Re: [LINK] Let's Sue Microsoft [Was: Code Red puts Microsoft in hot seat]

From: Adam Todd (at@ah.net)
Date: Tue Aug 07 2001 - 00:40:27 EST


>While perhaps Microsoft could and should do more to clue these people up
>or make it harder for them to deploy every bit of software by default
>without thinking about it, I don't think this cluelessness is
>Microsoft's fault.

I can think of a zillion analogies to argue this point. But then, it comes
back to the opposite, if we legislate against Football because a kid gets a
spinal injury, then next week we'll legislate you can't have a back yard
pool because a kid drowns, then we'll legislate you can't have a computer
because you might get an electric shock ...

However, I do feel the Microsoft has let itself down by trying to create
software that is far more complex on the most incorrect platform to develop
it upon. If Microsoft were to work with Industry, rather than try and
create proprietary solutions, then such problems are less likely to occur.

I can only IMAGINE what might have happened if I were to detail publicly
the RedHat bug I copped so much flakt from so few individual last
year. It was thanks to the advice form the MANY to keep my mouth shut
that RedHat itself still exists as a product today. How long until the
exploit is found is something I can't guess, and no doubt when people drop
their ego (Microsoft included) and start working together rather than
hamming each other in the corner, these exploit problems will cease to be
problems.

There has been discussion about creating a "counter-worm" for the CodeRed
work that actually goes back to the exploited server and removes CodeRed,
blocks the hole and issues itself to the next server to try and exploit
it. I'm not sure where the development for this yet yet.

On Friday PM I had <3000 attempts. By 9AM this morning I had 11,000. Just
now I have 18744.

Interesting.

Maybe if I get time I'll break it down by hour :)



This archive was generated by hypermail 2.1.1 : Fri Aug 31 2001 - 03:10:03 EST