Governments to see Windows code

By Stephen Shankland
15 January 2003 02:50 PM
Tags: windows, code, source, court, microsoft, government, source code, linux
Microsoft will share the source code underlying its Windows operating system with several international governments, a move designed to address concerns about the security of the OS.

The Redmond, Washington-based software giant, which dominates the market for desktop software, has signed deals or expects to shortly with 10 countries and organisations, Salah DanDan, worldwide GSP manager, said in an interview.

"The GSP is the global initiative announced today that seeks to provide governments with access to source code and information that governments need to be confident in the security of the Microsoft platform," DanDan said.

Under the program, DanDan said, governments will be able to see source code for Windows 2000, XP, Server 2003 and CE; use that code to build those versions of Windows; see Microsoft security documentation the company doesn't otherwise share; visit Microsoft's headquarters; talk to Microsoft developers; and perform their own tests on the code.

Microsoft has criticised the open-source movement, the philosophy behind Linux and several other projects that compete with Microsoft software. But one advantage the open-source community has over Microsoft is that suspicious parties may see exactly what's going on in the software it produces.

"Certainly they want to reduce the possible reasons people are looking at Linux," said Gartner analyst Michael Silver. "It sounds like another attempt by Microsoft to appear to be a bit more open."

Microsoft acknowledges that the availability of other products' source code can "drive interest" in seeing Microsoft's code. Microsoft hopes to outdo open-source efforts by showing those governments how to use the source code once they have it, the company said.

Countries could use help poring through the millions of lines of source code, but Silver believes Microsoft clearly has a broader agenda in mind. "It's very political in nature," he said of the program.

The source code program could help "appease a country like China that there are no back doors..." Silver said, referring to secret entrances by which an outsider can take over a computer or retrieve information from it.

China is one of about 60 countries eligible for the program, DanDan said, declining to state whether it was a participant.

Microsoft is working hard to court Chinese buyers and the Chinese government, walking a fine line between coaxing the Chinese to crack down on piracy while not driving potential customers into the arms of companies such as Red Flag Linux.

Security problems have plagued Microsoft to the point where Gartner has recommended against using some packages. Providing access to Microsoft programmers could allay concerns that there are other, undisclosed vulnerabilities lurking within the secret confines of the Windows source code.

The Government Security Program was the brainchild of Craig Mundie, Microsoft's chief technical officer of advanced strategies and policy, who was responding to government requests for more information access, DanDan said.

"This program is a personal project of Craig Mundie. It's something he has worked on for the last few years," DanDan said. As Mundie has been "in contact with government officials around the world, he had several conversations in which the need to have greater access and visibility into Microsoft code came up."

Mundie has been the most visible executive in Microsoft's debate against open-source software, under which programmers are free to see, modify and redistribute source code. Among other things, he called the approach unhealthy.

Microsoft began approaching countries about the project in late summer, DanDan said.

DanDan wouldn't say what concerns governments hoped to address, beyond the general category of security. "If you get more information about the workings of Microsoft Windows, you can make your own determination about how secure the windows platform is," DanDan said.

While Linux's openness has pressured Microsoft, there are many other factors involved in a decision about what software to use.

Becoming more open is only one issue Microsoft must deal with in warding off the Linux competitive threat. "There are lots of reasons that governments have started lining up behind Linux, and security and openness and (fear of) back doors is only a portion of," Gartner's Silver said. "There still monetary issues."

Linux and open-source software has encroached on Microsoft in Peru and Germany, among other countries.

In addition to Linux, perpetual Microsoft rival Sun Microsystems been giving governments free copies of its StarOffice software, a competitor to Microsoft Office based on the open-source OpenOffice project. Recipients include China, Taiwan, Chile and Hong Kong.

Under a different program called the Shared Source Initiative, Microsoft already shares Windows source code with governments and companies. Partners in that program include several branches of the US government, including the State Department; Austria; Sweden; and Switzerland, said Jason Matusow, the program's manager, in an earlier interview.

"There is a reality that having source code does have benefits for some organisations," Matusow said.

The Shared Source Initiative is available to about half the countries who are eligible for the Government Security Program, DanDan said.

Advertisement

Talkback 2 comments

    Too little, too late. Will the ...Anonymous -- 15/01/03

    Too little, too late. Will they stop locking you into upgrades? Nope. Will they stop having really crappy storage formats? Nope. Will they forgoe profit for progress? Sh*t no!
    Enough of the billion dollar monopoly. Let the industry move forward without the king parasite!

    Some initial thoughts of a pos ...Con Zymaris -- 17/01/03

    Some initial thoughts of a possible question-set posed by an interested
    government rep to Microsoft:

    1) How do we (the customer) know that what you present to us is the same source code you build as binaries?

    2) How do we know that the 3% you are hiding, doesn't in fact house possible back-doors and trojans? Having us visit and view it at your
    offices will not really provide the necessary time with the code to analyse it properly.

    3) Can we build (i.e make) the source code into executable binaries, so we can verify what you claim?

    4) With Open Ssource Software, we may not have the technical wherewithal to understand the complexities of the code, but we know that thousands of security experts worldwide are reviewing all the source code. Will you make Windows code available to them too, so that they may alert us of possible breaches, trojans backdoors and other breaches?

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Jacquelyn Holt G'Day USA: Aussie start-ups head to America
    The G'Day USA: Australia Week campaign today announced the finalists for the Innovation Shoot Out event, which will see eight Australian technology start-ups travel to San Francisco in January 2010 to demonstrate the commercial viability of their products in the US.
  • Array All I want for Xmas is Telstra pricing
    Five consecutive days without broadband has led me to what seemed at the time to be an act of desperation: contemplating signing up for Telstra's 100Mbps cable modem service.
  • Array Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • More blogs »

Tags

Back to top

Featured