Scott Charney: Microsoft's security chief reveals all

Shortly after the 9/11 bombings, Microsoft hired Scott Charney, a federal prosecutor for the US justice Department, to head up its Trustworthy Computing division. At AusCERT 2008, ZDNet.com.au caught up with Charney to hear his thoughts on how those events changed the security landscape and what he thinks about the current state of IT security.

The Trustworthy Computing division's sole task was to ensure that Microsoft made security the highest priority when developing products.

Scott Charney, VP of Microsoft's Trustworthy Computing Group

Charney was an interesting choice for Microsoft. In his role as lead federal prosecutor for the US Department of Justice's criminal division, he worked on every major hacking case in the United States between 1991 and 1999.

The first real evidence that Microsoft had changed its ways came with the release of Windows XP Service Pack 2, which contained an improved firewall, had auto-update turned on by default and consolidated security controls into a single "security centre". According to Microsoft, the update made Windows XP 15 times safer.

In this exclusive eight-part video interview, Charney discusses Microsoft's current approach to security, what challenges lie ahead and what has gone wrong in the past.

Advertisement

Talkback 4 comments

    Mwahahhahaaaaa...........Anonymous -- 27/05/08

    Microsoft.....security....microsoft ?...security ????

    Mwahahahhahahhahahaaaa.....!!!!!!!

    *wipes eyes*

    Ahhhhhhh........... thanks, I needed that.

    And everyone else is to blame.Anonymous -- 27/05/08

    So it's the users and the applications that are the problem, not the shoddy OS they use or run on.
    It's all so clear to me now!
    So this means they're finally throwing in the towel and now not even bothering to try and defend their products, they're just going to try and shift the blame elsewhere.
    'Yes Your Honour, it was the victims fault. If he hadn't have walked down that dark alleyway with that money then none of this would ever have happened. My client is blameless"

    Oh, why did they put a lawyer in this position anyway? Surely someone with a clue about the issues would have been more appropriate? Having said that, I think his job is the most unenviable in the Redmond structure, that and chair replacement guy for Ballmer.

    hear hearAnonymous -- 27/05/08 (in reply to #320102713)

    good call Anon.

    MS Security - via Xenix!Bill Caelli -- 27/05/08

    Ahh!! History and total amnesia at Microsoft.

    In the 1980s to the 1990s Microsoft sold - wait for it - its own version of UNIX - named "Xenix" - still a trademark of Microsoft - and - more - it was largely used for internal systems at Microsoft at the time!

    Now - guess what - that same Xenix became "Trusted XENIX" via a company called "Trusted Information Systems (TIS)" in the USA and it received a very high security "rating" of B2. John Ulett was the MS marketing manager for many years.

    Then - of course - there was MS "Palladium", renamed NGSCB - Next Generation Secure Computing Base - project . What happened ??

    No application can be any more secure than the operating system it runs upon... and that is the truth that Scott has to start admitting - and MS to start fixing! Yes - NGSCB gave us some direction with its "Nexus" trusted computing base direction. It should have been IN VISTA - now!

    After all - we should well and truly be operating in some form of "Flexible Mandatory Access Control or FMAC" by now - the direction that SELinux and SUN's Solaris 10 are both moving into - with availability NOW.

Add your opinion


Latest Videos

Blogs

  • David Braue Will Rudd's bush backhaul bonanza deliver?
    Rural areas will be welcoming the government's decision to put its money where its politicising is, funnelling $250m into a regional fibre upgrade to six rural centres. Remedying over a decade of near-neglect at the hands of telecoms privatisation, the investment could be the firmest step yet for Labor's NBN dream — but with inevitable political questions and a looming election, Rudd and Conroy need to deliver, and quickly, to preserve the NBN's credibility.
  • Array Doing for AV what VoIP did for telephony
    Sydney-based start-up Audinate is making traditional analog cabling obsolete in favour of TCP/IP-based networking technology. And it's doing a pretty good job so far, with its technology used by World Youth Day and the Sydney Opera House.
  • Array WiMax in Australia: Part two
    WiMax could be the standard that drives the next phase of mobile broadband, it provides an opportunity for players wanting to establish a pure IP network to carry voice and data effectively — but is this what operators want?
  • More blogs »

Tags

Back to top

Featured