Dailydave mailing list archives

XP SP2 - "Exploit writers need to stop being such a pussy"


From: Dave Aitel <dave () immunitysec com>
Date: Mon, 09 Aug 2004 22:30:03 -0400

So I'm in some random city in the American South. On my way here, United decided to lose my bag. Of course, they have an automated voice recognition system answering their "lost baggage phone" with no option for a human agent, and he can't understand my last name, which means "he" can't find my baggage. There's nothing like showing up to a financial institution in shorts and a "Bill Gates - Dropout" tee shirt. I always wondered why every other business traveller seemed to have everything they were going to need for an African safari in their carry on bag. Now I know!

I try to think of consulting as a lot like Dead Like Me - where you have a small group of people that you hang with every day, but you're constantly going on little missions yourself, guided only by an address.

So I'm sick of people getting scared of SP2. Microsoft still has, in my opinion, a strategic weakness. They don't have any good exploit writers on staff, and they think of exploits in an antique way. Even with the conversations I had in Vegas, I still sense this, and if exploit writers were smart, they'd look at a culling as a good thing. If the rotton bottom layer fruit is gone, and the market collapses a bit, the industry will get a lot cleaner and more fun to be in. As bin Laden said, "Is this the land of people who prefer death over honey?"

I think this will help us in other ways too. Weld's OIS game looks like a "the industry was unable to self regulate, please regulate for us" pitch. I haven't thought of a good solution to that, but it wouldn't hurt to have the industry dip a bit and let the bigger players concentrate on other things for a while - like their bottom line. And, of course, when Microsoft stops feeling the pain, the OIS will disolve like so much cigar smoke.

I had my whole collection of Dawson's Creek DVDs in the suitcase too. That really irks me.

-dave





_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://www.immunitysec.com/mailman/listinfo/dailydave


Current thread: