Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Article: Gates memo calls for security focus

1 view
Skip to first unread message

JWMeritt

unread,
Jan 17, 2002, 10:41:34 AM1/17/02
to
"Jan. 16 — Microsoft Corp. chief software architect
Bill Gates sent a company-wide memo earlier this
week calling on developers to do a better job of
writing safe, secure software. The memo comes
just weeks after an embarrassing flaw was found
in the company’s flagship product, Windows XP.
According to one security expert familiar with the
memo, “It’s an acknowledgement from Bill that
‘We’d better do this, or else.’”"

Full article at http://www.msnbc.com/news/689243.asp

I feel so much better now.......not!

Naturally, THIS got immediate media dissemination. Their "oops" they hide as
long as they can...
James W. Meritt, CISSP, CISA

Simon Chang

unread,
Jan 18, 2002, 12:03:22 AM1/18/02
to
It remains to be seen whether Gates & Co. continues to treat inadequate
security policy and implementation as just "public relations issues". We
have heard so much about how much they talk the talk but not walk the walk,
that it is becoming harder to trust much of anything that comes out of
Redmond. Now, what would be interesting is if Microsoft follows Apple's
initiative and drastically revamp their code base (Apple now has Darwin,
which is based on FreeBSD). After all, if they are bold enough to steal
revolutionary GUIs from other companies, they should also be free to take a
honest, hard look at the way they churn out code and perhaps learn from the
open source community. That is, of course, if their greed and pride don't
get in the way.

Simon Chang

"JWMeritt" <jwme...@aol.com> wrote in message
news:20020117104134...@mb-fc.aol.com...
> "Jan. 16 - Microsoft Corp. chief software architect

Jerry Leslie

unread,
Jan 18, 2002, 3:15:21 AM1/18/02
to
Simon Chang (sch...@quantumslipstream.net) wrote:
: It remains to be seen whether Gates & Co. continues to treat inadequate

: security policy and implementation as just "public relations issues". We
: have heard so much about how much they talk the talk but not walk the walk,
: that it is becoming harder to trust much of anything that comes out of
: Redmond. Now, what would be interesting is if Microsoft follows Apple's
: initiative and drastically revamp their code base (Apple now has Darwin,
: which is based on FreeBSD). After all, if they are bold enough to steal
: revolutionary GUIs from other companies, they should also be free to take
: a honest, hard look at the way they churn out code and perhaps learn from
: the open source community. That is, of course, if their greed and pride
: don't get in the way.

Microsoft would have to abandon the policies espoused by this former
Microsoft Program Manager, who felt that rewriting code was a deadly sin
and that bloated code was good...

http://www.softwaremarketsolution.com/
"An Interview with Joel Spolsky of JoelonSoftware

Part I of II

Overview

We recently sat down with someone we regard as one of the industry's
most fascinating personalities, Joel Spolsky, president and one of the
founders of Fog Creek Software (www.fogcreek.com), located in New York
City. Joel worked at Microsoft from 1991 to 1994 and has over ten
years of experience managing the software development process. As a
Program Manager on the Microsoft Excel team, Joel designed Excel Basic
and drove Microsoft's Visual Basic for Applications strategy. (Joel
takes particular pride in the fact that on the day Bill Gates asked if
date math functions were compatible across the company's different
procedure and function libraries, he, Joel Spolsky, was able to
reassure the great man himself that with the exception of January and
February 1900, all Microsoft application libraries counted dates the
same way.)

[snip]

SMS: Joel, what, in your opinion, is the single greatest development
sin a software company can commit?

Joel: Deciding to completely rewrite your product from scratch, on the
theory that all your code is messy and bug prone and is bloated and
needs to be completely rethought and rebuild from ground zero."

[snip]

SMS: Yes, but isn't such code tight and small? Don't products built
this way avoid the dreaded "bloatware" label?

Joel: Don't get me started! If you're a software company, there are
lots of great business reasons to love bloatware. For one, if
programmers don't have to worry about how large their code is, they
can ship it sooner. And that means you get more features, and features
make users' lives better (if they use them) and don't usually hurt (if
they don't). As a user, if your software vendor stops, before
shipping, and spends two months squeezing the code down to make it 50%
smaller, the net benefit to you is going to be imperceptible, but you
went for two months without new features that you needed, and THAT
hurt..."


--Jerry Leslie (my opinions are strictly my own)

Alun Jones

unread,
Jan 18, 2002, 10:16:08 AM1/18/02
to
In article <a28lip$her$4...@joe.rice.edu>, les...@clio.rice.edu (Jerry Leslie)
wrote:

>Microsoft would have to abandon the policies espoused by this former
>Microsoft Program Manager, who felt that rewriting code was a deadly sin
>and that bloated code was good...

Oh, it's _very_ easy to abandon policies espoused by a _former_ employee :-)

While you're at it, you can even replace his picture in the official
histories.

Alun.
~~~~

[Note that answers to questions in newsgroups are not generally
invitations to contact me personally for help in the future.]
--
Texas Imperial Software | Try WFTPD, the Windows FTP Server. Find us at
1602 Harvest Moon Place | http://www.wftpd.com or email al...@texis.com
Cedar Park TX 78613-1419 | VISA/MC accepted. NT-based sites, be sure to
Fax/Voice +1(512)258-9858 | read details of WFTPD Pro for NT.

Alun Jones

unread,
Jan 18, 2002, 10:16:08 AM1/18/02
to
In article <u0O18.81315$Sj1.32...@typhoon.ne.mediaone.net>, "Simon Chang"
<sch...@quantumslipstream.net> wrote:
>It remains to be seen whether Gates & Co. continues to treat inadequate
>security policy and implementation as just "public relations issues".

In Microsoft's favour, look what happened when Gates wrote a memo suggesting
that the company should get with the Internet. Complete U-turn on the part of
the whole company, with a huge emphasis on Internet development. What Gates
says, goes. Just maybe those doomsayers within Microsoft who have been saying
"yes, but what about the security angle?" (I presume there are some) will now
be listened to, and their recommendations acted on. I certainly hope so.

Jerry Leslie

unread,
Jan 18, 2002, 11:22:04 AM1/18/02
to
Alun Jones (al...@texis.com) wrote:
: Oh, it's _very_ easy to abandon policies espoused by a _former_ employee :-)

:
: While you're at it, you can even replace his picture in the official
: histories.
:
Sort of like Stalin did in Russia. :-)

The General Electric site's corporate history section has NO mention
of their days as a mainframe computer manufacturer, when they made
the GE 635, sort of a clone of the IBM 7094, and the GE 645, the Multics
machine.

Juha Laiho

unread,
Jan 18, 2002, 4:51:40 PM1/18/02
to
al...@texis.com (Alun Jones) said:
>In article <u0O18.81315$Sj1.32...@typhoon.ne.mediaone.net>, "Simon Chang"
><sch...@quantumslipstream.net> wrote:
>>It remains to be seen whether Gates & Co. continues to treat inadequate
>>security policy and implementation as just "public relations issues".
>
>In Microsoft's favour, look what happened when Gates wrote a memo
>suggesting that the company should get with the Internet. Complete
>U-turn on the part of the whole company, with a huge emphasis on
>Internet development. What Gates says, goes.

Yep, whatever we think of Microsoft, we have to remember that they have
an army of programmers and other software people. Within that army,
they're pretty much bound to have some excellent ones, too. If the
incentives of this army are bound to produce safer code, that's what
they will do. They certainly have enough resources to meet pretty
much any single given goal. Conflicting goals are a different issue..

And as another thing, even as just a marketing move, I cannot but
congratulate MS on the statement: (computing) security consciousness
in the general public has been in rise for perhaps the last two years,
and the rise has begun to steepen lately. It's an excellent moment for
MS to step up and announce a security initiative.
--
Wolf a.k.a. Juha Laiho Espoo, Finland
(GC 3.0) GIT d- s+: a C++ ULSH++++$ P++@ L+++ E- W+$@ N++ !K w !O !M V
PS(+) PE Y+ PGP(+) t- 5 !X R !tv b+ !DI D G e+ h---- r+++ y++++
"...cancel my subscription to the resurrection!" (Jim Morrison)

Wolfgang Schelongowski

unread,
Jan 19, 2002, 1:19:36 PM1/19/02
to
In <Y_W18.3703$qk1.114...@newssvr11.news.prodigy.com>
al...@texis.com (Alun Jones) writes:

>In Microsoft's favour, look what happened when Gates wrote a memo suggesting
>that the company should get with the Internet. Complete U-turn on the part of
>the whole company, with a huge emphasis on Internet development. What Gates
>says, goes. Just maybe those doomsayers within Microsoft who have been saying
>"yes, but what about the security angle?" (I presume there are some) will now
>be listened to, and their recommendations acted on. I certainly hope so.

Two problems:
1) Security is not an add-on like Internet. They'll have to junk
Win95/98/... and completely rewrite the WinNT/... . The same goes
for most utilities running with privileges.
2) What Gates said implies a U-turn in the _roots_ of the company's
philosophy.
Cf. http://news.com.com/2010-1078-818611.html
--
"Some people are heroes. And some people jot down notes."
-- Terry Pratchett, The Truth

David Mohring

unread,
Jan 19, 2002, 8:16:34 PM1/19/02
to
On Fri, 18 Jan 2002 15:16:08 GMT, Alun Jones <al...@texis.com> wrote:
>In article <u0O18.81315$Sj1.32...@typhoon.ne.mediaone.net>, "Simon Chang"
><sch...@quantumslipstream.net> wrote:
>>It remains to be seen whether Gates & Co. continues to treat inadequate
>>security policy and implementation as just "public relations issues".
>
>In Microsoft's favour, look what happened when Gates wrote a memo suggesting
>that the company should get with the Internet. Complete U-turn on the part of
>the whole company, with a huge emphasis on Internet development. What Gates
>says, goes. Just maybe those doomsayers within Microsoft who have been saying
>"yes, but what about the security angle?" (I presume there are some) will now
>be listened to, and their recommendations acted on. I certainly hope so.
>

I fully admit, it is a Great Leap Forward, just like another one in history...

http://www.asiaweek.com/asiaweek/magazine/99/0924/cn_economy.html
+Mao launched the Great Leap Forward program in 1958, arguably the greatest
+economic folly of the 20th century. To help China surpass the economies of
+Britain and the U.S. in 15 years, he decreed that every Chinese should
+produce smelt iron. Hundreds of millions of citizens neglected farms to make
+low-grade pig iron. Beijing did not know that grain was rotting in the fields

Why the above quote? Check out the language Mr Gates uses in his letter
( see the register
http://www.theregister.co.uk/content/4/23715.html
). Remind you of the announcements of the old "five year plans" from
the old Soviet and Maoist regimes? Even down to the use of catch phrases!

If Microsoft's Management is serous ( and given their past pronouncements
on the security of their products - thats a very big "if" ) , it is a
Herculean but not impossible task ahead. It will not happen overnight.

"Microsoft Makes Software Safety a Top Goal" - January 17, 2002
http://www.nytimes.com/2002/01/17/technology/17SECU.html
+"Every developer is going to be told not to write any new line of code," Mr.
+Allchin said, "until they have thought out the security implications for the
+product."

YES !!! Finally, but a little too late since almost all of the core OS and
application code has already been written.

Microsoft should have started this process three years ago.
The attempt to turn their current inherently designed insecure products
into a "trusted" system is like that of turning a sows ear into a silk
purse. The result is more likely to be pots and pans into useless,
unsaleable pig iron. A lot of the core design for many of the products
is going to have to be rewritten.

As for "Trustworthy computing" See
"Avoiding bogus encryption products: Snake Oil FAQ" ...
http://www.faqs.org/faqs/cryptography-faq/snake-oil/
... the warning principals apply as much to "secure" software
products as it does to cryptographic products.

For software to be "Trustworthy" it requires that both the source and
build processes be verifiable by public inspection by peers in the
industry. That *requires* an unrestrictive license such as open
source ( http://www.opensource.org/docs/definition.html ), where
everybody can download the source and rebuild the code to compare
the result with the offical distributed binaries.
Microsoft's Shared Source like license, which requires the user agree
to non-competition clauses, prevents real peers from examing the source.

So do the Microsoft executives really have the guts to do what it
takes to get the job done?

David Mohring - "Trust Microsoft" Sung to the Southpark tune of "Blame Canada"

Alun Jones

unread,
Jan 20, 2002, 4:09:47 PM1/20/02
to
In article <a2cdbo$v6q$1...@xivic.prima.de>, nospa...@xivic.prima.de (Wolfgang
Schelongowski) wrote:
>Two problems:
>1) Security is not an add-on like Internet. They'll have to junk
> Win95/98/... and completely rewrite the WinNT/... . The same goes
> for most utilities running with privileges.

In what way do you believe that Windows NT is in need of being "completely
rewritten"? What assumption(s) at the core of the NT design are fundamentally
incompatible with system security?

>2) What Gates said implies a U-turn in the _roots_ of the company's
> philosophy.
>Cf. http://news.com.com/2010-1078-818611.html

The article you quote doesn't seem to support your theories. First, as I
noted earlier, Microsoft _has_ previously done a U-turn in the roots of the
company's philosophy. It's shown surprising maneuverability when the top-man
gets his knickers in a twist over something. Suddenly, he's decided that
security is "job 1" at Microsoft - are you truly of the opinion that he's
going to allow some flunky or other to continue producing crappy code that
embarrasses him by contradicting his newly stated credo?

Second, you seem to be confusing marketing messages with the company's
philosophy. Microsoft's philosophy is to occupy "top notch" in the market,
being the biggest single provider of whatever-it-is that they set their sights
on. If .NET has to be abandoned, re-written, or beefed up to meet the mantra
of the day, then it will. Note how, when .NET is the mantra, Microsoft have
been acting as if it's required for every project, big or small - they bring
that same fervour to each new main direction. Let's hope they do this with
their approach to security.

They have a lot of work ahead of them, but go back and take a look at the
naysayers that, at the time, believed Microsoft didn't have what it takes to
get busy in the Internet world...

Good luck to them - for all our sakes, I hope they succeed.

Walter Dnes

unread,
Jan 20, 2002, 9:55:02 PM1/20/02
to
On 19 Jan 2002 19:19:36 +0100, Wolfgang Schelongowski, <spam...@xivic.prima.de> wrote:

> Two problems:
> 1) Security is not an add-on like Internet. They'll have to junk
> Win95/98/...

They've already done so, and WinME is receiving minimal support.

> and completely rewrite the WinNT/... .

The main problem with XP is the same problem that Redhat faces.
Setting the out-of-the-box-defaults to something reasonably safe. That
can be done without radically altering the product. E.g. don't turn on
the indexing option in IIS by default. My former boss complained about
his W2K machine being a bit slow one day. We looked thourougly at a lot
of options in the settings. His W2K *DESKTOP* was running a whole slew
of server daemons (SMTP, etc). Turning them off produced a noticable
speed up. Fortunately, we're behind a corporate firewall at work. But
this same machine, hooked up to an "always on" broadband residential
connection would've been easy pickings for script kiddies.

> 2) What Gates said implies a U-turn in the _roots_ of the company's
> philosophy.

That's *ALREADY* happened. Microsoft noticed that when Office XP was
intoduced, their biggest competition was... Microsoft. I.e. 60% of
Office users weren't at Office2000. They were still running Office97 or
Office95 or even Office version 4.x (from the Windows 3.1 days). Bill
Gates and Microsoft already know that customers are no longer flocking
to upgrade for "features". So "features" are getting lower priority not
because Bill Gates had a divine vision, but for the down-to-earth reason
that they no longer help sell MS products.

Microsoft is *ALREADY* working on abandoning *SELLING* software, and
is trying to corral everybody into .NET. Microsoft is an amoral
corporation. They'll do whatever they think is necessary to sell more
product/service. If they have to produce secure software, they'll do
so. Not because of any "corporate vision", but because that's what they
have to do to make money. You may argue that their programmers are too
incompetent to do it right, and many people will believe you. But MS
will at least try, and they'll *EVENTUALLY* get it right.

--
Walter Dnes <walt...@waltdnes.org>
If you had purchased $1000 of @home stock in 1999, today you would
have $1.30. If you had purchased $1000 of beer in 1999, today you
would still have $59 in empty cans.

Bill Unruh

unread,
Jan 21, 2002, 1:15:31 PM1/21/02
to
In <vmG28.4153$Hq5.145...@newssvr11.news.prodigy.com> al...@texis.com (Alun Jones) writes:

]In article <a2cdbo$v6q$1...@xivic.prima.de>, nospa...@xivic.prima.de (Wolfgang

]Schelongowski) wrote:
]>Two problems:
]>1) Security is not an add-on like Internet. They'll have to junk
]> Win95/98/... and completely rewrite the WinNT/... . The same goes
]> for most utilities running with privileges.

]In what way do you believe that Windows NT is in need of being "completely
]rewritten"? What assumption(s) at the core of the NT design are fundamentally
]incompatible with system security?

The assumption that you can write secure code without taking security as
a prime consideration in planning and writing the code. That security
can be an "add on".


]>2) What Gates said implies a U-turn in the _roots_ of the company's
]> philosophy.
]>Cf. http://news.com.com/2010-1078-818611.html

]The article you quote doesn't seem to support your theories. First, as I
]noted earlier, Microsoft _has_ previously done a U-turn in the roots of the
]company's philosophy. It's shown surprising maneuverability when the top-man
]gets his knickers in a twist over something. Suddenly, he's decided that
]security is "job 1" at Microsoft - are you truly of the opinion that he's
]going to allow some flunky or other to continue producing crappy code that
]embarrasses him by contradicting his newly stated credo?

??? As long as the emphasis is not on security, insecure code will be
written. As long as the emphasis is on features, and on getting the code
out on time rather than to spec, insecure code will be released.
Security is not like the internet where you can cobble together code to
get the job done. It is a mindset, and that is a lot lot harder to
change, especially when you have trained your workforce for decades not
to take it into account.

]Second, you seem to be confusing marketing messages with the company's

]philosophy. Microsoft's philosophy is to occupy "top notch" in the market,
]being the biggest single provider of whatever-it-is that they set their sights
]on. If .NET has to be abandoned, re-written, or beefed up to meet the mantra
]of the day, then it will. Note how, when .NET is the mantra, Microsoft have
]been acting as if it's required for every project, big or small - they bring
]that same fervour to each new main direction. Let's hope they do this with
]their approach to security.

The companies philosophy has never been to be top notch, but top dog.
Anything which gets in the way of that is irrelevant.

]They have a lot of work ahead of them, but go back and take a look at the

Brion Leary

unread,
Jan 21, 2002, 11:27:03 PM1/21/02
to
I have trouble trusting an OS that that can not rid itself of legacy
code. In particular MS' TCP stack - its probing on port 137, its
leaking
of internal address when name lookups fail. It seems as if deep inside
MS' TCP stack lies LanManager code that treats the Internet as if it
where a local LAN.

Brion Leary

Alun Jones wrote:
>
> In article <a2cdbo$v6q$1...@xivic.prima.de>, nospa...@xivic.prima.de (Wolfgang
> Schelongowski) wrote:
> >Two problems:
> >1) Security is not an add-on like Internet. They'll have to junk
> > Win95/98/... and completely rewrite the WinNT/... . The same goes
> > for most utilities running with privileges.
>
> In what way do you believe that Windows NT is in need of being "completely
> rewritten"? What assumption(s) at the core of the NT design are fundamentally
> incompatible with system security?

>[snip]

Alun Jones

unread,
Jan 22, 2002, 11:54:02 AM1/22/02
to
In article <a2hls3$mgj$1...@nntp.itservices.ubc.ca>, un...@physics.ubc.ca (Bill
Unruh) wrote:
>In <vmG28.4153$Hq5.145...@newssvr11.news.prodigy.com> al...@texis.com (Alun
> Jones) writes:
>]In what way do you believe that Windows NT is in need of being "completely
>]rewritten"? What assumption(s) at the core of the NT design are fundamentally
>]incompatible with system security?
>
>The assumption that you can write secure code without taking security as
>a prime consideration in planning and writing the code. That security
>can be an "add on".

No, I'm serious. Please tell me where that assumption has been made in the
core of the NT system design. You're repeating all the vague statements that
are parroted every time, and you're not mentioning anything specific and
demonstrable. Sure, the apps on top of the system are frequently bust (and
don't try to parrot Microsoft's marketing-speak that Internet Explorer is a
"part of the operating system") - I know that, I make a living selling a
working alternative to the FTP server in IIS. Not a great living, but it's a
living.

>]The article you quote doesn't seem to support your theories. First, as I
>]noted earlier, Microsoft _has_ previously done a U-turn in the roots of the
>]company's philosophy. It's shown surprising maneuverability when the top-man
>]gets his knickers in a twist over something. Suddenly, he's decided that
>]security is "job 1" at Microsoft - are you truly of the opinion that he's
>]going to allow some flunky or other to continue producing crappy code that
>]embarrasses him by contradicting his newly stated credo?
>
>??? As long as the emphasis is not on security, insecure code will be
>written. As long as the emphasis is on features, and on getting the code
>out on time rather than to spec, insecure code will be released.

Yeees, but then as I said, there is this new memo (mentioned right up there in
the subject) that states that the emphasis is _not_ going to be on that any
more, and that the code should be written securely and to spec.

>Security is not like the internet where you can cobble together code to
>get the job done. It is a mindset, and that is a lot lot harder to
>change, especially when you have trained your workforce for decades not
>to take it into account.

The Internet isn't even like that. Sure, people _have_ cobbled code together
to get the job done (and the Unix/Linux/whatever world is no stranger to
network security flaws, either). But it's starting to show that the Internet
additions to many operating systems and applications have been cobbled on,
when it should by all rights have been cause for a rethink of the basic
design. [Note: Internet access _can_ be securely cobbled on, by using an
external "zero privileges" network-aware app with ties through a very thin
security-conscious layer to the portion that requires local security
privileges. It's just that most people are wedded to the monolithic core
concept of application development.]

>]Second, you seem to be confusing marketing messages with the company's
>]philosophy. Microsoft's philosophy is to occupy "top notch" in the market,
>]being the biggest single provider of whatever-it-is that they set their sights
>]on. If .NET has to be abandoned, re-written, or beefed up to meet the mantra
>]of the day, then it will. Note how, when .NET is the mantra, Microsoft have
>]been acting as if it's required for every project, big or small - they bring
>]that same fervour to each new main direction. Let's hope they do this with
>]their approach to security.
>
>The companies philosophy has never been to be top notch, but top dog.

I didn't say "be top notch", I said "occupy 'top notch'". In other words, be
"top dog". I'm very careful in my use of language - please don't read
something I didn't write.

>Anything which gets in the way of that is irrelevant.

That was yesterday (I hope). Today, they see it as being important that they
lock down their product. It's become relevant, if Gates' memo is to be
believed. I'm not predicting one way or the other, because Mr Gates may
discover a new religion tomorrow. However, I am heartened by this change of
track, and I hope that this allows those employees that Microsoft has who _do_
fight for security from the ground up to get their say, and to have their
opinions make a difference.

Barry Margolin

unread,
Jan 22, 2002, 12:10:14 PM1/22/02
to
In article <KOg38.437$sM5.21...@newssvr12.news.prodigy.com>,

Alun Jones <al...@texis.com> wrote:
>Yeees, but then as I said, there is this new memo (mentioned right up there in
>the subject) that states that the emphasis is _not_ going to be on that any
>more, and that the code should be written securely and to spec.

How does a memo change the background of all the programmers? Do you
seriously believe that MS is going to go on a major hiring campaign so they
can replace all their feature-oriented programmers with ones that have more
experience writing secure programs? Telling people to write secure
programs doesn't make them do it if they don't know all the things to think
about.

--
Barry Margolin, bar...@genuity.net
Genuity, Woburn, MA
*** DON'T SEND TECHNICAL QUESTIONS DIRECTLY TO ME, post them to newsgroups.
Please DON'T copy followups to me -- I'll assume it wasn't posted to the group.

Alun Jones

unread,
Jan 22, 2002, 12:45:21 PM1/22/02
to
In article <W1h38.18$_M1.32933@burlma1-snr2>, Barry Margolin
<bar...@genuity.net> wrote:
>In article <KOg38.437$sM5.21...@newssvr12.news.prodigy.com>,
>Alun Jones <al...@texis.com> wrote:
>>Yeees, but then as I said, there is this new memo (mentioned right up there in
>>the subject) that states that the emphasis is _not_ going to be on that any
>>more, and that the code should be written securely and to spec.
>
>How does a memo change the background of all the programmers? Do you
>seriously believe that MS is going to go on a major hiring campaign so they
>can replace all their feature-oriented programmers with ones that have more
>experience writing secure programs? Telling people to write secure
>programs doesn't make them do it if they don't know all the things to think
>about.

I understand, and I agree. However, if there's a big fat memo from the big
fat boss man that says "security is job 1", then the next time there's a
debate about whether to add a dancing piece of office supplies, or to fix a
security bug you could drive a road train through (sideways), or the next time
a programmer comes to his boss and says "there's a back-door hidden here, but
I could fix it in a couple of days", the security argument will win out.

I may be mindlessly naive, but I have this suspicion that even within the
bowels of Microsoft (why is it that the programmers' cubicles are always in
the bowels?), there are a number of programmers who have given security some
consideration, and are just itching to be let loose to rip out the old, and
wire in the new. They can't all be evil minions, surely?

Barry Margolin

unread,
Jan 22, 2002, 1:55:36 PM1/22/02
to
In article <Ryh38.444$Wr6.21...@newssvr12.news.prodigy.com>,

Alun Jones <al...@texis.com> wrote:
>I understand, and I agree. However, if there's a big fat memo from the big
>fat boss man that says "security is job 1", then the next time there's a
>debate about whether to add a dancing piece of office supplies, or to fix a
>security bug you could drive a road train through (sideways), or the next time
>a programmer comes to his boss and says "there's a back-door hidden here, but
>I could fix it in a couple of days", the security argument will win out.

I don't think there are lots of programmers there who have been trying to
fix security bugs, but were being told not to (except in cases where it
might require significant redesign of the application). That's not the
problem. The problem is with programmers who don't understand the security
implications of what they're writing in the first place, thus causing the
security holes to exist in the first place.

Alun Jones

unread,
Jan 22, 2002, 2:51:37 PM1/22/02
to
In article <IAi38.25$_M1.51885@burlma1-snr2>, Barry Margolin
<bar...@genuity.net> wrote:
>I don't think there are lots of programmers there who have been trying to
>fix security bugs, but were being told not to (except in cases where it
>might require significant redesign of the application). That's not the
>problem. The problem is with programmers who don't understand the security
>implications of what they're writing in the first place, thus causing the
>security holes to exist in the first place.

I'll agree with that, but extend it to note that if your corporate structure
doesn't emphasise security, then mentoring other developers around you to
consider security is going to be considered a waste of time by your
supervisors, and the programmers you're trying to educate.

Besides, if the unspoken mantra around you is "features, not security", and
you want to maintain a paycheck in an uncertain world, are you really going to
get to work fixing security bugs, or even analysing the security implications
of the code you are writing, or are you just going to "get it working"?

With a change of mantra comes a change of effect. Hopefully. I do like to
think the best of people :-)

Wolfgang Schelongowski

unread,
Jan 22, 2002, 1:42:00 PM1/22/02
to
In <vmG28.4153$Hq5.145...@newssvr11.news.prodigy.com>
al...@texis.com (Alun Jones) writes:

>In article <a2cdbo$v6q$1...@xivic.prima.de>, nospa...@xivic.prima.de (Wolfgang
>Schelongowski) wrote:
>>Two problems:
>>1) Security is not an add-on like Internet. They'll have to junk
>> Win95/98/... and completely rewrite the WinNT/... . The same goes
>> for most utilities running with privileges.

>In what way do you believe that Windows NT is in need of being "completely
>rewritten"?

Bill Unruh has answered that.

> What assumption(s) at the core of the NT design are fundamentally
>incompatible with system security?

One I know of is that the GUI is an integral part of the OS and
*always* runs during normal operation.

>>2) What Gates said implies a U-turn in the _roots_ of the company's
>> philosophy.
>>Cf. http://news.com.com/2010-1078-818611.html

>The article you quote doesn't seem to support your theories. First, as I
>noted earlier, Microsoft _has_ previously done a U-turn in the roots of the
>company's philosophy. It's shown surprising maneuverability when the top-man
>gets his knickers in a twist over something. Suddenly, he's decided that
>security is "job 1" at Microsoft - are you truly of the opinion that he's
>going to allow some flunky or other to continue producing crappy code that
>embarrasses him by contradicting his newly stated credo?

In a situation like this it's not a question of allowing. We're
talking about Microsoft, not a shop with ten or hundred people.
Thousands of people working there have been instructed for years
that features and getting it out fast are what matter, and to neglect
other goals. That has become a part of their mindset and The Way
Things Are Done Here. Even if Bill had unlimited powers of The Most
Evil Overlord Of Mankind he wouldn't be able to change that fast -
it'll take years to achieve such a turnaround.

>Second, you seem to be confusing marketing messages with the company's
>philosophy. Microsoft's philosophy is to occupy "top notch" in the market,
>being the biggest single provider of whatever-it-is that they set their sights
>on.

I think their philosophy is to make money fast by whatever means
except those that are grossly illegal or will severely damage their
reputation. Building secure software takes time and has therefore
been thought of as "the less the better" if it wouldn't be too
obvious to the public.

>They have a lot of work ahead of them, but go back and take a look at the
>naysayers that, at the time, believed Microsoft didn't have what it takes to
>get busy in the Internet world...

Internet was just another case of "well, it seems we can't impose our
standards here, so we'll have to work according to those that are
generally accepted."

Barry Margolin

unread,
Jan 22, 2002, 3:54:33 PM1/22/02
to
In article <dpj38.486$%w.224...@newssvr12.news.prodigy.com>,

Alun Jones <al...@texis.com> wrote:
>In article <IAi38.25$_M1.51885@burlma1-snr2>, Barry Margolin
><bar...@genuity.net> wrote:
>>I don't think there are lots of programmers there who have been trying to
>>fix security bugs, but were being told not to (except in cases where it
>>might require significant redesign of the application). That's not the
>>problem. The problem is with programmers who don't understand the security
>>implications of what they're writing in the first place, thus causing the
>>security holes to exist in the first place.
>
>I'll agree with that, but extend it to note that if your corporate structure
>doesn't emphasise security, then mentoring other developers around you to
>consider security is going to be considered a waste of time by your
>supervisors, and the programmers you're trying to educate.

Of course. I don't think anyone is saying that the Microsoft memo is a bad
thing, but just that it's a bit too late, since most of the mistakes have
already been made (in both hiring and software design).

Some are also skeptical that this memo will really result in an attitude
adjustment. It sounds more like a public relations ploy, like many of the
airport security changes that have been made since 9/11 (*please*, I
implore the readers of this group, let's not digress into a debate of
whether my impression of the airport changes is correct or not, as that's
beside the point).

Bill Unruh

unread,
Jan 23, 2002, 5:36:13 PM1/23/02
to
In <Ryh38.444$Wr6.21...@newssvr12.news.prodigy.com> al...@texis.com (Alun Jones) writes:

]In article <W1h38.18$_M1.32933@burlma1-snr2>, Barry Margolin

]<bar...@genuity.net> wrote:
]>In article <KOg38.437$sM5.21...@newssvr12.news.prodigy.com>,
]>Alun Jones <al...@texis.com> wrote:
]>>Yeees, but then as I said, there is this new memo (mentioned right up there in
]>>the subject) that states that the emphasis is _not_ going to be on that any
]>>more, and that the code should be written securely and to spec.
]>
]>How does a memo change the background of all the programmers? Do you
]>seriously believe that MS is going to go on a major hiring campaign so they
]>can replace all their feature-oriented programmers with ones that have more
]>experience writing secure programs? Telling people to write secure
]>programs doesn't make them do it if they don't know all the things to think
]>about.

]I understand, and I agree. However, if there's a big fat memo from the big
]fat boss man that says "security is job 1", then the next time there's a
]debate about whether to add a dancing piece of office supplies, or to fix a
]security bug you could drive a road train through (sideways), or the next time
]a programmer comes to his boss and says "there's a back-door hidden here, but
]I could fix it in a couple of days", the security argument will win out.

That is not the way it happens. Clearly if there is a security hole they know about, they will
close it. I think that they have always done this. The question is how diligently you look for
them, how rigourously do you set up your software coding practice to ensure security.
HOw strong is the pressure to 'finish that code". How much do they delay things in order to
search for that 12th time for security bugs. How much does every programmer, as he decides to
start coding think of the security implications of every line of code, of every declaration.

Alan J. Flavell

unread,
Jan 23, 2002, 6:42:22 PM1/23/02
to
On Jan 23, Bill Unruh inscribed on the eternal scroll:

> That is not the way it happens. Clearly if there is a security
> hole they know about, they will close it. I think that they have
> always done this. The question is how diligently you look for
> them, how rigourously do you set up your software coding practice
> to ensure security. HOw strong is the pressure to 'finish that
> code". How much do they delay things in order to search for that
> 12th time for security bugs. How much does every programmer, as he
> decides to start coding think of the security implications of
> every line of code, of every declaration.

Perhaps the solution is to require the programmers to operate their
own computer, using only the vendor's vanilla software, permanently
connected to the Internet without a firewall, and to fix - in their
own time - any problems that arise.

May seem harsh, but (aside from the bit about only using the vendor's
software) it's pretty much what we academic sysadmins have been doing
for as long as there has been an Internet, up until relatively
recently when the need for at least a degree of firewalling became
sufficiently obvious to the folks who hold the money that we could
persuade them to spend a bit on it.

[Hey, I'm not talking about CERN: I'm only a user here.]


Barry Margolin

unread,
Jan 23, 2002, 7:41:21 PM1/23/02
to
In article <Pine.LNX.4.40.020124...@lxplus023.cern.ch>,

Alan J. Flavell <fla...@mail.cern.ch> wrote:
>Perhaps the solution is to require the programmers to operate their
>own computer, using only the vendor's vanilla software, permanently
>connected to the Internet without a firewall, and to fix - in their
>own time - any problems that arise.

That's silly. Why would the programmers responsible for Microsoft Project
be expected to fix security problems in Internet Explorer? Your idea is a
recipe for anarchy, with everyone having to have their fingers in other
groups' pots. Too many cooks spoil the broth, and this is definitely *way*
too many cooks.

Alan J. Flavell

unread,
Jan 24, 2002, 8:11:31 AM1/24/02
to
On Jan 24, Barry Margolin inscribed on the eternal scroll:

> Alan J. Flavell <fla...@mail.cern.ch> wrote:
> >Perhaps the solution is to require the programmers to operate their
> >own computer, using only the vendor's vanilla software, permanently
> >connected to the Internet without a firewall, and to fix - in their
> >own time - any problems that arise.
>
> That's silly.

Of course. I'm sorry I failed to put in an explicit <IRONY!!!> alert.

> Your idea is a recipe for anarchy, with everyone having to have
> their fingers in other groups' pots. Too many cooks spoil the
> broth, and this is definitely *way* too many cooks.

I think I recognise that situation. Like having a would-be web
browser as a non-optional component of the operating system...

Alun Jones

unread,
Jan 24, 2002, 10:40:27 AM1/24/02
to
In article <a2ndst$jtp$1...@nntp.itservices.ubc.ca>, un...@physics.ubc.ca (Bill
Unruh) wrote:
>That is not the way it happens. Clearly if there is a security hole they know
>about, they will close it. I think that they have always done this. The question is how
>diligently you look for them, how rigourously do you set up your software coding practice to ensure
>security. HOw strong is the pressure to 'finish that code". How much do they delay things
> in order to search for that 12th time for security bugs. How much does every programmer, as
> he decides to start coding think of the security implications of every line of code, of every
> declaration.

All valid questions. And yes, I agree that it's going to take some time
before Microsoft becomes "all that they can be", even if the security
requirements are all taken seriously at all levels. However, I think we'll
start to see _some_ changes happen immediately. Exploitable flaws will, I
hope, be easier to report, and fixed much quicker (if only because they can be
recognised as exploitable earlier).

The bottom-up approach to fixing security, however, is going to be the one
that takes the time. Nobody's expecting Microsoft to throw out huge great
gobs of code, or to rewrite their apps from scratch - that would just be a
waste of their time and our money. But I hope they'll turn some programmers
to the task of ripping out unnecessary and redundant code, of removing kludgy
operations and protocols, to the extent to which they are able. Of course,
the mantra of backward compatibility might prove a hurdle that takes some
ingenuity to cross - I'm intrigued as to whether Microsoft will do as before,
and take every effort to dilute their code to cope with poorly written, but
wildly popular, applications, or whether they'll have the stones to say "tough
cookies" to the programmers that have chosen to code to undocumented features.

Bill Unruh

unread,
Jan 24, 2002, 11:30:18 AM1/24/02
to
In <LVV38.877$L41.38...@newssvr12.news.prodigy.com> al...@texis.com (Alun Jones) writes:

]In article <a2ndst$jtp$1...@nntp.itservices.ubc.ca>, un...@physics.ubc.ca (Bill

]Unruh) wrote:
]>That is not the way it happens. Clearly if there is a security hole they know
]>about, they will close it. I think that they have always done this. The question is how
]>diligently you look for them, how rigourously do you set up your software coding practice to ensure
]>security. HOw strong is the pressure to 'finish that code". How much do they delay things
]> in order to search for that 12th time for security bugs. How much does every programmer, as
]> he decides to start coding think of the security implications of every line of code, of every
]> declaration.

]All valid questions. And yes, I agree that it's going to take some time
]before Microsoft becomes "all that they can be", even if the security
]requirements are all taken seriously at all levels. However, I think we'll
]start to see _some_ changes happen immediately. Exploitable flaws will, I
]hope, be easier to report, and fixed much quicker (if only because they can be
]recognised as exploitable earlier).

No, I could well expect the opposite-- hide the mistakes. MS is secure--
Gates says so -- and so any reports otherwise are simply outsiders
trying to make trouble. (Admittedly it is hard to see how they could
travel further down that road-- maybe law suits against anyone who
reports a bug?)


]The bottom-up approach to fixing security, however, is going to be the one

]that takes the time. Nobody's expecting Microsoft to throw out huge great
]gobs of code, or to rewrite their apps from scratch - that would just be a
]waste of their time and our money. But I hope they'll turn some programmers
]to the task of ripping out unnecessary and redundant code, of removing kludgy
]operations and protocols, to the extent to which they are able. Of course,

No, that is a horrible approach. It is much more expensive to try to
remodel than to just build it new. The chances of introducing new bugs
in trying to alter a program someone else (inclidung yourself a year
ago) wrote are very high.

Alun Jones

unread,
Jan 24, 2002, 3:24:12 PM1/24/02
to
In article <a2pcqq$mf6$1...@nntp.itservices.ubc.ca>, un...@physics.ubc.ca (Bill

Do you really rewrite everything you use on an annual basis? At some point,
it would seem obvious that you do have to work with what you have.
Re-engineering would seem to apply only when the existing code is _horrible_
[of course, we are talking about Microsoft...] - otherwise, your own
cautionary note on human fallibility applies even more so, with the call to
rewrite everything.

Mike

unread,
Jan 25, 2002, 8:15:37 AM1/25/02
to
On Thu, 24 Jan 2002 00:41:21 GMT, Barry Margolin <bar...@genuity.net>
wrote:

>That's silly. Why would the programmers responsible for Microsoft Project
>be expected to fix security problems in Internet Explorer?

Why does a MS Office install patch my Windows OS DLL files?

> Your idea is a recipe for anarchy,

Anarchy? Yes. But the common term for it is DLL Hell.

0 new messages