Microsoft: Behind the firewall

By Fran Foo
09 December 2003 05:00 PM
Tags: linux, windows, flaw, unix, open-source, european union, open source, microsoft
COMMENTARY--In an unprecedented move, software giant Microsoft released a technical white paper last month entitled "Security at Microsoft". The 27-page document broadly describes how malicious or unauthorised use of digital assets is prevented within the organisation.

It also reveals the workings of its Operations and Technology Group (OTG), which is responsible for managing IT security for more than 55,000 employees and around 300,000 computers located over 400 sites.

The paper disclosed some interesting facts:

  • Per day, four million messages are exchanged internally and approximately eight million messages externally.
  • More than 65,000 workers worldwide have remote access to corporate e-mail accounts, files and network resources through direct dial or VPN (virtual private network) and the OTG manages 250,000 remote access connections each week.
  • A two-factor user authentication is implemented to counter any attacks during remote connections, including the use of smart cards.
  • Computer Associates' eTrust is used on all desktop computers and fully managed servers, except gateways which run on Trend Micro's InterScan Viruswall and Brightmail software.
  • On a daily basis, approximately 2.4 million unsolicited e-mail messages are filtered with an average of 800 viruses stripped.
  • Microsoft experiences around 100,000 intrusion attempts each month.
  • Over 125,000 virus-infected e-mail messages are scanned and quarantined monthly.

    The last part of the paper launches into some mindless dribble about how the OTG is central to "silently installing patches on desktops and servers" and the admission on Microsoft's part that it "regularly releases patches to correct vulnerabilities in operating system and user applications."

    In fact, in an interview published by ZDNet Australia last month, a senior Microsoft executive admitted that "it's been a fairly painful year from a security standpoint...there have been more patches than we would have liked."

    This week, Microsoft could start testing a CD designed to allow users of older Windows systems to update their PCs in a "simplified" fashion. This product has the potential to ensure that computers are duly patched whenever a vulnerability is detected.

    The white paper and CD are decent marketing tools to elevate Microsoft's security standing but this doesn't negate the fact that the crux of the matter is its malformed software.

    The competitive landscape will only intensify. Afterall, open-source groups, for instance, are here to stay. Sure, time-to-market pressures are part and parcel of the business world but if Microsoft persists on delivering [more] sub-standard products, and producing documents with empty rhetoric, in time, the cracks will get bigger and it might be too late to defend itself.

    In the US, Sun Microsystems is speaking to Walmart and Office Depot to sell computers installed with Java Desktop System. If K-mart and Harvey Norman start selling similar PCs in Australia, will this put a huge dent in Microsoft's market share? Send your comments to itmanager@zdnet.com.au.

  • Advertisement

    Talkback 0 comments

    Sponsored content

    Power Centre - Content from our premier sponsors

    Blogs

    • Phil Dobbie Is wholesale-only backhaul just a pipedream?
      The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
    • Array Get extensions going in Firefox, redux
      Previously on Null Pointer we looked at getting extensions working in Firefox betas, and that was great until the fine folks at Firefox changed their minds.
    • Array How reliable is IP telephony?
      Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
    • More blogs »

    Tags

    Back to top

    Featured