
'We're all in this together...'
By Pia Heikkila
Published: 18 October 2001 17:45 BST
In a move which should bring an end to a long week of finger-pointing, Microsoft has finally decided the whole industry is responsible for security - vendors and users alike.
The debate was originally sparked by a Gartner report which recommended users stop installing Microsoft server software altogether, such are the security weaknesses.
A Microsoft security expert then hit back, telling silicon.com there was nothing wrong with the software itself. He claimed that "laid-back" system administrators were to blame for the rapidity with which viruses spread because they do not update security patches often enough.
That provoked a deluge of response from angry sys admins, most of whom agree with Gartner's view that Microsoft's Internet Information Server (IIS) is inherently insecure, and that the company has a tendency to release untried software.
Microsoft did retract its original accusation, but the company's top security boss has now brought the debate to a close, saying: "We are all in this together."
In an exclusive interview, Howard A Schmidt, Microsoft's chief security officer, told silicon.com the company does not release immature software, but is still trying hard to make its technology more secure.
He said: "It is unfortunate the mistakes are not caught earlier as we acknowledge the fact there is a problem with issuing patches. But we are constantly trying to improve our products and learn from our previous mistakes."
When asked who is to blame for the lax security of IIS, he said: "We are all in this together, sys admins, the IT professionals, the developers, the security people. We are trying to identify all the pieces which fit together to improve security."
He also said sys admins have a very hard job and the company is trying to help to make technology easy for them.
Schmidt also responded to Gartner's recommendation. He said: "Our software is not less secure than our competitors', but we have identified the fact that some of the bugs might have created problems. This is why we offer a free lockdown tool to get the problem fixed as soon as possible."
We'll be publishing the full video interview with Schmidt in the next few weeks.
Incl: IIS, DHCP, DNS, DFS, Active Directory, Group Policy) Experience of EPOS or VPN is beneficial however by no means essential.If you are looking ...
It is essential that applicants have experience of installing and configuring MOSS solutions from the ground up. Interview slots this week. This is ...
The role involves Project Management, Relationship Management (Fund Managers/Administrators), Team Leadership, Vendor Management and Technology ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
silicon.com Dear silicon.com... ZX Spectrum nostalgia, Mac attack, tag a bag… Reader Comments of the Week
Steve Ranger Editor's Blog: Home computing from Acorn, Amiga and Amstrad, to the ZX Spectrum Nostalgia 2.0...