- TalkBack 9 of 14:
- Next »
- « Previous
- Thread View
- Flat View
- Word up
- Running with limited privileges can sometimes be impossible. Microsoft takes a lot of crap for their poor decisions, but they're only half the problem. The software app vendors share equal resposibility for the state of Windows security, in that they build their applications requiring poor security practices be in place (vulnerable services running, broad rights given, etc.). And this isn't just small, obscure companies. I had a dust up with IBM about their WebSphere product several years ago. SANS wanted us to take the fight public but we couldn't afford the publicity or time. NIST has claimed for years that they were in the process of creating a certification program for applications that would allow vendors to place a badge on their products to denote they passed a security compliance test - basically that the vendors product doesn't rely on something stupid like admin privileges or services that might not be desirable in an Internet-exposed environment. However, I've yet to see any evidence that the effort is getting anywhere.
- Posted by: ejhonda Posted on: 01/06/06 You are currently: a Guest | Members login | Terms of Use
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
What do you think?
SponsoredWhite Papers, Webcasts, and Downloads
- Why Isn't Server Virtualization Saving Us More? A Few Small Changes May Dramatically Increase Your Efficiency VMware Companies have rapidly adopted server virtualization over the past few ... Download Now
- Key Strategies for Federal Agencies - Safe and Cost Effective Migration for Legacy Hardware GovConnection The federal government has mandated that federal agencies reduce energy ... Download Now
- The True Costs of Virtual Server Solutions VMware In an economic environment that is repeatedly heralding the message "do ... Download Now
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Keep Up With The Latest In Document Management with The DocuMentor.
-
Doc delivers the scoop on today's enterprise content management, printer maintenance, and all other issues related to document management. It's the DocuMentor Blog.
- Learn more >>
- The more you simplify, the more you save
-
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
- Learn more >>
- Twelve Ways to Reduce Costs with Microsoft® SQL Server® 2008
-
Discover ways in which organizations can use Microsoft SQL Server 2008 to save time and money.

- Click to download>>
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- How to Drive Better Business Outcomes with Exceptional Web Experiences Download the eBook
- Driving Business Agility through SOA Connectivity & Integration Read the White Paper from IBM
- Linking Decisions and Information for Organizational Performance Read the Tom Davenport study









