleep over the fact that someone can easily take note of your license plate number without your knowledge? Without you having any control over whether they can or not? Or over the existance of the many other ways you personally, and your belongings, can be IDed, without you knowing about it? I really doubt it. There are so many things we DON'T have control over related to privacy, so we choose to bitch about the things that we do. It's a flawed arguement that something you can control (if you care) is a privacy issue at all, when 99% of the things that are (more severe) privacy issues can't be controlled.

  335. Hold on a second... by Snover · · Score: 1

    Does this mean that Microsoft is going to steal Linux? Sure, it's their arch-enemy, but hey! Oh! Now it all makes sense! No wonder they're suing Lindows! Duh! They want the name for themselves!
    ...They are good...

    --

    [insert witty comment here]
  336. New Version was Re:timing? by RyuMaou · · Score: 1

    Um, think about it for a minute. If they want to stay in business, they have to "reinvent" their OS every couple of years anyway. If they don't, what will they have to sell? Have they come up with anything truly new in the past 3 years? (And, no, I'm not counting .NET. They bought most of that when they bought other companies.) Maybe they'll actually build in security the next time around.

    We can dream, right?

    --
    Oh, the trials and tribulations of a network geek! Read about them at: http://www.ryumaou.com/hoffman/netgeek/
  337. See Onion Or Crowd by Anonymous Coward · · Score: 0

    You mean like the CIA onion's project or the AT&T Crowds proxy?

  338. Microsoft's hot new security feature by Alsee · · Score: 2

    At every bootup Windows will contact Microsoft for security activation based on User, Password, HardwareID, and comprehensive SystemLog of all activity.

    Any unauthorized access will result in immediate shutdown. Reactivation will require voice confirmation and explanation of unauthorized activity. 1-900-ILO-VEMS. To enhance your security and combat privacy, fines will be conviently billed to your phone.

    -

    --
    - - You can't take something off the Internet! That's like trying to take pee out of a swimming pool.
  339. Aha! I know why! by Alsee · · Score: 2

    Microsoft HAS to lock down security BIGTIME.
    Microsoft just got a patent on Digital Rights Management Operating Systems.

    If you read the patent you'll see they plan to keep the user locked down with an iron fist.

    If you secure an operating sytem from attacks by authorized users, what chance does an unauthorized attacker have?

    -

    --
    - - You can't take something off the Internet! That's like trying to take pee out of a swimming pool.
  340. Re:That GUID on WMP? Yeah . . . by jo42 · · Score: 1

    Yeah, "{00000000-0000-0000-0000-000000000000}" sounds good...

  341. complain if you will... by deeoji · · Score: 2, Insightful

    True that M$ is nowhere near as secure as *nix; however, as you bash away and curse M$, remember one thing -- if it wasn't for M$, it's bugs, flaws and SIZE, you probably would never have been able to afford the computer you are using to post your bashings. If NOTHING else, at least Bill G. has pushed the market forward and the Windows monopoly has in turn pushed the hardware developers. It is irrelevant which operating system is the most widely used because there will always be the groups of people who don't want to conform and as such feel the need to promote whatever product they use as superior. Well often those people perceive "Alternative" to be synonymous with "Superior" -- that doesn't mean its true. If MAC's ruled the world, you can bet you ass that OSX would be nothing like what it is today - it would not have the slightest traces of *nix and would be the endless target of rants, bashes and various posts by people who just wanted to be "non-conformists". Funny thing about non-conformists though; most of them conform more than they admit. I'd be willing to bet that the majorority of the vitrolic posts concerning this article were derived by someone sitting at their PC - and if they had just finished playing a game (OTHER THAN freakin another freakin quake engine clone) they may still be logged into that hated Windows OS! Yes, bitching all the way, but still, somewhere secreted away is their installation of Windows. So stop ranting about the advantages of Linux and just be happy that perhaps somehting is now going to be done about the security issues at hand and have a little damn respect for the develpers that (misguided or not) have put an OS onto more machines than you can possibly imagine! Monopoly - sure, but at some point those monopolies server/ed a purpose... if it wasn't for the AT&T monopoly years ago you'd still be turning a damn crank to talk to Martha the switchboard operator to call Andy and Barney down at the sheriff's department...

    So in closing - who gives a rats ass what OS you run, ANY attention to security is good for EVERYONE!

    --
    ...n8
    1. Re:complain if you will... by fok · · Score: 1

      what I don't conform with is the constant reboots as a OS feature.

      --
      \m/
  342. The perfect solution by Anonymous Coward · · Score: 0

    I have discovered the perfect solution for M$ security problems. It's called the power button, turn off your windows boxes before you hurt someone please.

  343. Just an email... ??? by _RiZ_ · · Score: 1

    I have personally sent out emails saying I would end world hunger, put the earth at peace, make the israelis and palestinians stop fighting, wake up earlier in the morning, start working out, eat better, but to date not a one of them has done anything other than sit in an inbox, get deleted or just plain ignored. Its MS ya know, whats good for them is never good for us.

  344. Put spending caps on campaigns by Anonymous Coward · · Score: 0

    And provide money amounting to that cap to all candidates.
    Offer free political advertising.

    Part of campaign finance reform is controlling the campaign expenditures, not just controlling donations.

  345. (Professional Page Layout) Re:If.. by Anonymous Coward · · Score: 0

    Ummm, At the risk of feeding even more trolls, use LyX. Who needs WYSIWYGif you can get WYSIWYM! (What You See Is What You Mean).

    LyX works less like word and more like what I'm used to from truely professional DTP software. It uses style definitions throughout for starters. And it can export to LaTeX. What more could you want?

  346. What Schnier is really describing.... by Kramer747 · · Score: 0

    Is a UNIX-like OS!
    Everything he describes is Unix or Linux.

    -No Registry
    -Run server applications as users
    -Configurable installation
    -Seperation of Protocols etc../
    I find it ironic that Bill Gates is being lectured on how to design a 30+ year old operating system.

  347. Re:That GUID on WMP? Yeah . . . by iamwhatiseem · · Score: 1

    It's not only the defaults, but the Microsoft "Trojans" during installations. 99.9% of all end users will use the "Reccomended" install choice when installing Bill's programs and his OS's. i.e. - when installing office 2000, you get the demonic Outlook duo, and internet 'tools'. Programs, that even if you don't use them, still provide holes.