Microsoft Security

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
OS Opinion released a short article on Microsoft's new security plan. Microsoft will not be writing new code this month, but just doing a quick security audit. Bravo Microsoft!

It was mentioned on The OpenBSD Journal that the biggest problem with Microsoft's security is the users. So will education be pimped by Microsoft? Let's hope so.

There is also an article on Security Focus mentioning several companies, including Microsoft, @stake, and Foundstone (among other big players) working on a draft on full disclosure. This will include a one month wait before releasing specific exploit code and information. Is this full discloseure as we know it? Not exactly. But I think this is definitely a good idea to give the vendor time to release a patch, and 30 days should be long enough.
 

Psychoholic

Elite Member
Oct 11, 1999
2,704
0
76


<< It was mentioned on <a class=ftalternatingbarlinklarge href="http://www.deadly.org" target=new><FONT face=Tahoma color=#000080>The OpenBSD Journal</FONT></A> that the biggest problem with Microsoft's security is the users. So will education be pimped by Microsoft? Let's hope so. >>


I've said that of any OS. I doesn't matter what OS is being used, a lax, uneducated Administrator is a disaster waiting to happen.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0


<<

<< It was mentioned on <a class=ftalternatingbarlinklarge href="http://www.deadly.org" target=new><STRONG><FONT face=Tahoma color=#000080>The OpenBSD Journal</FONT></STRONG></A> that the biggest problem with Microsoft's security is the users. So will education be pimped by Microsoft? Let's hope so. >>


I've said that of any OS. I doesn't matter what OS is being used, a lax, uneducated Administrator is a disaster waiting to happen.
>>



Agreed, but considering the source (OpenBSD site) you should be happy that BSD snobs are admitting its not all Microsoft's fault
 

Psychoholic

Elite Member
Oct 11, 1999
2,704
0
76
OK, that's the first and the last time I try the WYSIWYG editor. Trying to quote someone sucks.



<< Agreed, but considering the source (OpenBSD site) you should be happy that BSD snobs are admitting its not all Microsoft's fault >>


You're right. I'm happy they are finally admitting that. It's about damn time they wake up and listen to what I've been saying for a long time now.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0


<< OK, that's the first and the last time I try the WYSIWYG editor. Trying to quote someone sucks.



<< Agreed, but considering the source (OpenBSD site) you should be happy that BSD snobs are admitting its not all Microsoft's fault >>


You're right. I'm happy they are finally admitting that. It's about damn time they wake up and listen to what I've been saying for a long time now.
>>



Now its not *ONLY* the fault of the users, but they are the biggest problem in my opinion. I cant wait to see what Microsoft pulls out of all this.
 

Psychoholic

Elite Member
Oct 11, 1999
2,704
0
76


<< Now its not *ONLY* the fault of the users, but they are the biggest problem in my opinion. >>


Never said that was the only problem, but I'd be willing to place the percentage around 80% or so. For example, IIS would not have been affected by most of the Nimda variants even without the patch, if only the Administrators knew how to securely lock down IIS.

Microsoft isn't perfect and there will still be bugs and security holes, that's true of any software. As both you and I know there's no such thing as bug-free.



<< I cant wait to see what Microsoft pulls out of all this. >>


I think whatever happens it will improve security considerably. I've have already seen improvements in the handling/availability/access of security patches since they first started talking about clamping down on security problems.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0


<<

<< Now its not *ONLY* the fault of the users, but they are the biggest problem in my opinion. >>


Never said that was the only problem, but I'd be willing to place the percentage around 80% or so. For example, IIS would not have been affected by most of the Nimda variants even without the patch, if only the Administrators knew how to securely lock down IIS.
>>



But why not have it secure by default and make the admins screw it up? My philosophy on those things.



<< Microsoft isn't perfect and there will still be bugs and security holes, that's true of any software. As both you and I know there's no such thing as bug-free. >>



Agreed.



<<

<< I cant wait to see what Microsoft pulls out of all this. >>


I think whatever happens it will improve security considerably. I've have already seen improvements in the handling/availability/access of security patches since they first started talking about clamping down on security problems.
>>



Since I have little exposure to Windows stuff except what I read on the net, Ill let you help keep me up to date on this stuff. Most of the web sources are biased the opposite direction than you, so you can help make a sort of balance. If you dont mind of course
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |