Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » MS Retreats Over Vista Security Claims
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Detecting wireless network intrusions ? »
« No pay off in extortion attacks?  
AuthorAll Replies

SUMware
Premium
join:2002-05-21


3 edits
reply to dave
"SDL is not perfect, nor will it ever be perfect."

said by dave See Profile :

Ah. One employee of Microsoft says something, and it's reported as 'Microsoft says'...
I bet you'll find some core OS engineers that agree with Russinovich and some that are seriously pissed off at him for dissing their baby in public.
More lowered expectations...?

From ComputerWorld - April 27, 2007:
How the ANI bug got baked into Vista: Microsoft explains
quote:
In a postmortem of last month's Windows animated (.ANI) cursor vulnerability, one of Microsoft Corp.'s security development gurus today spelled out how the bug sneaked into Vista

Michael Howard, an authority on Microsoft's Security Development Lifecycle (SDL) -- a multipart initiative that aims to get developers to design more secure code -- posted an extensive entry on the brand-new SDL blog that outlined lessons learned from the ANI vulnerability. "SDL is not perfect, nor will it ever be perfect," Howard acknowledged yesterday. "We still have work to do, and this bug shows that."

That bug, which first surfaced late last month and posed enough of a threat that Microsoft went out of cycle to patch it, affected all older editions of Windows as well as the newest, and supposedly more secure, Windows Vista. Some security researchers, in fact, took Microsoft and its SDL process to task for not catching the flawed code as Vista was written, debugged, tested and polished.
Michael Howard is a security program manager on the Microsoft Windows XP team, focusing on secure design, programming, and testing techniques. He works with hundreds of people both inside and outside the company each year to help them secure their applications. He is the author of Designing Secure Web-Based Applications for Microsoft Windows 2000 from Microsoft Press. Prior to working on Windows XP, Michael worked on next-generation Web server technologies and IIS. He has worked on Microsoft Windows NT security since 1992.
Forums » Up and Running » Security » SecurityDetecting wireless network intrusions ? »
« No pay off in extortion attacks?  


Thursday, 26-Nov 23:41:34 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [112] Time Warner Cable Fires Broadside At Broadcasters
· [109] New AT&T Ad Campaign Hits Back At Verizon
· [95] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [70] TiVo Sees Record Customer Losses
· [62] In-Flight Internet Headed For Bumpy Landing?
· [54] Thanksgiving Open Thread
· [37] ICANN Slams DNS Redirection
· [36] Senators Want ACTA Made Public
· [35] EFF Wages War On Fine Print
Most people now reading
· Bell Response to PIPEDA Request [TekSavvy]
· Newegg Black Friday Sale started [Users Find Hot Deals]
· Not strictly "Home" related - but WOW anyways... [Home Repair & Improvement]
· Only firefox accesses Internet? [Security]
· SSD [Computer Hardware Discussion/Reviews]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· IPComms Free DIDs now with sip registration maybe?? [VOIP Tech Chat]
· Slow speeds in the evenings [TekSavvy]
· I'll Just Unplug That... [No, I Will Not Fix Your #@$!! Computer]
· [ Classes] Druid tanking: rotation and glyphs [World of Warcraft]