Microsoft Invites Black Hats into Vista
gtzpower writes "Microsoft is inviting hackers to 'Take Your Best Shot' at Vista. 'You need to touch it, feel it,' Andrew Cushman, Microsoft's director of security outreach, said during a talk at the Black Hat computer-security conference. 'We're here to show our work.'" From the article: "A security team with oversight of every Microsoft product — from its Xbox video game console to its Word program for creating documents — has broad authority to block shipments until they pass security tests. The company also hosts two internal conferences a year so some of the world's top security experts can share the latest research on computer attacks." Essentially a tie-in with an article we discussed yesterday.
To quote Bush to terrorists: "Bring it on!"
Result: We're getting our asses kicked.
To quote MS to Blackhats: "Bring it on!"
Result: Look at XP and they didn't invite anybody.
MS has enough problems with BHs already. To invite them? WTF? Lot's of people at MS are already saying they wont make it in time and that the code is bad to begin with. Do they not listen to their own people?
It's total nonsense - they're still using the BSD stack they stole years ago. Most of the networking implementation is historical, and the guys at Microsoft that actually knew how it worked left years ago. "Vista" has big clumps of legacy code that they're either scared to lose or incapable of replacing. There are *no* good programmers at Redmond any more: /we/ all left!
The current versions of "Vista" are full of security holes (some of which had be plugged in XP!) A "raw" install lasts less than 20 minutes when exposed to the 'net before it's utterly compromised.
In the 90's, Linux advocates used "stability" as their main argument against Windows. Microsoft took that argument away with XP (regardless of the idiotic BSOD comments tossed around these parts).
From 2001 to now, Linux advocates have used "security" as their main argument against Windows. Microsoft is in the process of taking that argument away.
Soon, Linux advocates will be left with "price" as their main argument (glossing over the fact that startup price is insignificant compared to total cost of ownership), which the public really doesn't care about (they'll just think that Linux is free because it's not worth paying for).
-- "I never gave these stories much credence." - HAL 9000
Then again, maybe you could just use the Microsoft logo (and the normal Windows logo for Windows topics), like a site with credibility would do. Just a thought.
-- "I never gave these stories much credence." - HAL 9000
chroot jails are a BSD thing, actually.
Actually, the BSD jail is far more than a chroot. Chroot has been available under Linux/Unixes for a long time.