Slashdot Mirror


Gates Says Windows Reliability Is Greater

mogrinz writes "According to an interview with the New York Times, Bill Gates is proud of the achievements Microsoft has made in increasing the security of Windows. As for the effects on people being attacked by SoBig.F, etc? Gates says this is "something we feel very bad about". Gates summarizes the Microsoft position very succinctly: "We're doing our very best, and that's all we can do"."

6 of 568 comments (clear)

  1. Re:No? by tomstdenis · · Score: 5, Insightful

    Why? His company released a patch to fix it a few months before the attack started.

    Would Linus feel particularly hurt if a worm went around that attacked kernel v0.94 ???

    Tom

    --
    Someday, I'll have a real sig.
  2. Re:Just Great by digitalunity · · Score: 5, Insightful

    Now that's just mean.

    If by reliability, you mean it's ability to function in a proper way without self-destruction, I'd say he is succeeding. Windows XP is indeed better than the previous offerings. Once upon a time, you didn't even have to touch your computer and it would spontaneously have problems. It has gotten much better. Now, it's resilience against the evils of the internet...

    That's another story. Indeed, Gates should institue a moratorium on new projects until the old ones can become stable enough to actually properly handle the internet.

    Sobig.F is a good example of how fundamental the problems with Microsoft software is. The changes required to secure (pick one: Windows,IE,Outlook,Exchange,IIS) need to happen at the API layer. Unfortunately, this would take industry-wide support, something not even Microsoft can make happen overnight. It would seem with all the money companies already have invested, there is a lot of corporate inertia to overcome.

    --
    You can't legislate goodness. Let each to his own destiny, by will of his freely made choices.
  3. Re:No? by militantbob · · Score: 5, Insightful

    Agreed. Microsoft took the appropriate actions. They recognized the problem, and released a fix far before any damage was done. They even made AutoUpdate enabled by default, to cover the rear ends of lazy/unknowing/careless users. I think Microsoft is making steps forward - small but important steps, such as ahead-of-time patches, offering a foundation for cooperation with 3rd party IM client producers, and admitting to and showing indications of intention of addressing security and stability problems.

    Microsoft has a long way to go. There's no doubt about that. But *some* of the recent news concerning Microsoft has surprised and pleased me.

    If users would leave AutoUpdate on, or take the time to check for patches once every week or two themselves.. and MS doesn't bloat 2004 and instead focuses on security/stability... I think things will be just fine.

    --
    "The Tree of Liberty must be refreshed from time to time with the blood of Patriots and Tyrants." --Thomas Jefferson
  4. Gates and the Chewbaca defense by UnknowingFool · · Score: 5, Insightful
    It's interesting how Gates tries to deflect the questions:

    Q. The buffer overrun flaw that made the Blaster worm possible was specifically targeted in your code reviews last year. Do you understand why the flaw that led to Blaster escaped your detection?

    A. Understand there have actually been fixes for all of these things before the attack took place. The challenge is that we've got to get the fixes to be automatically applied without our customers having to make a special effort.

    The interviewer asks how Blaster occurred despite Trustworthy Computing. Gates responds again and again that if everyone patched their systems, Blaster would not have been an issue. In essence, he is correct but he doesn't really answer the question. But this isn't a complete solution as not all users can automatically patch their systems.

    Before everyone starts chiming in on how real system admins would have been prepared. Remember a few things:
    1) After being burned by a few bad patches, some corporations now have a policy that specifically states that patches must be tested first. With the huge amount of patches that is released by MS, this is a full time job.
    2) Remote users (laptop users, VPN users, etc.) are like sailors coming back from overseas. Who knows what they were exposed to and what viruses they have. This is outside the control of most admins.
    3) Microsoft itself was not prepared for Slammer. SQL servers that were being used in a development environment (read outside of normal sys admin networks) were not patched. With large organizations, sometimes there are unknown, rogue installations.

    --
    Well, there's spam egg sausage and spam, that's not got much spam in it.
  5. Re:No? by gl4ss · · Score: 5, Insightful

    actually linus might take it pretty personally if there was a hole found in linux that affects every linux kernel from 0.94 to 2.6test4.. even if he did then release a patch for it a bit later.

    (as equivalent as the holes that have found to be in all nt based ms os's)

    -

    --
    world was created 5 seconds before this post as it is.
  6. Re:No? by militantbob · · Score: 5, Insightful

    Turning off AutoUpdate is a scary thing, in the case of the casual user. This is one area where I wish there was *more* harrassment and hassle required before disabling could be accomplished. A big bold warning box as soon as that checkbox is clicked, and another when the changes are saved. Many of my non-technical friends have heard about the 'insecurity' or 'privacy concerns' that are 'inherent' in auto-installs such as AutoUpdate and virus definition updates... and so they figure out how to turn it off, not knowing that THAT is the most dangerous thing they could do.

    The harm caused by a worm to the user who disables AutoUpdate is his own responsibility. But the warnings should be more clear and in more places, when one considers what you pointed: that the user's choice may very well prove harmful to countless others. It is his machine, it is his choice. But he should be compelled by the software itself to make that choice in a more educated fashion.

    --
    "The Tree of Liberty must be refreshed from time to time with the blood of Patriots and Tyrants." --Thomas Jefferson