You are here: silicon.com > Comment & Analysis

Comment & Analysis

Microsoft's security run around

So even Microsoft, with all its legendary technical expertise, cannot come up with a bullet-proof network.

By editorial@silicon.com

Published: 27 October 2000 16:00 GMT

And this was no minor hack - according to the Wall Street Journal, which uncovered the incident, our malicious individual (assuming it was the work of one person) hid a Trojan program called QAZ in a Notepad document, which was sent to a Microsoft employee's email.

The employee opened the file, which triggered the Trojan to alert a computer in Asia. It's then supposed to have installed tools from a site in the South Pacific.

Other computers were infected as the Trojan propagated, passwords were collected, and then reportedly emailed to an address in St Petersburg, Russia.

Whether or not that's all true - and some security experts doubt the Russian connection, with Microsoft itself refusing to confirm the details - it is undoubtedly true that the network was compromised.

So what does all this mean for businesses in general? One mischievous silicon.com viewer suggested in a Reader Comment that Microsoft's own products were to blame - an echo of the aftermath of the last LoveBug attack, when Microsoft was accused of releasing inherently insecure products.

Our viewer said: "Most Microsoft products appear to ship with security disabled (default security on NTFS drives, UDP port 139 wide open, etc). It seems to me that their philosophy is 'enable everything and then try to switch off the holes you don't want open'. Personally I think good security starts the other way round."

He's quite right, at least on his last point - any IT manager who hasn't changed the default security settings on his or her software, whether Microsoft's or otherwise, deserves to be hacked.

But even that may not be enough. Surely Microsoft itself would have taken every precaution to protect such sensitive data - assuming the Wall Street Journal report is correct and the source code of upcoming products was accessed.

A determined hacker, either with malicious intent or with industrial espionage in mind, will always be able to crack every network, given time.

So what's the answer? Unfortunately, no system is totally secure - just as no filing cabinet or safe is totally secure.

Total security, in this case, would have involved Microsoft removing the source code under development from its network. Hardly an option as productivity would grind to a halt.

So all you can do is balance security, and the amount you spend on it, with productivity - while factoring in the potential damage of losing the data in question.

It's hardly a perfect solution. But as Microsoft has just found out, this is a far from perfect world.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Senior Finance Treasury Analyst

retail bank, senior finance analyst, analyst, product controller, middle office, P&L, risk management, pricing, regulatory, risk, asset liability ...

Marketing Analyst w/ SAS - Global High Street Bank - London

One of the UK's biggest high street banks requires a SAS analyst to join Segment Analysis team. SAS ! SAS ! SAS ! SAS ! The suucessful candidate ...

Software Sales Executive Banking Risk Software

Suitable backgrounds would include: Misys, Wall Street, Sungard, Temenos, FRS Global, SAS, Calypso, Fiserv, Finarch, GL We currently seek a Software ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: