On CBS MoneyWatch: 11 Buzzwords That Should Be Banned
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 34 of 49:
Next »
« Previous
The standard bad news for MS
``The first critical problem involves a vulnerability in the "Task Scheduler" stemming from an unchecked buffer, which is a program in memory that accepts data from external sources. An unchecked buffer is one that does not include commands to ensure that the data is valid.

Microsoft said that if a user is logged on with administrative privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs, deleting data, or creating new accounts with full privileges. Microsoft added that users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.''

i.e., the standard ``free'' functionality that comes with the MS platform. But see it in another, more positive light: it is a feature that allows DISTRIBUTED SYSTEMS MANAGEMENT. The problem is that is allows the WRONG people to carry out a the wrong management to one's valuable personal data.


``According to Symantec, in a Web-based attack scenario, an attacker would have to host a Web site that contains a Web page used to exploit this vulnerability. An attacker also would have to persuade them to visit the Web site, typically by getting them to click a link that takes them to the attacker's site.''

And it is so hard these days to make someone click a link on the page he/she is currently visiting....


``Microsoft said the second critical update concerns vulnerabilities related to "HTML Help" and "showHelp." If a user is logged on with administrative privileges, an attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system, the company said.''

So, you thought you could do sysadmin tasks AND read help at the same time? Wrong: this is a prohibited combination as per the `Trustworthy Computing Intitiative' spec ( wink )


``Microsoft said four other security updates rated as "important," the second-highest rating given by the company. The last security update was rated "moderate" in severity.''

What does it take to call a thread as `critical'? Does the PC need to start smoking first?


``Corporate VP Mike Nash announced the tool for Download.Ject during a speech at the Worldwide Partner Conference in Toronto. The company also said that it has reached its goal--ahead of schedule--to train half a million customers and partners on how best to secure their systems.''

Great, with the claimed 600,000,000 PCs available arounf the world, it would take around 1,200 days (3.28 full years) to train all these people, IF 1/2 million of them woulbd be trained PER DAY.


``Microsoft also noted that five times as many people are using Windows' automatic update feature as were signed up 10 months ago.'' 5 times WHAT?


Again, I CANNOT get over the fact that there can be s/w for which 10s or 100s of millions man-hours have been invested by a company with relatively limitless resources, but IT CANNOT BE CORRECTED!! This deserves a prominent place in the ``IT History of SHAME''....

How is it that organizations with minute resource vs those of MS, CAN produce s/w that behaves more securely and more efficiently and it can run on a LENGHTY array of different h/w platforms? We are living in interesting times....

OK: now download your 250MB BETA patch and contribute your share to pay the $ 200 Billion bill to clean up the MS global security chaos.


MS will be renembered as the company that managed to foll so many people for such a long time. AKA the era of Massive Masochism.


Enjoy ! -m
Posted by: michael-t   Posted on: 07/13/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Microsoft trapped in the hole they dug themselves  toadlife | 07/13/04
One problem though  DarthRidiculous | 07/13/04
More than that  AbsolutelyNot | 07/13/04
Sounds wonderful, but most...  bjbrock | 07/14/04
a better solution:  ryusen | 07/14/04
I'd be up for that  toadlife | 07/14/04
group policy...  ryusen | 07/14/04
Already Available  Alto_z | 07/14/04
GAIN  Alto_z | 07/14/04
Wrong!  toadlife | 07/13/04
If a tree falls and no one's there to hear it...  Michael Kelly | 07/13/04
The trouble is...  Immanuel Tranz-Mischen | 07/13/04
But...  Immanuel Tranz-Mischen | 07/13/04
So?  toadlife | 07/13/04
Here's one problem though...  Michael Kelly | 07/13/04
They don't appear to distinguish admin from root.  Immanuel Tranz-Mischen | 07/13/04
ctrl-opt-com-P combo  Alto_z | 07/14/04
In addition to my earlier comment...  Alto_z | 07/14/04
Everything bad re windows and security  Richard Flude | 07/13/04
ignorant, fanatic, or both?  toadlife | 07/13/04
The goose is ready  Richard Flude | 07/13/04
I think it's undercooked  toadlife | 07/13/04
If the AV software...  bjbrock | 07/14/04
Not a all  Richard Flude | 07/14/04
I agree  CobraA1 | 07/14/04
Not really  toadlife | 07/14/04
Another tip  PA-ITGuy | 07/14/04
There however are still some errant install packages  Alto_z | 07/14/04
Shut up  OhMyGosh | 07/14/04
sp  OhMyGosh | 07/14/04
That's like saying that Guns cause violence...  saumur85 | 07/14/04
Make me!  toadlife | 07/14/04
Major Apps need to change  chaz@... | 07/14/04
The standard bad news for MS  michael-t | 07/13/04
re: The standard bad news for MS  toadlife | 07/13/04
Exactly  michael-t | 07/13/04
In other news  Yagotta B. Kidding | 07/13/04
Man, you have to feel for the guys at Microsoft. How much can they take???  DonnieBoy | 07/13/04
Yes, but THEY HAVE to clean THEIR mess  michael-t | 07/13/04
You ain't seen nuthin' yet  Eggs Ackley_z | 07/14/04
RE: You ain't seen nuthin' yet  BXLE | 07/14/04
Old Guy?  Eggs Ackley_z | 07/14/04
I'll give MS this much...  Michael Kelly | 07/14/04
Ballmer must have meant the FLAWS ARE GROWING.  Xunil_Sierutuf | 07/14/04
Readers and MS are missing the point!  netace_z | 07/14/04
relativity of ease...  ryusen | 07/14/04
nfortunately, you missed the  michael-t | 07/14/04
If a tree falls in a forest...  Canberrait | 07/14/04
Critical Flaws?!  grannyhoot | 07/15/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here