CCIA Urges Dept. of Homeland Security to Avoid Microsoft
An anonymous reader writes "The Inquirer has posted an article reporting that the Computer and Communications Industry Association (CCIA) has urged the US Department of Homeland Security, in an open letter to Tom Ridge, secretary of the department, to avoid using Microsoft software because Microsoft's software is 'riddled with obvious and easily exploited vulnerabilities.'"
The Department of Homeland Security continues to use Microsoft products despite massive flaws, just like everyone else for whom familiarity is more important than actual security.
to use OpenBSD without a windowing environment, or any ethernet interfaces.... "most secure setup in the world" the report claimed. When the department asked about useability and productivity of these other avenues they were told "STFU n00blah and RTFM".....
If Ridge and DHS doesn't already know this, they've been asleep. I do work for the Defense Department, and we won't consider using Microsoft code for anything that's important.
Government spending is just another way to dump money into the local economy, while rewarding campaign contributions.
Man if it wasn't for timestamps, I'd swear we were in 15th century Britan. Hello Fifedom!
You think that I'm crazy, you should see this guy!
And what happens when the DHS begins to use Linux/Solaris/et al and the attackers focus their attention on these products and find numerous and obvious vulnerabilities?
People tend to forget that more holes are found in Microsoft products partly because more people use Microsoft products. As a result, that's where the attackers focus a great deal of their energy. Linux would have the same problem if it had Microsoft's market share.
What happens if SCO goes after the Department of Homeland security for using something like linux? Would it be considering terrorism?
I've left to find myself. If you happen to see me, please, keep me there until I return.
Microsoft supports terrorism!
The OMB (Office of Management and Budget?) just added MacOS X and Linux to approved OS's to use for government applications.
With the right push, we might see the tides change in *nix favor.
Seriously, if this guy really wanted to help out the government, he'd be suggesting that they keep their systems patched and stripped down and firewalled, and that they employ and expert security team no matter what OS they are.
The fact is, you can make windows as secure as any other OS out there, as long as you know what you're doing.
I think it's fishy that they don't back up their "obvious and easily exploited vulnerabilities" claim with any real examples. The only evidence they provide is Blaster and SoBig -- an exploit for a vulnerability patched a month in advance, and a simple dumb-user email worm. Unfortunately all anyone sees is the fact that two worms came out near the same time -- and not the fact that they could have been prevented easily by more competent sysadmins and informed users.
Anyway, I think it would be cool to see the DHS use a less-mainstream OS. But I don't think this open letter makes an argument any more sophisticated than the "microsoft sucks! You'll get a million viruses dude!" spouted off by any 13-year-old linux zealot.
The following sentence is true. The preceding sentence was false.
ANY software can be compromised to ANY degree. There are just as many exploits lurking in an Open Source distribution (let's face it, it's rare that someone uses ONLY the Operating System), as there are in anything.
Implementing (and adhering to) strong policy, working diligintly to keep systems updated, and keeping users informed. These are essential parts to creating (and maintaining) a "secure" infrastructure.
Granted, it's easier said than done; but it's possible. There are FAR MORE corporations/entities that DID NOT get affected by blaster/sobig/melissa/codered/etc. than there are corps/entities that did.
It would be totally inappropriate for a goverment agency to blacklist a specific vendor without going through extensive hearings. That does not mean that they should not consider the vendor's history when evaluating each purchase. For the anti-MS crowd that means that they should reject each MS product individually.
More seriously, they need to evaluate what their software requirements are. I strongly suspect that they need software which will:
Come on, people, take a look at the membership of this organization and ask yourself if they would EVER take a position which was NOT anti-microsoft. This is not some middle-of-the-road computer science organization, it's a lobbying organization with an axe to grind. That MS software has security flaws is a given, and their position in this case may well be correct, but the CCIA's opposition to MS software is NOT news.
A quick look at About CCIA lists the following:
Our member companies range from Sun Microsystems, Fujitsu, Nokia, Nortel Networks, Tantivy, Time Domain, and Vion to AT&T, Verizon, NTT USA, Oracle, Intuit, Yahoo!, Sabre, and AOL
Its the who's who of MS competition.
The fact is, you can make windows as secure as any other OS out there, as long as you know what you're doing.
Can you?
Can an NT administrator, using user level tools, perform the equivalent of a chroot jail? Can he make specific apps suid or sgid?
While Windows technically does not imply use of other Microsoft products, it does tend to be correlated with it. Outlook has had numerous poor security decisions that a mail admin simply cannot fix. IIS has also had poor architectural decisions. Remember MS swearing that they'd rewrite the thing from the ground up for the next release? The design of IE -- permeating the entire OS, providing many services to applications, and with no internal security model in place, makes for all kinds of nasty problems. It's a great way for spyware to slip pass personal firewalls, it's used in places like Outlook where a full-blown HTML renderer with the huge variety of features it has is a pretty bad idea from a security standpoint, and it provides a high degree of control to remote websites over the local computer -- much higher, than Mozilla.
The MS Blaster issue wasn't actually all that egregious, AFAIK. It's not like UNIX systems haven't had RPC flaws in the past, either. The real problem was the number of unmaintained machines that were vulnerable. I'd call something like Melissa, that relies on phenomenally stupid security decisions from Microsoft ("let's have an automatic execution environments in our documents, which are intended for wide interchange!") much worse.
May we never see th
2002
Microsoft Yearly Earings $6.16 billion.
Microsoft Cash Reserves $46 billion
Microsoft Market Share 92% of the Desktop
Watching Ed Black poke Microsoft with the sword of it's own making - Priceless
I think their model works better than Red Hat's, where I get 3-5 emails a day notifying me of critical software fixes
If you took a few minutes to read those fixes you would realize almost all of them are "proactive", that is, they are fixing vulnerabilities, before an exploit is made against them. This is intrinsic in the OSS model, where experts worldwide examine the source code all the time, for instance in university classes and research centers. Commercial, closed-source software, on the other hand, usually is examined only by crackers who throw anything they can at the software until it breaks.
Personally, the system I prefer is Conectiva's, where apt-get is combined with rpm packages. Running "apt-get update; apt-get dist-upgrade" each time I get a vulnerability warning takes much less time than deleting spam, even in my relatively well protected email account.
If I had gone and said the north american power grid should be replaced at the wake of the outages [ . . . ], I would have been accused of countless acts of civil disobediance.
My first question is what is wrong with Slashdot? I mean someone saw fit to give the parent coward "Insightful" for what she or he wrote? Someone wind the clock back before 2000 when Slashdot wasn't frequented by Microsoft apologists.
I'm not sure what makes you think your exercising your 1st Amendment right to speak freely (assuming you're a US citizen) would be branded civil disobedince, but in case you're really worried (and not just ranting) know you're in good comapny: first, the outage of August 2003 has produced a US-Canadain task force to investigate problems with the aging power grid. In fact, the power grid is so important that it is the subject of dozens of assessments conducted by North American Electric Reliabilty Council. Let's just say that NERC is not sanguine about the reliability of the North-American power grid. The problem is so widespread that even US lawmakers anticipate a massive political dispute.
Regarding your comparison of the power grid to the Internet, network events such as MSBlaster and Sobig.F highlight the fragility of an information network built of insecure nodes. At present, the overwelming majority of the nodes of the Internet are powered by Microsoft software. For better or for worse, "press releases and open letters right at the wake [sic] of major worms" draw attention to the real effects of maintaining so insecure an information network. MSBlaster and Sobig.F are not theories but facts and so prove the unreliability of an Internet composed mainly of Microsoft-powered nodes. The timely discussion of network events such as MSBlaster, Mimda, Code Red, Sobig.X, etc. in the press should, in my opinion, be an obligation of network adminstrators.
Given your post, you'd probably have us ignore the problem in the hopes that the next worm/virus/trojan does not damage our shared information network even more spectacularly. Thanks, but I would rather disseminate information and share data about such network events rather than stop my eyes, ears, and mouth with sand.
blog
Let's see, spend lots of $$$ to deal with patching MS security holes (lots of centralized and automated Software Install packages out there for Win32), or deal with user-unfriendly Linux suites that do not scale or integrate with others no matter how well patchable the platform is. Personally, I never trust third-party RPMs and they're never compiled the way I want them anyway.
I believe in MS on the front-end, linux on the back-end, running a virus gateway at the mailservers, antivirus software at the desktop, and centralized patching to fire off new patches on all desktops at once. That said, I would only put MS on the back-end at gunpoint. Linux may not need any of that protection at the desktop, but the lack of apps keeps it from being as usable; the apps that are available are not very compatible with what everyone else is using. In these days of limited sysadmin resources, I would rather the users have a very intuitive package in front of them to minimize calls like "how do I start using this? I have to source what and do what to my environment?" The sysadmin resources should be left to take care of the valuable back end.
Linux is far from 100% secure...take a look at various security bulletins each week and you'll see all sorts of apps that are being patched. Have we forgotten past Linux worms? How many recently patched phpBB2 or Nuke for recent problems according to those advisories? Where is the mantra of "the hole shouldn't be there in the first place?" that is constantly fire off at MS when those holes are found in open source software? Is it because many Linux apps are like that and the blame is distributed across a multitude of developers rather than a single monolithic software company that simple minds can more easily divert their attention to? Sorry, but "they patched it within 8 hours" is not an excuse. For both platforms, "the hole should not have been there! where is the code auditing that should have prevented that problem from being there in the first place?" As complex as software is becoming, I do not think that this is going to go away without radically altering current coding practices.
What we need is a very large corporation to adopt 100% Linux (reference Guinea Pig in wikipedia) so that apps become more compatible and patches are more easily recognized. We've seen smaller companies like Ernie Ball do this, but we need bigger testbeds. Then, we can complain in 10 years about the Linux juggernaut and how Putrix is better.
"Beware of he who would deny you access to information, for in his heart, he dreams himself your master."