On GameSpot: The best gaming gifts for the holidays
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 9 of 14:
Next »
« Previous
Word up
Running with limited privileges can sometimes be impossible. Microsoft takes a lot of crap for their poor decisions, but they're only half the problem. The software app vendors share equal resposibility for the state of Windows security, in that they build their applications requiring poor security practices be in place (vulnerable services running, broad rights given, etc.). And this isn't just small, obscure companies. I had a dust up with IBM about their WebSphere product several years ago. SANS wanted us to take the fight public but we couldn't afford the publicity or time. NIST has claimed for years that they were in the process of creating a certification program for applications that would allow vendors to place a badge on their products to denote they passed a security compliance test - basically that the vendors product doesn't rely on something stupid like admin privileges or services that might not be desirable in an Internet-exposed environment. However, I've yet to see any evidence that the effort is getting anywhere.
Posted by: ejhonda   Posted on: 01/06/06 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Now explain why....  DarbyOhara | 01/05/06
Never go away  Boot_Agnostic | 01/05/06
Think Layers... Like an onion.  Mr. Roboto | 01/05/06
Sounds like you run as admin  toadlife | 01/05/06
Tsk, tsk  rickhal | 01/05/06
Poor Microsoft  toadlife | 01/05/06
Look at the type of users readers of this column have to deal with...  TimeBomb | 01/06/06
Poor, Poor Microsoft  toadlife | 01/06/06
Word up  ejhonda | 01/06/06
NIST Checklist program  ejhonda | 01/06/06
My experience is different  toadlife | 01/06/06
Inherent probem in Windows  percuno@... | 07/30/06
It's about TIME SOMEONE did something!!!  Betelgeuse58 | 01/05/06
Someone already did !  LuisB | 01/08/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

SmartPlanet

Click Here