Slashdot Mirror


Air Force Warns Microsoft/Others to Tighten Security

FattyBoeBatty wrote to us with a story from USA Today about the the Air Force and security concerns. The Microsoft point is the primary point of the article, but the AF CIO has also made the point at industry forums, and evidently with Cisco. Specific companies aside, I think it's a good thing that organizations are beignning to realize the exposure they have on security issues - and maybe will actually start to take steps to close them.

115 of 336 comments (clear)

  1. real CIO by The+Iconoclast · · Score: 2, Funny

    i guess in the airforce the CIO is a REAL O. ;-)

    --
    Quando Omni Flunkus Moritati
  2. Then why do they stay? by FortKnox · · Score: 4, Insightful

    Why do they stick with MS if they have security issues?
    Why hasn't anyone asked this question?

    We run Exchange Server, and we get hit by an Exchange Server virii
    Quick solution: Don't use exchange server.

    Why sit and wait for MS to comply?
    It just seems odd to me.

    Note: I'm not saying "Y d0nt j00 B 1337 4nd us3 L1NU><?" I'm just asking why stick with MS.

    --
    Good quote, too many chars. Seriously, the slashdot 120 char limit sucks!
    1. Re:Then why do they stay? by ari{Dal} · · Score: 3, Insightful

      Because the Air Force doesn't want to retrain all their personnel on software they're not familiar with.
      The costs of retraining and reconfiguring all their hardware far outweighs the kick in the ass scare they can put into Bill to fix up what they're already using.
      Just about everyone who has ever come into contact with a computer has experience with windows. From a user-interface point of view, its quick, clean, and easy.
      From a security point of view, its a nightmare.
      Unfortunately, the people who are deciding what to buy and what to install aren't the security-savvy techs.. they're the corporate middle management suits who see the flashy bells and whistles MS offers and bite so fast it'd make your head spin. MS had advertising, marketers, and a well-known product. Security wasn't as big a concern. All that adds up to a major problem today.
      Not only that, but lets face it, back when the USAF were first installing and configuring these services, there weren't many viable options out there. Yes yes, i know .. sendmail, etc. But who was out there pitching sendmail to the AF?

      --
      Moral indignation is jealousy with a halo - H. G. Wells
    2. Re:Then why do they stay? by alen · · Score: 3, Insightful

      It's easier to train users not to open up certain attachments. And with the right software you can block certain attachments all together. With it's faults I still think Exchange is the best corporate messaging/groupware solution. It's fully integrated and you don't have to worry about trying to make a bunch of different products work together to give you the same functionality as Exchange.

    3. Re:Then why do they stay? by regen · · Score: 2

      Another issue is that microsoft will come in and setup an entire system for you. One stop shopping. Believe it or not, this sells. IBM is basically the same way. When you want a complex system put in place its often easier to deal with a single large vendor than several smaller but better vendors.

    4. Re:Then why do they stay? by jsse · · Score: 2

      Why do they stick with MS if they have security issues?

      Who is going to get back the BSOD-submarines when the contract with MS is being terminated?

    5. Re:Then why do they stay? by Pii · · Score: 5, Insightful
      I'm not sure you understand the economics of the military...

      It does not cost the Air Force anything to retrain, nor to reconfigure.

      The Air Force (and the military in general) is already paying for the training of every person that enters the service. It would be a trivial matter for them to re-tool the courses in their Computer Sciences School, so that the students learned some other product or technology. (Besides, it's not like they teach an "NT Systems Administrator" course... They teach basics, like "Computer Programming," or "Computer Operations." The real training occurs on the job, after the E-2 or E-3 posts to his first duty station. In the Marine Corps, I entered as a "Cobol Programmer," and my fist duty billet was in networking (Banyan Vines, Ethernet and Token Ring environments).)

      Likewise, the cost of reconfiguring all of the systems they've already purchased is also free. They have a labor force that they are already paying (that they have to pay, twice monthly, regardless of what they are tasked with), so why not "upgrade" all of the mail systems. It will not affect their costs at all.

      This is a luxury that most of Microsoft's customers do not have, but is a very real, very possible option for the Armed Forces.

      --
      For those that would die defending it, Freedom
      has a sweet taste that the protected will never know.
    6. Re:Then why do they stay? by Amazing+Quantum+Man · · Score: 2

      The interface to Howitzers ran on Solaris (AFATDS), SCO Openserver (IFSAS), or proprietary systems (Paladin, LTACFIRE).

      --
      Fascism starts when the efficiency of the government becomes more important than the rights of the people.
    7. Re:Then why do they stay? by Zathrus · · Score: 3, Insightful

      Sure they're paying for the training of everyone in the military already. But you seem to think that they have nothing better to do with that time than to train them.

      For every hour that an USAF fighter jock, mechanic, paper-pusher, or whatever is in training, that's one less hour they are available to do their real job. And yeah, some people may have enough slack time that this wouldn't be an issue, but I suspect that it's not true for the organization as a whole. You have to look at things like opportunity costs when you're talking about a change over to an entirely new system.

      Plus you're assuming that the trainers would be military also. I seriously doubt that. Which means you have to hire civilian consultants, which involves a rather long and expensive bureaucratic process just to get bids, not to mention the actual cost of paying them for services rendered.

      And, funny thing, this is exactly the same issues that corporations face. After all, they're already paying people for their time, regardless of what they're tasked with. And they're responsible (osteniably) for all job-related training. But the costs - in both time and money - are not insignificant for any company of any size.

      As to the original question - what else are they going to use? There's a great huge gaping whole when it comes to productivity software like Exchange/Outlook. Yes, there's Notes. Yes, there's Netscape/Solaris whatever-its-called-now. And maybe Novell still has a solution (I don't know personally). But none of them match the ease of use, "ease" of administration, and interoperability offered by Exchange/Outlook. They either don't work as well together across various pieces, they cost too much to maintain, or they don't integrate as well into the OS (gee, surprise... anyone? And no... I'm sure being a monopoly had NOTHING to do with that... riiight).

      Yes, the lies about the low cost of administration on Exchange are starting to be revealed now. But only after MS has beaten most of the competition into pulp. Within a release or two Exchange will be considerably better than what it is now. This is how MS operates.

    8. Re:Then why do they stay? by GooberToo · · Score: 2

      The costs of retraining and reconfiguring...

      That's not correct. The cost is the same if they brush their teeth or learn a new system. With the military, it's a fixed cost...for the most part...most military people just do busy work when not at war.

    9. Re:Then why do they stay? by flatrock · · Score: 4, Informative

      Because security is only one of the issues they have to deal with.

      I worked as a contractor in computer support for the Air Force years ago. This was before they used Exchange. They were using DEC Teamlinks where I was at. Teamlinks wasn't very easy to use. The client interface was cludgey and didn't have all the nice integrated features you get with Outlook today. The server which was a DEC Alpha crashed a lot. I think the server was simply a very expensive lemmon. The DEC staff on site, as well as outside support people spent a lot of time replacing parts and tweaking software, but couldn't get it to remain stable.

      Exchange and Outlook were a much better choice even with the risk of a virus taking down the system because the system they had was taking itself down on a regular basis.

      Training is also a serious issue. There was a full time person who's job was to train users to use Teamlinks. One thing many people don't realize is that the majority of the people using this software on an Air Force base aren't military. They're civil servants and contractors. Military people follow orders pretty well, and contractors do as their told, or find themselves without a job. Civil servants are a different story. Contractors come and go, militry people get transferred after about 4 years or so, but the civil servants will still be there when the others are gone. If they aren't interested in learning something, they just make a few excuses and put it off until there's a new Deputy DIrector, or whoever's making the decisions. We had a chief scientist that refused to use the email or calandar software. He had his secretary print all his email and put it in his inbox. She would respond to his email as he directed her to, and handle all the scheduling in the calander software. She had been around for a very long time, and wasn't very computer friendly herself. Every time she got confused or made a mistake, it was the computer's fault, and whoever got the support call was in for a bad day. One contractor didn't seem to realize that she was always right and got himself banned from her office which led to his eventual dismissal. These people don't like to learn new things. If it isn't easy to learn, they pretty much have the ability to make everyone's life a living hell, and sooner or later the people making the decisions realize that any solution has to take that into account.

      While email is a security issue in that poor security can result in lost productivity, it shouldn't be an issue of national security. Confidential and secret information should never end up on the email system.

      In my experience with the AIr Force, the people making the decisions were not technically incompetent. They also requested and received input from many different highly skilled technical people, and they had a lot of experienced people with backgrounds in Unix, VMS, and NT to draw upon. They were trying to get a product that best met all their needs. Security was obviously a consideration in their decision, but it didn't outweigh their need for a usable system.

      The real issue is that the ease of use that they desire is somewhat in opposition to a high level of security. This means that an alternative to Exchange/Outlook may not provide them with greatly increased security. For them to change and eat the rather high costs or retraining their employees, there needs to be a product that does a considerably better better job of meeting their needs, with security only being part of those needs.

    10. Re:Then why do they stay? by elandal · · Score: 4, Insightful
      We run Exchange Server, and we get hit by an Exchange Server virii
      Quick solution: Don't use exchange server.

      A solution allowing internal use of Exchange is also possible.

      Don't expose Exchange servers to the internet. Have internet email come to a secure MTA (no, not sendmail, something more simple and more easily secured). The internet-MTA can then spool email for virusscanning and whatever other mangling needs to be done (remove every attachment with filename ending with .vbs (and a hundred others) and so on). After mangling, forward to internal Exchange servers.

      Easy, doesn't require powerful machines even for a large amount of email (OK, depends on the amount of mangling done), easily replicated to several sites, and likely to be near-zero administration.
    11. Re:Then why do they stay? by Pii · · Score: 3, Informative
      For every hour that an USAF fighter jock, mechanic, paper-pusher, or whatever is in training, that's one less hour they are available to do their real job. And yeah, some people may have enough slack time that this wouldn't be an issue, but I suspect that it's not true for the organization as a whole. You have to look at things like opportunity costs when you're talking about a change over to an entirely new system.
      We are talking about changing the back end, not necessarily the client side. The only people that need retraining would be the IT folk, not every Pilot, Mechanic, or Clerk.
      Plus you're assuming that the trainers would be military also. I seriously doubt that.
      I have no first hand experience with the Air Force in this regard, but I do have first hand experience with the way the Marine Corps does this. Every single instructor at the Marine Corps' Computer Science School is a Marine. Every non-instructor position that made up the rest of the school was either a Marine, or a Purple person (Civilian employees of the Department of Defense). I would be surprised if the same did not hold true for the other branches of Service. (Not terribly surprised... The Marine Corps does a number of things differently than the other branches...)
      And, funny thing, this is exactly the same issues that corporations face. After all, they're already paying people for their time, regardless of what they're tasked with. And they're responsible (osteniably) for all job-related training. But the costs - in both time and money - are not insignificant for any company of any size.
      And this is what people seem to be misunderstanding about the Military... This is nowhere near the same issue that corporations face. Every decision a corporation makes reflects the bottom line, as corporations exist to turn a profit. The Military is not encumbered by this guiding principle. Sure, they have a budget to work within, but if their requirements change, or the need is great, they get additional funds, and they do what must be done to satisfy requirements that no corporation has to consider.

      The purpose of the military is to win wars, and when they make a decision, lives hang in the balance .

      Few corporations can make that boast, defense contractors being the most likely exceptions.

      If the solution carries a higher pricetag, but saves lives, and better enables the military to communicate effectively and securely, putting the ultimate goal (winning wars) within reach, the cost or effort does not matter. For them, bottom line is not the single most important factor in arriving at a solution, and the profit-motive is non-existant.

      --
      For those that would die defending it, Freedom
      has a sweet taste that the protected will never know.
    12. Re:Then why do they stay? by Znork · · Score: 2

      Retraining isnt an argument. People learn to navigate websites, people easily learn to use games, and those are the most UI-divergent 'applications' in existence today, far more different than Windows-vs-GNOME/KDE. Not to mention you have to 'retrain' all those people every time you upgrade MS software anyway.

      If they can handle all that, they can *easily* handle doing their basic job with Linux rather than Windows.

      People arent *quite* as stupid as some UI experts would have us believe (well, most people at least. The helpdesk hoggers are another matter, but they call even if their desktop looks the same as it did yesterday). Most people can easily move from one piece of software to another. They do it every day.

    13. Re:Then why do they stay? by ari{Dal} · · Score: 2

      I wasn't talking about the training of new people coming in... you'll notice in my post i said "REtrain". Anyone who's going to switch software systems to something they've never used before is going to need retraining.. and that's going to be just about everyone from the top down. The initial training isn't the problem, its the repitition of that week of training or so that's going to cause headaches.

      --
      Moral indignation is jealousy with a halo - H. G. Wells
    14. Re:Then why do they stay? by jtosburn · · Score: 2, Informative

      Quoth Zathrus:
      As to the original question - what else are they going to use? There's a great huge gaping whole when it comes to productivity software like Exchange/Outlook. Yes, there's Notes. Yes, there's Netscape/Solaris whatever-its-called-now. And maybe Novell still has a solution (I don't know personally). But none of them match the ease of use, "ease" of administration, and interoperability offered by Exchange/Outlook. They either don't work as well together across various pieces, they cost too much to maintain, or they don't integrate as well into the OS (gee, surprise... anyone? And no... I'm sure being a monopoly had NOTHING to do with that... riiight).

      If you aren't familiar with the alternatives, how can you assess their attributes in any remotely meaningful way? I won't try to provide the answers, though I'm evaluating everything I can find to fill this gap at my company, but for the record, the main possibilities that I see, so far are:

      * MS Exchange
      * Lotus Domino / Notes (can use Outlook as client if you wish)
      * Novell Groupwise
      * Samsung SDS Contact, the next version of HP's OpenMail, which no one appears to have seen yet.
      * Sun's iPlanet Calendar Server, maybe can use Outlook as client, but intends web client access
      * Steltor Corporate Time Server, can use Outlook as client
      * Bynari Insight, also can use Outlook as a client (can you tell that this a (unfortunate) requirement for me ? )

      This is taking the definition of groupware rather loosely...providing email is no big deal, so providing calendar / resource scheduling services is the priority for me. Others may be just as interested in the various collaboration tools and archiving stuff found in Notes & Groupwise.

    15. Re:Then why do they stay? by GooberToo · · Score: 2

      Hmmm...the half dozen people I know that are in the service tell a completely different story.

  3. Nice to see... by Pii · · Score: 4, Interesting
    You know, when a customer that has $6B dollars a year to spend on technology say jump, Microsoft had better damn well be asking "How High?"

    I'm kind of disappointed that the Air Force is using Exchange in the first place. I hope that when they realize that Microsoft is not ever going to be able to meet the somewhat unique requirements of the DoD (For them, lives do hang in the balance), that they are willing to take their business elsewhere.

    --
    For those that would die defending it, Freedom
    has a sweet taste that the protected will never know.
    1. Re:Nice to see... by Pii · · Score: 2
      Well actually, as a veteran (see my Bio) with an IT Specialty, I do actually have some insight as to the requirements for Information Technology in the military. Since I left the service, I've supported myself as a consultant it this industry, so yes, I do have a good grasp of why Microsoft is a bad choice.

      Great post though, really. Keep 'em coming.

      --
      For those that would die defending it, Freedom
      has a sweet taste that the protected will never know.
    2. Re:Nice to see... by Martin+S. · · Score: 2

      You know, when a customer that has $6B dollars a year to spend on technology say jump, Microsoft had better damn well be asking "How High?"

      EXCEPT it appears that Microsoft have been giving the Air Force the run around for two years. If they can do that, what hope do morals have ?

    3. Re:Nice to see... by BlueboyX · · Score: 2

      I am afraid I agree. I would think that the DoD would want to use their own version of Linux or an OS totally their own. The military historically has made alot of their own stuff using their own programming languages. Why would this be different?

      I think that I can answer my question myself though. With spending cutbacks + computers in every military building, they need something that they can easily and cheaply contract new software for. Windows has VB, VC++ etc so that the same app can be more cheaply than for other OS's (well, whether that is true or not is not as important as the fact that the BELIEVE that it is true). Like many corporations nowdays, they just want to point to a problem, throw some money at someone and say 'fix it' without having worrying about it anymore. This would be as opposed to having teams of their own computer scientists writing programs for and supporting Linux/DoDix/whatever.

      I am thinking that their current use of windows is a transitional state, but a transition to what is the quesiton.

      --
      "Never, never suspect the dreams within the dreams of dreaming children." ~The Amazon Quartet
  4. canadian air force by Toshito · · Score: 4, Funny

    The canadian air force is also putting a lot of pressure on punch card manufacturers to force them to close a lot a security holes in their software...

    --
    Try it! Library of Babel
  5. Not a matter of warning by jfonseca · · Score: 2, Informative

    It doesn't matter who warns Microsoft and when. Security isn't something you suddenly do, it is built from architecture to deployment, and Microsoft is nowhere close to engineering any secure products.

    Windows is insecure in its conception, and unfortunately I see very little that can be done to reverse this.

    --
    Broken Hearts are for Assholes. - Frank Zappa
    1. Re:Not a matter of warning by rhizome · · Score: 2, Interesting

      You probably have a different sense of "security" than Microsoft does. The edict from billg was only the first step in Microsoft's embracing and extending the public's perception of computer security. It's not that MS will re-engineer their software to meet security standards derived from decades of experience, because Microsoft has never done anything like that. The closest example to this process would be the focus on Internet Explorer throughout the late '90s, where MS made strides in browser engine design, but at the expense of standards and other browser companies. Microsoft has never played nice in the sandbox (only "concessions", like today's MSKerberos story from the EU), they simply use advertising and PR to redefine "security" as "that which Microsoft provides".

      --
      When I was a kid, we only had one Darth.
    2. Re:Not a matter of warning by jfonseca · · Score: 2, Interesting

      Microsoft's sense of security is not only different from mine, it is different from reality. Like a PhD thesis, these types of things are only proven in practice, and practice shows, time and time again, that their approach to software construction is insecure.

      And still some admire them for releasing timely patches. Well if were Microsoft I'd thank the white hats for warning them of a security flaw weeks before the public.

      I agree with you. Their view of security is a marketed approach to security. Just read what Bruce Schneier has to say about Microsoft's "sense".

      Still on the practical side of things, not going into OS wars, just subscribe to bugtraq and do a little statistics on daily microsoft bugs and holes discovered. I find it amazing that anyone out there on mission critical environments, specifically official government and defense agencies, are still using this stuff.

      I apologize if I am offending some Microsoft fans out there but to me Microsoft security, reliability and credibility have ceased to exist long ago.

      --
      Broken Hearts are for Assholes. - Frank Zappa
    3. Re:Not a matter of warning by Pii · · Score: 2
      Ummm... No.

      You have adequately defined what the Internet was designed for, but you have mislabelled it.

      The Internet was not designes to be secure. It was designed to be redundant, or fault tolerant, and the protocols it uses are designed to ensure standards based interoperability.

      I whole-hearedly agree with your sentiments regarding Postel and company, though.

      --
      For those that would die defending it, Freedom
      has a sweet taste that the protected will never know.
    4. Re:Not a matter of warning by Pii · · Score: 2
      I understand how you can include redundant capabilities into a comprehensive view of security, but I don't think that's what the original poster meant when he referred to "security," nor is it what most people would categorize as "security" today.

      Aside from that, your view falls apart for other reasons. If, as you seem to believe, the protocols commonly referred to as TCP/IP were "designed to be secure," or to "provide security," then why was packet-level payload encryption only recently (in the 30 years of TCP/IP) added? How did usernames/passwords transmitted across the network in clear-text become the norm, rather than the exception? Why was source routing ever included?

      The TCP/IP protocol suite is not, nor has it ever been, about security. It has always been about redundancy, fault-tolerance, and interoperability.

      "Security" has until recently been left to the applications themselves. Security has always been an afterthought. If that were not the case, how would the man-in-the-middle attacks, and packet sniffers, ever have posed a security risk?

      Our favorite little DARPA project did indeed begin as a defense project, and was primarily to increase our level of national security, but that end was served by providing the mechanisms to route around failures in the network, not in keeping the network traffic safe from prying eyes.

      --
      For those that would die defending it, Freedom
      has a sweet taste that the protected will never know.
  6. Re:Try as they will.. by jmb-d · · Score: 2, Funny

    you think the Military is going to get any progress??

    Sure -- the military has weapons that go *boom*, as opposed the government as a whole, which has a Justice Department that just goes bust.

    --
    In walking, just walk. In sitting, just sit. Above all, don't wobble.
    -- Yun-Men
  7. Re:Is this government's role? by Pii · · Score: 5, Interesting
    Political pressure? Hogwash...

    The Air Force is waving it's $6 Billion annual budget at Microsoft, and saying to them that if their shoddy, unsecure software does not dramatically improve, these dollars will be going to your competitors.

    That's called "Economic Pressure," and in the free market, it's the single greatest motivator ever, and it always will be.

    To put it in democratic terms, the Air Force has issued fair warning that it intends to "vote with it's feet."

    --
    For those that would die defending it, Freedom
    has a sweet taste that the protected will never know.
  8. Re: It's not the server, it's the client. by Robber+Baron · · Score: 3, Insightful

    Exchange may have it's faults, but I've seen virii spread with equal rapidity via Sendmail. If you want to blame something, blame Outlook. Or more correctly blame the default settings to which Outlook installs.

    --

    You're using her as bait, Master!

  9. Re:Is this government's role? by sharkey · · Score: 2

    government harrassment of the vendor

    I think you misspelled "government bending over for the vendor".

    --

    --
    "Outlook not so good." That magic 8-ball knows everything! I'll ask about Exchange Server next.
  10. Responsibility by ksw2 · · Score: 5, Insightful
    As much as I enjoy seeing Microsoft get negative publicity, maybe the Airforce should evaluate their own security practices... I mean, wasn't the Lovebug an email attachment virus? Couldn't a relevant security policy have changed this? I'm not fluent in Windows holes, but it seems to me if they have a huge problem with Outlook in particular, USAF could mandate Eudora as their official email client rather easily.

    I'm not trying to say M$ is inoccent, I just want to point out that no matter how secure the OS is, users need to be educated in computer security, or it's all going to go to shit anwyay. My $0.02 (cha-ching)

    1. Re:Responsibility by MillionthMonkey · · Score: 3, Insightful

      As much as I enjoy seeing Microsoft get negative publicity, maybe the Airforce should evaluate their own security practices... I mean, wasn't the Lovebug an email attachment virus? Couldn't a relevant security policy have changed this?

      The Air Force shouldn't be using Outlook. How did the worst possible email client get deployed in the Air Force? It's a platform for launching viruses and worms. (You can also read your email with it.) Users should be able to click on an email attachment- hell, they should be able to view the email in a preview pane- without having to worry that it might propagate a worm. Period. Anyone who thinks otherwise shouldn't be let anywhere near a compiler.

      Using Outlook is inherently risky. Our company has standardized on it for some reason (it comes with Office is why, I guess) and our network admin is resisting whiny requests from management for an Exchange server. Just last week someone using Outlook clicked on an .scr attachment he got from a guy he exchanged business cards with at a conference. Well, as soon as he did that, the .scr went out to every single one of our customers. ("Hey, c'mere, what's an .scr file supposed to do?") Serves us right, I guess.

      If I were a four star general and that happened to me, I'd want to drop a daisy cutter on the Microsoft campus.

    2. Re:Responsibility by WildBeast · · Score: 2

      Look, if I, a Junior sysadmin was able to protect my company from the ILOVU virus (we use Exchange and Outlook btw); I have to wonder how the government fails to protect itself. Maybe the sysadmins in there are ignorant or maybe they just don't have much time on there hands.

    3. Re:Responsibility by flatrock · · Score: 2

      You can make it so Outlook won't run .scr files. I agree that this should be the default case, but this is something you can fix.

      Your company has probably standardized on Outlook because they need Calander and a Mail CLient, and Outlook is a powerful, integrated tool for these tasks, ..... and it comes with Office. Outlook is very insecure in it's default install, but if can be made much better with a little effort. You trade sume functionality for the increased security, but that's uaually a tradeoff you have to make for increased security.

      You definately don't like Outlook, but what do you reccomend? What do you think is a good replacement for the functionality that Outlook provides, including features such as calander software and such?

    4. Re:Responsibility by flatrock · · Score: 2

      They like everyone else always have more to do than time to do it, but they deal with a tremendous amount of email volume from all over the world. This means that they often get these viruses before the security alerts go out, and don't get the advanced warning that many small companies get the benefit of.

    5. Re:Responsibility by DunbarTheInept · · Score: 2

      You bandy about the word "prevent" too easily.
      If thpse updates actually prevented the spread of viruses, there would only need to be one such update. But they keep having to come out with new ones, for some reason - oh yeah, because the previous ones didn't catch everything.

      --

      Don't label something "offtopic" unless you know the topic well enough to tell what's on topic.

    6. Re:Responsibility by frank_adrian314159 · · Score: 3, Informative
      You definately don't like Outlook, but what do you reccomend? What do you think is a good replacement for the functionality that Outlook provides, including features such as calander software and such?

      Lotus Domino. Preferably on an IBM iSeries, but on a PC if you have to. All of the calendaring, none of the viruses...

      --
      That is all.
    7. Re:Responsibility by sheldon · · Score: 2

      If you do not understand the issues, please don't bother to respond.

      The updates I spoke of are only re-released when new versions of the applications come out, for compatibility reasons. Yes, the virus definition files do have weekly updates, but that is all.

      Are you even aware of the Outlook 2000 update and what it does?

    8. Re:Responsibility by zeda · · Score: 2, Insightful

      How do you think Outlook got deployed.

      Some Generals were probably conned by M$ sales reps like usually. Except when Generals give orders you have to obey.

    9. Re:Responsibility by DunbarTheInept · · Score: 2

      It doesn't matter what the Outlook 2000 update does. ALL software has the following common problem: FIRST the exploit is discovered, THEN LATER it gets patched. Thus to claim that a patch "prevents" the security holes is a claim that cannot possibly be true. There will always be a window of time between discovery and patch during which the system is vulnerable. It cannot be any other way.

      --

      Don't label something "offtopic" unless you know the topic well enough to tell what's on topic.

  11. Re:Is this government's role? by BasharTeg · · Score: 5, Interesting
    Let's let free enterprise do its job. Political pressure has no role here. The private sector must remain free and independent so that it can provide the solutions that the marketplace wants.


    This is complete garbage. The government is a customer and a member of the marketplace too. Just as IBM, or DELL, or some other company who does business with Microsoft could put "pressure" on them, so can government agencies, who are customers also. The government harrassment, and Air Force's "threatening posture" are no different than two businesses exchanging fire over their differences. THIS is how free enterprise works. You are free to make a crappy product, but the Air Force is free to complain about it, demand that you fix it, slam you publicly about it, and threaten to take action, including switching to another product. You're forgetting the consumer side of "free enterprise."


    Besides, national security is a priority, and they have every right to demand security in the software that's trusted for that use. What happens when NASA buys a crappy booster rocket, and it falls apart? Are they not allowed to put political pressure on the company that produced it, because that would be a bother to free enterpise? Give me a break.

  12. Being a Communications/Computer officer in the AF by gsfprez · · Score: 5, Insightful

    I totaly disbelieve this article.

    We are whole heartedly all out sold out to Microsoft.

    We (actually, the US military) have recently implimented a MS only messaging solution using Exchange and Outlook called DMS. The solution took well over 6 years to develop secure email (snicker), and still doesn't work right. Even though there is freeware that could have been implimented that we would be able to see the source code for - the PHB lemmings of the AF chose, instead, to go with a MS solution.

    We also recently moved to a multi-thousand GAL (global Address list) - the microsoft proprietary solution which has opened us up for years to things like Mellissa and I LOVE YOU and all of that other crap that used MS features to spread itself like wildfire.

    Every base has MS license agreemets for support - and by those agreements - like the rest of the world - are either going to continue paying $.50 a hit for our fix each year, or pay $100 each time we buy another computer.

    As a young Lt., I spent 6 months replaceing perfectly functional Solaris boxes that performed our web, smtp, DNS, SQL, and other basic network services with NT 4.0 boxes. A week after we recovered from Service Pack 2 - i strongly recommended that we slow our migration - and that it was costing us more time and money supporting Windows machines than the UNIX boxes which never needed any work or upkeep. Some had uptimes of 4 years until I pulled the plugs on them. (don't beat me - i was the lowest ranking puke in the house - and i did what i was told)

    After the first virus attack - I stood up in a meeting and demanded to know why the room wanted to spend all its time figureing out how to rip out the functionalities of the Windows boxes that made us vulnerable and didn't look at solutions which were inherently not vulnerable - and was flabbergasted. It was like I was in a room full of guys from Boston and had said that the Bruins sucked. They all became instant apologists for MS and their shit software... how it wasn't that hard to fix the problem and that we had virus software, yada yada yada..

    Meanwhile - my home Mac OS 8 server was chugging along just fine, even though I had gotten the viruses from lots of people at work. But it easily could have been a FreeBSD or Linux box too.

    This is a lot of huffing a puffing. Its a farce. It is because there is no one with the nads to make a descision against what everyone knows - that MS 0wn2 J00, stupid Air Force.

    --
    guns kill people like spoons make Rosie O'Donnell fat.
  13. mistaken perceptions.... by rusty0101 · · Score: 5, Insightful

    I was just thinking back on why this might be a problem for the military in general. Havng had some experience as an admin in the Army, amoungst some other experiences, I feel comfortable with the asertion that from the perspective of a software user, the millitary is no different than any major corporate entity. While they do have hardware and software than most corporations do not have, the same can be said for GM, Sabre, and Citicorp. Yet for most day to day operational stuff, admins, supply people, and more and more mechanics are using off the shelf software to support their job. Part of this is cost savings. Even at inflated dod prices, it costs them less to purchase Office than it does to write their own office suite. For situations that do not require hardened computers, it is cheaper to buy off the shelf than to custom order. That doesn't mean that these systems require any less security than corporate systems do, or even that they need more security, though that is arguable. However the implications of a hacked PC that manages where soldiers are going to be stationed, or what parts are in inventory, or what grade screw belongs on that part of the engine, are a bit different for computers in the military than they are for a corporate office. Likewise for whether that order makes it to the server in a timely manner. For a buisness, it means money. For the Military it also means money, but it can also mean lives, or battles. -Rusty

    --
    You never know...
    1. Re:mistaken perceptions.... by Pfhreakaz0id · · Score: 2

      if the military is anything like the gov. agency I contract for, money is allocated in fiscal year budgets, period. That's better than public companies, which only look a quarter ahead.

    2. Re:mistaken perceptions.... by dillon_rinker · · Score: 2

      It's not just the military or your government agency...it's the whole government. NO monies are allocated on anything more than an annual basis...thus the yearly budget fiasco. It would be VERY difficult to extend this to much more than two years, since the House originates all appropriations bills, and they have 100% turnover every two years (though some of the reps get rehired).

      My sister-in-law worked on a ten year project, and every year was a nail-biter as she waited to find out if the last 4-5-6 years of work had been wasted or not.

  14. Re:It's their own fault by tongue · · Score: 2

    Government organizations more so than anyone else need a scapegoat to point a finger at when something doesn't go right. Free software is starting to make inroads into these types of organizations, but the root of the problem is the level of bureaucracy that has to be dealt with in order to actually DO anything in government. In the name of protecting taxpayer "investment", there is all sorts of documentation, testing, and basic criteria that have to be met, and while Linux and BSD are completely capable of meeting those criteria, they require someone like RedHat to actually do the legwork to get them in the door. Up until very recently nobody has been interested because of the level of nastiness that has to be dealt with; with the advent of the NSA's secure linux, however, this may be apt to change in the near and not-terribly-distant future.

  15. But by wiredog · · Score: 2

    If the Air Force is anything like the Army, it's the sergeants who keep things running.

  16. No Security without Liability by Lysander+Luddite · · Score: 2

    We'll never see (more) secure products until the manufacturers become legally liable for losses due to the software. There's simply no financial incentive to improve security, especially if you're the biggest player.

    My guess is, this letter was an attempt to secure a cheaper license from MS. They're not going to simply switch over to something else.

    1. Re:No Security without Liability by Error27 · · Score: 2
      Liability is a bad idea. It is a right of free speech and free thinking for people to be able to create any type of software and distribute it so long as it isn't malicious. They shouldn't have to have a legal department.

      If you ask me, the airforce can't complain. Everyone smart enough to watch TV can tell you Microsoft does not make secure products.

      It's stupid to pretend to be shocked by this. If anyone should be have to pay for Microsoft's security problems it's the people who bought the software with known security problems... Oh wait, they already do.

    2. Re:No Security without Liability by Lysander+Luddite · · Score: 2

      So basically it is the user's fault they used the software simply because software is free speech? That is a silly argument.

      Under your argument the customer should have been liable for any problems caused from Y2K bugs. Instead what happened was laws were passed that created a financial incentive for IT pros to certify everything was y2K compliant.

      If you want to write software that absolves you of any kind of product liability then you should not be charging for it. You can then hide your product up in the free speech argument all you want. Name me any other industry where a manufacturer can pawn off ALL (not just gross negligence or imporoper use of the product) but ALL responsibilities for product defects onto the customer.

    3. Re:No Security without Liability by Error27 · · Score: 3, Insightful
      "If you want to write software that absolves you of any kind of product liability then you should not be charging for it."

      That's a good distinction to make because it allows free speech. It seems like a small thing, but all the software I use at home falls under this catagory.

      In some ways, it's reasonable for vendors to be held responsible for their products, but the idea is still problematic. Liability hurts small vendors more than large vendors. How do you measure the harm done? How do you assign blame to products that were developed by more than one company? Is every Linux company liable for a problem in the Linux kernel? What about software that costs money but is downloaded from another country? What about free products such as Internet Explorer or Outlook?

      Some of common security problems are really user interface problems. For example, most users misconfigure windows network neighborhood. Is Microsoft liable for that?

      In your first post you stated: "My guess is, this letter was an attempt to secure a cheaper license from MS. They're not going to simply switch over to something else."

      I agree with you, and I suspect no new laws are going to change this. There may be some consumers that may need protection from vendor laziness, but the airforce knew about the problems with Microsoft products and chose to use them anyways. I don't think they should be able to sue Microsoft for something they knew was going to be a problem all along.

    4. Re:No Security without Liability by Lysander+Luddite · · Score: 2

      My whole problem with the free-speech protects me from liability argument is the fact that all benefits flow to the programmer/seller and none to the consumer.

      Now if you don't charge for a product then I can see how liability wouldn't be an issue. However, if you sell me a product you have engaged in a market contract. I am buying the product assuming it will perform as advertised.

      Take the iPod/iTunes fiasco. When i-Pod was released there was an update to iTunes which, in some circumstances, erased the user's hard drive. Since iTunes was a free download the responsibility is on the owner. But if Apple sold that piece of sftware they should be liable because I obviously didn't pay for software that would delete my harddrive upon installation.

      Yes, small software developers would be hit the most. That is regrettable. OTOH, I have found software written by smaller companies to have, in general, fewer bugs.

      I'm not asking for perfect software, but users should have a reasonable expectation that software they willingly have purchased will not cause losses. If I buy a car I just assume the tires will not blow if I take a corner fast. Likewise, if a software bug is known and nothing done to resolve it in a timely manner, then I should be able to collect damages commiserate with my losses.

      There is no easy answer. Saying people should just move to Open Source or do more shopping are not operating within the business realities of contemporary America.

      Thank you for the chance for discussion.

    5. Re:No Security without Liability by Error27 · · Score: 2
      >>My whole problem with the free-speech protects me from liability argument is the fact that all benefits flow to the programmer/seller and none to the consumer.

      I completely agree with you that the free-speech argument can only affect authors and distributors, not vendors. In my mind saying "Vendors should be held responsible" is entirely different than saying "Programmers should be held liable."

      You may be entirely correct when you say that vendors should have some level of responsibility. It opens a whole can of worms, but it's something to potentially consider.

  17. Dept of Interior's Network - An Interesting Story by gdyas · · Score: 5, Interesting

    Not about the Air Force or MS, but related.

    The Dep't of the Interior's networks & web sites are now just coming back up, after being shut down for over 2 months by court order due to an almost complete lack of security on the network that allowed virtually anyone with a port sniffer to get into the Indian Trust Database -- a terrible failure of their IT, and a wonderful example of how exposed & poorly run many government networks are. CNN has a short summary.

    The interesting story here is that my mom (a Nat'l Park Service employee) was recently given a service award for letting the accounting people go to her house & use her computer at home (which I set up, and is secure, running WinXP behind a Linksys BFSR41 routed switch w/ firewall) to install software to make payments to contractors, do office supply, etc.

    Interior deserved what they got & should have had their shit together, but the result was over 2 months of torture for almost every DoI employee. It's fearsome, though, that a firewalled home connection could be more secure than government and military networks. I dunno about the military, but Interior is apparently desperate for decent IT support.

    --

    The only tool you've got against psychosis is experience.

  18. Re:A step in the right direction... by praedor · · Score: 2

    It might make a dent in M$ is the Air Force follows the Army's lead and switches to Apple. Pretty damn secure is Apple, love Macs or hate 'em.

    --
    In Bushworld, they struggle to keep church and state separate in Iraq as they increasingly merge the two in America.
  19. Isn't the AF due a letter from the MS or BSA? by theinfobox · · Score: 5, Interesting

    This "warning" to Microsoft makes me wonder if the Air Force will soon be recieving a letter from MS's Licensing Dept. about whether they have the "correct" number of Windows and Office licenses.

    And on a more serious note... A couple of posts have questioned why the AF uses MS products. When I was in the Air Force we were directed to convert our bases' Novell/cc:mail/Linux servers all over to MS products. The reason we were told was that they wanted a standard set of products used at all AF locations. This way, when you went from base to base, you would already be familiar with the software infrastructure. The reason MS was chosen was because it was easier to train people to learn the basics of Windows compared to the others. At the time, the Air Force was also learning that if they spent 4 years teaching someone to be a Linux/Solaris/etc guru, they would opt for a civilian job when their re-enlistment time came(i.e. they rather double or triple their salary and not have to worry about being sent to Bosnia).

  20. A few reasons by devphil · · Score: 2


    You don't simply up and abandon your entire email structure on a whim. First you threaten the manufacturer to improve or else, and that's what the AF has done.

    I work on an AF base, and in my building alone we have about a half-dozen Exchange servers. (One alone can't handle the load.) What do you recommend as the "quick solution" here? What suite of programs are we going to use on all the desktops now that Exchange is gone? Remember that it doesn't just do email; it does tasks and meetings and all that crap.

    What "quick solution" do you recommend for thousands of people at a time?

    --
    You cannot apply a technological solution to a sociological problem. (Edwards' Law)
    1. Re:A few reasons by Chang · · Score: 2

      One possible quick solution would be an IMAP server(s) and the Bynari Insight Connector.

      I've tried it and it does what they say it does.

      Exchange does NOT do tasks and meetings. Outlook does. Two Outlook users on separate ISP pop accounts can schedule meetings and send tasks back and forth. The only thing Exchange adds to the mix is handling free/busy times and Outlook has the capability to publish these to something other than an Exchange server.

      Exchange is a proprietary IMAP server with window dressing, and marketed to make PHB's think they can't use Outlook's features without it. Obviously you bought into that.

    2. Re:A few reasons by frank_adrian314159 · · Score: 2
      What suite of programs are we going to use on all the desktops now that Exchange is gone? Remember that it doesn't just do email; it does tasks and meetings and all that crap.

      What "quick solution" do you recommend for thousands of people at a time?

      Lotus Domino. Preferably on an IBM iSeries. Consolidate your six Exchange crap-boxes into one Model 820 with six server LPARs. All of the calendaring and better searching than MSX, with NO viruses (as of yet). I can't believe that the military is so stupid as to think that MS is the only groupware supplier out there.

      --
      That is all.
    3. Re:A few reasons by devphil · · Score: 2


      Exchange is a proprietary IMAP server with window dressing, and marketed to make PHB's think they can't use Outlook's features without it. Obviously you bought into that.

      Well yeah, because it' true.

      --
      You cannot apply a technological solution to a sociological problem. (Edwards' Law)
  21. Re:My Humble Opinion by gmack · · Score: 5, Interesting

    That is a complete load of crap. How many apache exploits have we seen in 2 years? How many in IIS? Apache runs 60% of web sites according to netcraft. Yet Apache has had few exploits.

    What really blows your theory apart is that in the past there have been smaller companies with worse records.

    MS' problem is that they never seem to consider the security implications when they start tossing on new features. Then when something does break they pass the blame. Or cry about getting more attention for being the leader.

    I find it rather sad that they clame to have a server that any monkey can set up and run but then when it breaks they blame the monkey.

    The problem does *not* end with the discovered exploit either. Exploits happen and they need to deal with them properly.

    This means:
    Not treating exploits as a PR problem.
    Not rolling bug fixes into feature upgrades.
    Not having other software accidentally remove fixes.

  22. This makes sense now... by niola · · Score: 2

    From the article:
    Gilligan, former Energy Department CIO, has discussed security most often with executives at Microsoft. "They are the biggest supplier to the Air Force, and my attempt has been to encourage them to set an example," he says.

    I am guessing if M$ is a major supplier of software to the Air Force, it is probably the same for the other branches of service as well.

    Now I see why all of our helicopters and planes have been crashing without being shot down. Brings a whole new meaning to "Fatal Exception"

    --Jon

    1. Re:This makes sense now... by praedor · · Score: 2

      Except that the Army has switched to Macs because of security headaches.

      --
      In Bushworld, they struggle to keep church and state separate in Iraq as they increasingly merge the two in America.
    2. Re:This makes sense now... by niola · · Score: 2

      Except that the Army has switched to Macs because of security headaches.

      Seriously? Where did you hear that? I find that interesting.

      I have never been much of a Mac fan and as user-friendly their OS was, before OS X it performed like a pig and lacked such common features as preemptive multitasking, etc.

      Good for Apple. It would be nice to see them gain some market share. Now only if their hardware was more affordable...

      --Jon

    3. Re:This makes sense now... by Spencerian · · Score: 2

      Here's a link to this change, from the makers of the WebStar web server software for Mac OS. This was a couple of years ago.

      http://www.webstar.com/army/

      This was based on Mac OS 9 technology, which is pretty unhackable. Mac OS X is just another UNIX in the Web world (uses Apache) but WebStar is making a OS X version of its web server that doesn't sound like they're putting a GUI on Apache but using their own code.

      --
      Vos teneo officium eram periculosus ut vos recipero is.
  23. Security Upgrade by suitti · · Score: 2, Insightful
    Upgrades are painful. When the vendor makes big changes, upgrading to another vendor reduces the differences in costs. If the Air Force wants better security, they'll need to upgrade. The cost of upgrading to, say, Linux, may be cheaper than the cost of upgrading to the next MS product. And, the security implications may be well understood by then.

    The costs that many are concerned with are new applications checkout and user education.

    When a local church was considering upgrading their Windows 3.1 system to 95, 98 or NT, I suggested that it would be just as easy to upgrade to a Mac. The secretary didn't know how to use anything other than WordPerfect, and the new Pastor already knew how to use a Mac. That left teaching the secretary how to boot and shut down the Mac - which you'd have to do with 95, 98 or NT. Naturally, the Air Force would have more work to do.

    When the DOJ case came out, at least one comment circulating was that the US should simply stop buying MS products - as that would cost MS more. As I understand it, this is the China solution.

    --
    -- Stephen.
  24. Absolutely by GedLandsEnd · · Score: 2
    The Air Force is displaying what we can only hope is a shifting in the mind-set of M$ customers - not litigants. Hopefully, other big-budget customers of M$ will follow suit.

    Since 9/11 and the new attention paid to security, more people are willing to make good on their threat to take their business elsewhere if the security of a product is poor. The excuse of comfort with Win products will no longer be an excuse to let Bill off the hook.

    M$ being a marketing firm will respond to market pressures way before they'd give up in court.

  25. Pot Calls Kettle Black - news at 11:00! by Medievalist · · Score: 2

    /.
    Given the history of inept system administration in the US Armed Services, I have to laugh.
    If M$oft actually delivers a secure system, it will immediately be compromised by some knucklehead who wants to play Everquest without his superior officer finding out.
    --Charlie

  26. The Media is getting a clue by tb3 · · Score: 3, Insightful

    I think mainstream media may be finally catching on. This is the first article I've seen were they flat-out state that Love-Bug, Melissa, Sir-Cam, and Nimba are Windows/Outlook viruses, not email viruses or internet viruses.

    Accuracy is nice, maybe the general public will soon learn who is really at fault here.

    --

    www.lucernesys.comHorizon: Calendar-based personal finance

  27. Re: It's not the server, it's the client. by Steveftoth · · Score: 2

    The difference is that Outlook server gives you the ability to create huge expanding without your control mail lists. Thus, one user can send a thousand emails because he has access to those thousand email addresses via the outlook server.

  28. Not necessarily by joib · · Score: 2

    There are more secure alternatives than sendmail. For example qmail and postfix. And sendmail has reportedly improved lately too. Personally I'd take any of them over exchange any day.

  29. Tale from the trenches... by PHAEDRU5 · · Score: 3, Interesting

    When I was stationed at Langley I was part of a team that implemented the first version of what's now called CTAPS.

    One part of the project was to take an existing application, Combat Airspace Deconfliction System (CADS), written in Modula 3 on a PC and re-implement it in C/GKS on a MicroVAX III running Ultrix.

    A couple of months after the re-implementation, my team got a call from an Army guy looking to use CADS. We asked him if he wanted to buy a MicroVAX III and learn how to use UNIX. Answer: No. He got the TEMPEST Z-150/Modula 3 version, as did a lot of other people.

    The reason Microsoft has gotten around is that it offered a reasonably simple-to-use product on a reasonably cheap hardware platform. Things may have changed since then, but there is a reason Microsoft is everywhere, and it's not all to do with a lack of military intelligence.

    --
    668: Neighbour of the Beast
  30. Re:Being a Communications/Computer officer in the by Zeinfeld · · Score: 2
    We (actually, the US military) have recently implimented a MS only messaging solution using Exchange and Outlook called DMS. The solution took well over 6 years to develop secure email (snicker), and still doesn't work right. Even though there is freeware that could have been implimented that we would be able to see the source code for - the PHB lemmings of the AF chose, instead, to go with a MS solution.

    And what public domain software is there out there that suports S/MIME security labels as mandated by the DoD?

    PGP is simply not up to the task of providing a military messaging system. In fact the principle insight that Phil Z. had was that PEM was being designed with the assumption that the rest of the world ran according to the strict hierarchical principles of the military.

    What the posters on this whole story don't understand is that they have a radically different approach to security than the Air Force. In the real world you increase security by removing features. In the military you increase security by adding security features.

    DMS was designed in the days before 'Commercial Off the Shelf' (COTS) became a US govt buzword. The military do genuinely have a number of requirements that are not shared by the general public, such as the ability to continue functioning after the loss of 80% or more of the infrastructure in a particular locality. But there is no reason why they need their own message formats and there is no reason why DMS can't use COTS to provide at least a core.

    --
    Looking for an Information Security student project suggestion?
    Try http://dotcrimeManifesto.com/
  31. Re:Try as they will.. by BLAMM! · · Score: 2, Interesting

    Tis true. But the sad fact is that the AF has a terrible time holding onto the technically savvy people needed to make this happen. Once trained, they get out to make 2 or 3 times the money in the civilian world. I know I was one of them.

    Speaking from experience, the typical geek simply isn't cut out for the military life. And to make matters worse, advancing in the military means spending more time being a pointy-haired boss and less time being a geek. That's the way it is.

    I'd love to see linux adopted by the AF, but 1) I've had the suggestion shot down too many times myself to expect it to actually happen and 2) they will have a tough time gathering the experience to do it.

  32. Eudora wouldn't help by devphil · · Score: 2


    You forget that Outlook+Exchange is more than an email client. Yes, we could mandate Eudora (or whatever) as an email client. What then do we mandate for a meeting scheduler and a remote task assigner and all the other crap that Outlook+Exchange does?

    And then who are you going to get to train people in all these new programs?

    --
    You cannot apply a technological solution to a sociological problem. (Edwards' Law)
  33. Re:My Humble Opinion by sphealey · · Score: 4, Interesting
    In my humble opinion, the only reason all the security holes are being found in Microsoft's software, is by virtue of the fact that it is, like it or not, running the majority of the world's computers, something like 95%. I am sure that if any other OS was as widely used, more breaches would be found
    How long have you been involved with information technology? Do you remember the days when computer systems actually worked according to specification? And when their suppliers could understand and fix things that were broken? To pick a very recent example, were you around when Microsoft marketing and monopoly clout started pushing Netware out of the NOS arena, despite the fact that Microsoft's offering had 20% of the features and 5% of the stability of Netware? Have you ever compared MS Active Directory to Novell eDirectory on a point-by-point basis, including features, managability, and stability?

    sPh

  34. Re:Not a matter of warning: Really? by praedor · · Score: 3, Interesting

    Yeah, keep parroting this...then you should mention that at the same time the vulnerability was announced, a fix was available: download zlib-1.1.4. Sheesh. You NEVER get this responsiveness from M$. Also, the vulnerability wasn't a root exploit, you couldn't trash a system with it, couldn't use it to gain root.

    --
    In Bushworld, they struggle to keep church and state separate in Iraq as they increasingly merge the two in America.
  35. Re:Is this government's role? by praedor · · Score: 2

    Huh? The MILITARY has national security interests in this. Of COURSE they have say. They are NOT threatening to attack Redmond with B-52s if security issues aren't better dealt with, they are implying that M$ may lose a major customer if they don't clean up their crap. That is absolutely valid and correct.


    Feel free to remove your aluminum foil hat and catch some sunshine.

    --
    In Bushworld, they struggle to keep church and state separate in Iraq as they increasingly merge the two in America.
  36. Re:Being a Communications/Computer officer in the by ftobin · · Score: 3, Insightful

    Trying to lay the catch-up game with Microsoft products is not a positive thing to do; the positive thing to do would be to get non-Microsoft solutions so that these problems don't occur. Positive solutions fix the problem, not patch the symptoms. Incessant, needless patching and worrying is what builds up the negative energy.

  37. Re:Dept of Interior's Network - An Interesting Sto by AJWM · · Score: 2

    and is secure, running WinXP

    Does this strike anyone else as oxymoronic? (Firewall or not.)

    --
    -- Alastair
  38. Re:Being a Communications/Computer officer in the by joib · · Score: 2


    As a young Lt., I spent 6 months replaceing perfectly functional Solaris boxes that performed our web, smtp, DNS, SQL, and other basic network services with NT 4.0 boxes. A week after we recovered from Service Pack 2 - i strongly recommended that we slow our migration - and that it was costing us more time and money supporting Windows machines than the UNIX boxes which never needed any work or upkeep. Some had uptimes of 4 years until I pulled the plugs on them. (don't beat me - i was the lowest ranking puke in the house - and i did what i was told)

    Man.. that work must have sucked majorly... Sounds like the typical case of the suits believing glossy MS brochures instead of their own techs and other people with actual experience. Or in this case, s/suits/guys-with-more-funny-looking-shiny-metal-t hingies-on-their-collars-than-you/g :)

  39. Your Proposed Cure is Worse Than the Disease by FreeUser · · Score: 2

    So basically it is the user's fault they used the software simply because software is free speech? That is a silly argument.

    Not really. He's saying that the consumer has a responsibility to make an informed purchase, and that creating liability and a pork barrel for lawyers is not a good solution. He's right.

    All of the information to warn a would-be purchaser that Microsoft Exchange Server is probably the worst possible choice one could make for a mail server if security is any concern whatsoever was widely and publicly available. Clearly the person or persons who made the decision to go with Microsoft, when demonstrably more secure (by orders of magnitude) options were available at little or no cost, either grossly neglected their duty and did no research, or were in a sweatheart agreement of some kind with Microsoft's salespeople, or Microsoft itself. That, or they opted for the product when it was still in the vaporware stage, which is even doubly incompetent.

    Either way, the person or persons who made this incompetent, and very possibly corrupt, decision should indeed be the ones to pay for it ... with their careers.

    --
    The Future of Human Evolution: Autonomy
  40. Re:My Humble Opinion by Stonehand · · Score: 2

    From a cracker's POV, I doubt they care that much about *all* web sites. If I were on that side of the fence, I'd be focusing on the ones with juicy credit card databases and so forth -- in other words, the big e-commerce sites, like online vendors, transaction processors and so forth. How many of those run Apache? 60%? More? Less?

    --
    Only the dead have seen the end of war.
  41. Re:Being a Communications/Computer officer in the by Elbereth · · Score: 2

    You've definitely got a point, but how many times do you have to learn a lesson before you figure out that Microsoft's security really sucks?

    Let's say that you get hit with ILOVEYOU and start to filter out attachments. Good job.

    Now you get hit with Code Red. You decide to check daily for security fixes at Windows Update. Good job there, too.

    Next, you get hit with a nasty virus because one of your employees couldn't live without his favorite screensaver. You install up-to-date virus definitions on all your PCs and check daily for new virus definitions. Also, you lock down all your PCs, so that nobody can install/remove programs without MIS approval. The employees grumble and complain, but it's obviously necessary.

    And after that, a disgruntled employee (perhaps the same one that caused the virus outbreak) decides to sabotage a few of the servers after he gets fired. You disable all remote manageability and literally lock the servers away in a secure room. MIS begins to grumble and complain now, too, but it's necessary...

    At what point do you finally switch over to something different? When no work can be done, because you're trying to patch the millions of holes Microsoft themself refuses to patch?

    UNIX has a whole slew of problems, too, but at least it isn't designed to be insecure.

  42. 7000 programmers by Rice-Pudding · · Score: 2, Funny

    Gates directed 7,000 programmers to spend February scouring the Windows operating system for openings hackers might exploit to steal data or shut down systems.

    Wow, 7000 programmers! I bet they figure out how to close the barn door.

  43. Re:Dept of Interior's Network - An Interesting Sto by Amazing+Quantum+Man · · Score: 5, Interesting

    Dude, remember that the DoD has a rather different idea of "Secure" than the average website (.com OR .gov).

    When they say "secure", they're talking Orange Book. They're talking about lives in the balance. "Secure" means, "If you fucked up, somebody died."

    --
    Fascism starts when the efficiency of the government becomes more important than the rights of the people.
  44. Re:Being a Communications/Computer officer in the by Bios_Hakr · · Score: 3, Insightful

    The military do genuinely have a number of requirements that are not shared by the general public, such as the ability to continue functioning after the loss of 80% or more of the infrastructure in a particular locality.

    I hope you were saying that as a joke. I am a systems maintainer in the USAF. Every day, I get a call about one or more "vital" telecom lines that have dropped.

    The customers that I service are given a single, anemic line running through an overtasked proxy server connected to an abominal firewall mapped with infuriating rules. I am not talking about a single base either either. It seems that most bases are this way. The backbones are generally good, if you happen to work at a base with a NIPRNET/SIPRNET gateway router. If you work at a smaller base, you will understand the constant plague of IDNX system reroutes and satalites that "just dissappear" for hours.

    And how do the customers react when they cannot access afpubs.af.mil? Do they use an alternate system? Is their 80% redundancy there? No, it isn't.

    The customer gets screwed and no one cares. NO ONE! Why? Because the motto of DISA is "Hey, what choice do you have?" Meanwhile, me and my co-workers dry out "wet cable", querry call paths, and wait for FedEx to bring in replacement line drivers.

    Sorry for the rant, I'm just wondering where the 80% redundancy is. I have been in for a while, and I have never seen it.

    --
    I'd rather you do it wrong, than for me to have to do it at all.
  45. Re:Being a Communications/Computer officer in the by Zeinfeld · · Score: 2
    They could very well have used a non-proprietary core, as the original poster suggested.

    Exchange is a 'non-proprietary core' (at least in the DMS usage). Exchange 5.5 is an X.400 MTA. The is nothing proprietary about X.400, it is just that Microsoft is the only vendor that still sells that junk.

    Exchange 2000 removes the X.400 junk from the core. It is not an OSI MTA that also does Internet, it is an Internet MTA that also does OSI. Don't judge Exchange by the horrors of 5.5, those horrors are mostly intrinsic to the OSI junk it is based on (plus the MAPI horrors).

    The problem with DMS is not that they chose prorpietary software, they simply chose the wrong open standard. Even today we have DMS folk comming to the IETF with drafts proposing some form of X.400 interop for S/MIME.

    What it comes down to is that the military defined a mail system that was so complex that Microsoft was the only company arround with the resources to provide client support.

    I think in hindsight, that would have been a very sensible decision, don't you?

    It isn't a matter of hindsight, there are plenty of reasons why DMS and the Federal govt. PKI are problematic. Most of those were known at the start.

    --
    Looking for an Information Security student project suggestion?
    Try http://dotcrimeManifesto.com/
  46. Thousands of Holes In There Too! by EXTomar · · Score: 2

    Do you know how long it will take to fill in each of the holes in those punch cards?

  47. Re:My Humble Opinion by sphealey · · Score: 3, Informative
    Yes, I do remember when my Commodore 64 worked to specification, I also distincly remember it not doing too much of anything compared to the computer systems of today.
    Um, I was thinking more like a DECSystem-10 (3 years uptime with a typical load of 50 simultaneous users), HP 3000 (50 users, at age 10 we dropped the maintenance contract and it ran for 5 more years with no outages or unscheduled downtime), VAX 780, IBM System/1 => AS/400 (2 years uptime on that one after our sysadmin resigned), that sort of thing.
    Have you ever had Novell run stable for any length of time?
    1250 user 3.11 network, 3 years with no significant unscheduled outages and no excessive maintenance time; 12500 user 4.x network, 4 years with no unscheduled outages. Some others as well.
    Have you ever had Netware lock up for no reason whatsoever?
    Yes, of course. I have had my car quit on me unexpectedly too. Once every 5 years or so. Not every 48 hours as with MS-LANMan 1.1.
    How long have you been involved in IT, long enough to become sour and bitter against anything new?
    Sorry dude: "new" != "better".

    sPh

  48. Why did this happen? by epepke · · Score: 2

    As an officer in the Air Force, perhaps you have some insight.

    Back in the 1980's, I was at the Supercomputer Computations Research Institute, a DOE-funded site. Although ours was the designated unclassified site, we dealt with a lot of groups (Oak Ridge, Lawrence Livermore, etc.) who weren't exactly unconcerned with security. The operating systems they used in house very very tight and had to pass fairly stringent security requirements just to be considered. This was one of the reasons that VMS was so popular; DEC had worked very hard on the security.

    If you had asked me then whether this would have happened, I would have laughed.

    I can see why the business and consumer cultures played the lemming. But the military has a reputation for getting thing that work, even if they cost, and dammit, Mil Spec used to mean something.

    So, what happened?

    1. Re:Why did this happen? by frank_adrian314159 · · Score: 2
      So, what happened?

      COTS initiatives.

      Congress, over the last 25 years has gotten tired of paying for specialized military development unless absolutely necessary. You can't go down to your local Office Depot and get a B-2 bomber, but you can get a copy of MS Exchange. If the military DID develop a specialized E-Mail solution, it WOULD have been much more expensive. Unfortunately, they didn't seem to look at the commercial (and free) alternatives very well...

      --
      That is all.
    2. Re:Why did this happen? by dillon_rinker · · Score: 2

      So, what happened?
      The end of the cold war. Budget cuts.

      The end of the Cold War coincided nicely with the entry of MS into the server market. As the budget cuts of the early 90s began, MS began marketing their server solutions to the military.

      Another poster mentions COTS (Commercial Off The Shelf) initiatives as a cause for the MS ascendancy in the military. Granted, but it's only a proximate cause. The COTS initiative was a cost-cutting move.

      Remember: Good, fast, cheap: pick any two. You can't have all three.

  49. Re:I Love (Bug) the Air Force! by Amazing+Quantum+Man · · Score: 2

    Hence the Army's move 2 years ago [appleturns.com] to a more secure system. Who's the jarhead now?

    Uh, the Marines? No offense intended to any leathernecks out there. But when I dealt with the Army and the USMC, the Marines were the jarheads.

    --
    Fascism starts when the efficiency of the government becomes more important than the rights of the people.
  50. that's a good one by BlueboyX · · Score: 2

    "We now hold MS responsable for all mishaps that occur due to problems in their operating system. Every time something bad happens to a soldier on the field, the same thing will happen to a MS executive. Gates is going to love taking the punisment of the guy who just got captured and tortured..."

    I wonder if that would speed up their security fixes.

    --
    "Never, never suspect the dreams within the dreams of dreaming children." ~The Amazon Quartet
  51. consumer choice by EricEldred · · Score: 3, Insightful

    "The military and the government don't really have too much choice at this point except to start to put pressure on Microsoft and others to improve software security," Erbschloe says.

    No, the consumer (the government here) can buy software that is certifiably secure and not pay for any that does not meet security requirements.

    The Air Force can buy Sun hardware and software, for example, instead of Microsoft. It can set requirements in contracts that are not slanted toward Microsoft but which demand software that the consumer can fix rather than waiting for a new version.

    Yes, if the government won't do this then it has to live with the consequences of caving in to the antitrust suit and plead with Microsoft to be nice to them.

  52. Re:Being a Communications/Computer officer in the by mckwant · · Score: 2

    PRECISELY. I was struck by that phrase that went..

    "UNIX boxes that don't need upgrading or maintenance..."

    Frankly, I'm fighting this same battle at my company. We've got a multiplatform network, and while the UNIX boxes require LESS maintenance, they'll still go to hell in a handbasket if someone doesn't feed/care for them every so often.

    Admittedly, the down side of UNIX isn't as brutal as that of NT (the server stays up), but people seem to miss the fact that the no maintenance *nix box is just as absurd a notion as the no maintenance NT box.

    The competition here isn't NT/*nix, but securing boxes, and the skript kiddiez using the cracks probably don't care WHAT they're breaking into, just THAT they're breaking into something.

    --
    ceci n'est pas un sig.
  53. Its a catch 22 by Srin+Tuar · · Score: 2


    If you are smart enough to setup email filers, etc, then you are smart enough not to use microsoft server products.


    After all MS does billet its warez as "easy to use", so it puts people in the mindset that they shouldnt have to do anything intelligent.


    (I worked at defense contractor where the Air Force's security demands amounted to: "all traffic must go through port 80, because that makes it secure")...

  54. Timediff between exploit and patch by Jeppe+Salvesen · · Score: 2

    Really. Please take a look at the length of the interval between a black hat creates an exploit, and a working patch is available for your platform. How many days a year is your computer exposed?

    With the "we don't tell you 'till we got a patch" information policy, you can be exposed for months without knowing it. With the "we tell you, and then we release the patch" information policy, you can react according to your relevant security policy.

    Microsoft has a long history of the former. Linux is generally rather quick on releasing comments and patches, and I believe almost all the major Linux distributions have automated security patch services now. I know Mandrake, Debian and Red Hat do.

    Until recently, windows update was used for pushing new versions of software. They rarely released security fixes, and then usually clogged together. If you wanted to stay secure in windows-land, you needed to look around for the patches. They appear to be using windows update for pushing security now, but remember that one of the worms of fall 2001 infected a windows update server. Do you trust these guys? Really?

    Oh - btw - the fact that they let a mac/solaris guy administer NT boxes could be yet another sign of brassy incompetence. And judgement is always biased. That is what judgement is. If it is purely bases upon facts and clear rules, it is not "judgement" but a fact.

    --

    Stop the brainwash

    1. Re:Timediff between exploit and patch by WildBeast · · Score: 2

      "we don't tell you 'till we got a patch"

      But isn't that exactly what they did with wu-ftpd?

      "Do you trust these guys? Really?"

      I've been Virus free since 1995, so yeah I trust them.

  55. Re:Dept of Interior's Network - An Interesting Sto by gdyas · · Score: 2

    Um, that would be the point in having all those open sockets behind a firewall.

    --

    The only tool you've got against psychosis is experience.

  56. Re:Dept of Interior's Network - An Interesting Sto by gdyas · · Score: 2

    Yes, I'm aware of that. Just thought I'd throw out another problem in another part of the government to show that security issues tend to be systemic across the gov't.

    And with the DoI being in charge of federal agencies like the Natl Park Service, the Forest Service, Fish & Wildlands, federal payroll & accounting, farm issues, etc etc etc, it's silly to argue that the preservation of the integrity of our country's internal assets is more or less important than the military's responsibilities. Wildfires, hurricanes, crop failures - lives are in the balance in those situations too, no?

    --

    The only tool you've got against psychosis is experience.

  57. Re:My Humble Opinion by sphealey · · Score: 2
    MS-LANMan 1.1.
    Dude, if that's your most recent experience with Microsoft's networking..... wow, man, wow....
    First, I should clarify that I do try to be vendor agnostic when selecting vendors and technologies. Let the problem dictate the solution and all that. If I sound bitter about M$, it is simply due to the number of bad experiences I have had with that particular vendor.

    As to Lanman 1.1: I have been working with NT 4.0 and now Windows 2000 since 1996. I find NT usable if not the best technology in the world. However, I have seen very little in Microsoft Networking that has changed since 3Com 3+Open / Lanman 1.0/1.1. In fact, my Netware-centric coworkers were amazed when I just jumped in and started configuring NT 4 literally without having seen it before my first logon. "How did I know all that stuff?" they wondered.

    Active Directory is a bit of a different story, but not entirely if you have worked with NT domains, which are based on MS Networking, which is based on Lanman, which is based on PCLP...

    sPh

  58. Re:Being a Communications/Computer officer in the by gmcraff · · Score: 2, Informative

    And on another subject, I'm right in the middle of getting Linux approved for use within the DoD and, by extension, the Air Force.

    No, I kid you not. Linux is getting the COE suite ported to it, elements of DISA are gung-ho about bringing it in, and some elements of AF/SC are doing their best to help. The specifics of who is doing what in what time frame are not things that can be discussed here.

    And how is this justified? What military program is forging the way for this OS (which is getting so big, commercially speaking, that every high tech company EXCEPT Microsoft and most of the gaming industry has a strategy on how to get in on the action) to be brought into the fold? Who had to put their [appropriate genitals] on the line in a military manner to get this going forward?

    The weather men.

    I kid you not. And you know what the biggest stumbling block is, besides office-internal politics? AF Communications. Capt. gsfprez (I'm guessing here) is right: Comm sold the Air Force infrastructure to Microsoft, and most of the old clever Sergeants and Airmen and young LTs who knew their UNIX during the dot-com times said, "Good-bye, sir! Patriotism and service warms the heart, but six figures will warm a whole house, and provide the house, too." So now the Comm field is whining "We can't have Linux! We don't have anyone who can administer it! We structured our entire training cycle around Windows! We're lucky to have two Unix-savvy people left in the whole squadron, and they're the overworked Master Sergeants." (Conjecture: I'm not in Comm. But I do get email from them.)

    Yep, Linux is coming the the DoD. The smug excuse of "Linux isn't an AF-approved operating system" will soon be susceptable to the rebutal of "Wanna bet?" Soon it will be time for stalwart young LTs and Captains to make Powerpoint presentations to the Majors and Lt Cols of the Comm squadron explaining why they should move vital network services to a Linux box. They're probably going to get slapped down; bureaucratic intertia is like that. But LTs and Captains become Majors and Lt Cols, some day.

    Oh, and by the way, the weather system that runs on Linux works so well that profanity is usually used as a magnifying adjective to words like "incredible" and "outstanding". [Any active duty guys who wants some details, email is welcome.]

    #include std.disclaimer: None of these statements are made on behalf of the AF. All opinions are my own. My perceptions may not take into account facts that have not been available to me. I may be wrong about any number of things. If you're going to get flustered by something you read on Slashdot, you seriously need to re-examine your priorities.

  59. Re:Dept of Interior's Network - An Interesting Sto by ftobin · · Score: 2

    I dunno about the military, but Interior is apparently desperate for decent IT support.

    I don't know about the DoI, but if it's anything like applying for civilian IT positions in the military or the FBI, they're going to need a lot of luck in getting good IT people who aren't just Windows monkeys in there to make a buck.

    Before landing the commercial job I spent months trying to get into an FBI or civiliant military position, but the application process is incredibly depressing. Position opening descriptions are incredibly verbose, but contain absolutely no useful information. They all tend to just say things along the lines of "Will work with computer systems to support the required needs." Just take a look at the first Computer Specialist opening I found at the FBI jobs site. Armed Forces position openings the same. Furthermore, the application process itself tends to be burdensome and unclear, requiring lots of documentation up-front, often dead-tree-style; there is seemingly no process of escalating back-and-forth information exchange which the commercial world tends to prefer.

    They are definitely trying to improve the application process, but they definitely need to clear up the red tape.

    Personally I'd like to work for a social institution like the federal government, even though the pay scale is significantly lower. However, they really need to streamline their application process if they want good people.

  60. Re:Being a Communications/Computer officer in the by sheldon · · Score: 2

    "At what point do you finally switch over to something different? "

    At what point do you finally realize that switching to something different doesn't solve problems, it just creates new ones?

    The answer is still... education... Learn how to admin what you have now, and save yourself a whole lot of hassle!

    "UNIX has a whole slew of problems, too, but at least it isn't designed to be insecure."

    No moreso than Windows 2000. The point is that if you know what you are doing and set things up properly, you don't have issues.

    Our company was not hit by Code Red. We did have issues with Nimda, but only on development machines which were not well managed; production were fine. We have not had any issues with production systems as a result of windows vulnerabilities in 3 years because we have smart Admins.

    Christ I have the GIAC Windows Security administration cert and don't know half what my companies admins know. But I would still recommend to those bitching, especially that air force Lt. that he attend the SANS annual and take Track 5.

  61. Re:Being a Communications/Computer officer in the by sheldon · · Score: 2

    So I should dump Unix for SMTP and DNS because of the problems with BIND and sendmail?

    Yeah, that's intelligent.

    Learn how things work, why things work, and then implement the solutions.

    The vast majority of currently known IIS attacks(Code Red, Nimda, and so forth) could have been prevented proactively by implementing the steps in the IIS security checklists from Microsoft, SANS, and so forth. It's not that hard, and all I see in your response is a knee jerk reaction against Microsoft without proper understanding of the issues.

  62. Re:My Humble Opinion by ahde · · Score: 2

    You're right. Most of the script kiddies target Microsoft, since most of them, until a couple years ago, didn't know of any other platform. But the real clever hackers target unix and other complex systems. Why don't the smart guys spend their time on MS? Because you don't have to be smart to do it. Even if you were a super hacker, why would go to all the extra effort of being devious when all you really need to do is pick an input and type a bunch of aaaaaaaaaaaa's

  63. Re:Being a Communications/Computer officer in the by ftobin · · Score: 3, Interesting

    First of all, if you were a smart unix user, you would not be using Sendmail. You talk about 'understanding', but do not understand that you have a nice choice of alternatives that are much more proactively secure than Sendmail, such as Postfix or Qmail. Same goes for Bind (we have djbdns and such). What do you get from Microsoft? Their one product. Big choice there.

    I do so fully well how and why things work. That's why I say to choose free unixes. They are not blackboxes. You can easily poke in, and figure out what's wrong. You can fix the problems yourself, even more proactively than your proprietary provider. All this and more you cannot do with proprietary, closed products.

    Furthermore, you aren't being proactive by simply applying vendor-supplied patches when they say to; that's reactive. Being proactive means learning how your software security works, especially internally, and performing appropriate actions.

  64. Re:Being a Communications/Computer officer in the by sheldon · · Score: 2

    "First of all, if you were a smart unix user, you would not be using Sendmail. "

    Well DUH.

    "you aren't being proactive by simply applying vendor-supplied patches when they say to"

    Who said anything about vendor-supplied patches?

    "Being proactive means learning how your software security works, especially internally, and performing appropriate actions. "

    That's what I said.

    I'm sorry but your post helps reinforce my point that you don't know what you are talking about.

  65. Costs and balances... by Brendan+Byrd · · Score: 2

    How about the cost of information, if classified documents wind up into Al-Queda hands? This is the military we are talking about, and they are using Windows?! Hell, I'd be suprised that they would even consider Linux and go straight for BSD, just to make sure that it's secure.

    So, just now, the USAF wakes up and says "Hey, I think security is a pretty good idea." Huh? Since when has the military branch of the government not been keen on security? (And why does "military intelligence" sound like an oxymoron. I guess this is yet another indictation of how ass-backwards our govt is.)

  66. WAY OT - you're missing the point... by dillon_rinker · · Score: 2

    Contrary to the slashdot belief, government spending money is a *GOOD* thing. It stimulates the economy...
    The government can't spend money unless they take it from me. Thus, government spending = taxation.

    So to paraphrase you...
    "Taxation stimulates the economy."

    An economic model that implies that the taking and spending of my money stimulates the economy is fundamentally flawed because it asssumes that I won't spend that money myself.

    This is not to say that government spending is always bad; I merely want to point out that your reasoning is flawed. Government spending is GOOD when it allows a democratically selected government to concentrate monies in a needed sector - propping up an industry vital to national security, for example. The problem is when we don't have a democratically selected government...but I digress from my off-topicness.

  67. Re:Dept of Interior's Network - An Interesting Sto by dillon_rinker · · Score: 2

    Wildfires, hurricanes, crop failures - lives are in the balance in those situations too, no?
    The point of the military is not preservation of life. I went through basic training with a hillbilly who, when first issued an M-16, gazed at it and reverently stated "This is a gun that was made to kill...people." The military infrastructure is in place to prevent the overthrow of the US government (ie implementation of non-Constitutional rule). No hurricane, forest fire, or regional crop failure can cause this.

    This does not alter your point that preservation of human life is essential.

  68. Joe McCarthy found out when HE fucked with 'em. by crovira · · Score: 2

    The military doesn't take crap from anybody and they have all the guns.

    You start selling shoddy goods to your defendors and you may find out what the Romans found out about their Preatorian guards. And find it out in the same way too. St the point of a "glaive."

    --
    MSBPodcast.com The opinions expressed here are my own. If you don't like 'em... Think up your own stuff.