On mySimon: Holiday Gifts for Kids
BNET Business Network:
BNET
TechRepublic
ZDNet

May 10th, 2006

Trouble ahead for security industry as Microsoft gets security right

Posted by David Berlind @ 9:34 am

Categories: General, IT Management, Personal Technology, Security, Software Infrastructure

Tags:

Whether you choose to believe it or not, Microsoft appears to finally be getting its security house in order.  No, frequent patches, like yesterday’s corrections to critical flaws, are not evidence that secure computing for Microsoft is an impossible task.  On the contrary. Microsoft, probably more than any other vendor (because of what it has been through), knows more about what it takes (technology-wise, business process-wise, timing-wise) to secure its customers than any other non-security vendor in the computer industry.  That doesn’t mean that there still isn’t a To-Do list with items left on it.  ID management is overflowing with enough companies and options to make your head spin. But it does mean that Microsoft, between what it’s doing for existing users of its products and what it’s doing in the next version of Windows (Vista), is on the right path. 

There’s other evidence of Microsoft’s progress. While vulnerabilities still exist and new malware that exploits them continues to turn up, it has been a long time since malware that exploited a vulnerability in Microsoft’s operating systems or applications resulted in a widespread outbreak or a serious disruption on the order of something like SoBig, CodeRed, Melissa, or the infamous ILOVEYOU worm that "celebrated" its sixth anniversary last week.  As Windows’ "surface area" (digital security-speak for multiple swaths of vulnerabilities) continues to shrink, malware developers will increasingly be looking elsewhere for trouble (for example,  some mobile platforms and, more recently, Mac OS X).  In its Spring 2006 Top 20 List of Security Vulnerabilities, the SANS Institute #1 listed item said:

Rapid growth in critical vulnerabilities being discovered in Mac OS/X including a zero-day vulnerability (OS/X still remains safer than Windows, but its reputation for offering a bullet-proof alternative to Windows is in tatters.)

When I think of words that foster confidence, or even hope that the situation will be corrected, "tatters" is not one of those words. 

The traditional security vendors appear to be scrambling as well.  Shortly after a recent meeting with Gene Hodges during which the then-CEO of McAfee told me that the company was going to do just fine despite Microsoft’s inclusion of competing security software and services in Vista, he jumped ship.  Usually, CEOs stick around companies with a lot of upside.  More recently, when news of OS X’s vulnerabilities turned up, McAfee went on the offensive and launched a Mac security product with an accompanying PR campaign that  Yankee Group analyst Andrew Jaquith lambasted as scaremongering. Desperate moves by a company that could be taking on water?  You decide. 

Meanwhile, after Fred Felman and Te Smith, a dynamic security duo that helped propel personal firewall maker Zone Labs to the stratosphere (and acquisition by Checkpoint), left Zone to join another security outfit (Tenebril), it wasn’t long before both moved on.  Said Felman of the entire security business at the time, "It’s beat."  Fellow Richard Stiennon who was a security analyst for Gartner before doing a short stint with spyware stomper Webroot and who is now a blogger for ZDNet (in addition to founding IT Harvest),  took umbrage at the idea that the security industry was out of gas. Sorry Richard. I’m with Felman who spent the better part of the last decade selling security products.  When someone like that says the business is beat and backs it up by leaving it, the business is beat.

Need another smoking gun? I don’t think you have to look beyond Symantec which has been diversifying its portfolio over the last few years; a strategy that, judging by CEO John Thompson’s more recent comments about identity management, isn’t done yet.  Since the beginning of 2005, Symantec has been on the acquisition trail having acquired Veritas Software, Sygate, WholeSecurity, BindView, IM Logic and Relicore.  Some of these companies are squarely in the security space.  Others, like Veritas and Relicore are more about systems management and reliability (tangentially connected to security, but not a direct hit).  This week,

Thompson indicated his quest may not be over, citing identity management (more closely tied to security, but not the sort of security that Symantec typically covers) as a category that interests him.  Identity management? Symantec.  It will be interesting to see where Thompson takes this.  ID management, especially in the business space, is overflowing with enough companies and options to make your head spin.  Not to mention how the key operating system players like Microsoft, Sun, and Novell (which is readying the official release of a new, open source-based ID management solution known as Bandit) have offerings in the space as well.  Next on my blog to do list: What I’d do if I were CEO of Symantec.

  • Talkback
  • Most Recent of 42 Talkback(s)
Start your mouths.
Windows update occurs over the web. Name one time windows update has been hit by the "bad" guys. I've never had a windows update go bad personally. We use WSUS at work to distribute windows updates an... (Read the rest)
Posted by: xuniL_z Posted on: 09/22/06 You are currently: a Guest | | Terms of Use
Vulnerability.  Anton Philidor | 05/10/06
Social engineers  dberlind | 05/10/06
Celebrate Paranoia  Harry Bardal | 05/10/06
Looking forward to Vista  zzz1234567890 | 05/10/06
Apple does not sell PC's  balsover | 05/11/06
But they could sell....  DCMann | 05/11/06
Why trade down?  thegestunkenaraygun | 05/15/06
You Must Be a Beta Tester...  DalyDose | 05/19/06
Mac lovers distain?  hoiatl | 05/26/06
sperior???  Cat Ketch | 05/24/06
WinFX file system  hoiatl | 05/26/06
Who will pay for an OS requiring 1GB RAM and 15GB disk space?!  HypnoToad72 | 05/26/06
I would say the trouble is more for  Linux User 147560 | 05/10/06
Not just Microsoft  dberlind | 05/10/06
David, I agree with you in this.  No_Ax_to_Grind | 05/10/06
Nothing to do with hardware  Yagotta B. Kidding | 05/10/06
Naw, works fine here.  No_Ax_to_Grind | 05/10/06
IF I have to use Windows...  Linux User 147560 | 05/10/06
Microsoft got security right?  hoiatl | 05/26/06
Report MS to the EC!  P. Douglas | 05/10/06
Report them to the EC?  hoiatl | 05/26/06
Best of all  Yagotta B. Kidding | 05/10/06
Oooh, so scary!  RocketEater | 05/11/06
Security and usability just do not go together well  mrjonno | 05/10/06
Users can remember passwords  MacGeek2121 | 05/10/06
Don't bet against history  RStiennon | 05/10/06
History doesn't account for change...  kckn4fun | 05/11/06
You missed the boat on this one, David!  iggy_e@... | 05/12/06
RE: Trouble ahead...  Protagonistic | 05/11/06
Focus may change, but the war isn't over  kkernes | 05/11/06
Beaten by whom?  znewt | 05/11/06
MS had two major security problems; now it has one  Langalibalene | 05/11/06
The unobtainable goal...  TaskMan! | 05/11/06
Ya Right! I Believe What I See  IceTheNet@... | 05/11/06
Strong Authentication - Not for Windows  realuserpaul | 05/11/06
To little to late  richdave | 05/11/06
Apple OSX is cheaper to secure  ralphrides | 05/12/06
Well, I guess this is the operational definition of "tatters". (NT)  MTMacPhee | 05/23/06
Bwaahaahaahaahaahaa!!!  Knorthern Knight | 05/28/06
I am certain the AV industry has nothing to worry about  michael_t | 05/30/06
Hackers, start your engines!  Userama | 05/31/06
Start your mouths.  xuniL_z | 09/22/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline