Full Disclosure mailing list archives
RE: Microsoft Cries Wolf ( again )
From: "Schmehl, Paul L" <pauls () utdallas edu>
Date: Tue, 1 Jul 2003 17:58:10 -0500
-----Original Message----- From: Kristian Hermansen [mailto:this_is_kris () hotmail com] Sent: Tuesday, July 01, 2003 3:09 PM To: full-disclosure () lists netsys com Subject: Re: [Full-disclosure] Microsoft Cries Wolf ( again ) I agree. It is not our problem. The reason is this. Microsoft would like to reduce costs. Fixing bugs in products costs money, and 0-day bugs need immediate fixes which slow down MS total output ability. They would like to see everyone reporting to the vendor first because this saves them money!!! In this respect, this also allows them to go on writing sloppy code in order to save a few bucks on every product, thus reducing their overhead. I don't want sloppy code. Let the 0-days fly....maybe MS will start doing extensive testing to their products before they release it for sale to millions of customers. I thought .NET was supposed to fix all this ;-P
That's too funny. Microsoft ran a "buffer overflow finder" against the codebase for XP, and the VP in charge announced publicly that they had "eliminated buffer overflows in XP". Within thirty days, eEye announced the UPnP vulnerability in SSDP, which is the single most devastating hole ever found in MS products. (You can compromise an entire network of XP machines with one attack, simultaneously.) You don't fix code by extensive testing. You fix it by teaching how to write secure code to begin with *and* by ongoing, consistent audits done before code is released. (OpenBSD has been doing this for years, and look at the results.) Paul Schmehl (pauls () utdallas edu) Adjunct Information Security Officer The University of Texas at Dallas AVIEN Founding Member http://www.utdallas.edu/~pauls/ _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- RE: Microsoft Cries Wolf ( again ), (continued)
- RE: Microsoft Cries Wolf ( again ) Mike Fratto (Jul 01)
- RE: Microsoft Cries Wolf ( again ) Cesar (Jul 01)
- Re: Microsoft Cries Wolf ( again ) Brett Hutley (Jul 02)
- Re: Microsoft Cries Wolf ( again ) Peter van den Heuvel (Jul 01)
- Re: Microsoft Cries Wolf ( again ) mattmurphy () kc rr com (Jul 01)
- Re: Microsoft Cries Wolf ( again ) Ron DuFresne (Jul 01)
- Re: Microsoft Cries Wolf ( again ) KF (Jul 01)
- Re: Microsoft Cries Wolf ( again ) Ron DuFresne (Jul 01)
- Re: Microsoft Cries Wolf ( again ) dhtml (Jul 01)
- Re: Microsoft Cries Wolf ( again ) Kristian Hermansen (Jul 01)
- Re: Microsoft Cries Wolf ( again ) KF (Jul 01)
- RE: Microsoft Cries Wolf ( again ) Schmehl, Paul L (Jul 01)
- Re: Microsoft Cries Wolf ( again ) Shawn McMahon (Jul 02)
- Re: Microsoft Cries Wolf ( again ) Kristian Hermansen (Jul 06)
- Re: Microsoft Cries Wolf ( again ) gandalf94305 (Jul 06)
- Re: Microsoft Cries Wolf ( again ) mattmurphy () kc rr com (Jul 01)
- Re: Microsoft Cries Wolf ( again ) Karl DeBisschop (Jul 01)
- Re: Microsoft Cries Wolf ( again ) Geoincidents (Jul 02)
- Re: Microsoft Cries Wolf ( again ) Justin Shin (Jul 02)
- Vote with your dollars (Was: Re: Microsoft Cries Wolf ( again )) Peter Busser (Jul 02)
- Re: Microsoft Cries Wolf ( again ) andrewg (Jul 02)
- Re: Microsoft Cries Wolf ( again ) Karl DeBisschop (Jul 01)