Updated: 24.11.2002; 15:38:19 Uhr.
disLEXia
lies, laws, legal research, crime and the internet
        

Friday, June 14, 2002

Microsoft Mistakenly Ships Nimda Worm with Software

Korean developers who recently received Microsoft's (Nasdaq: MSFT) Visual Studio .NET on CD got more than they bargained for: The software came complete with the highly infectious and persistent Nimda worm. [NewsFactor Cybercrime & Security]
22:27 # G!

Microsoft's Allchin: API disclosure may endanger U.S.

>From a 2002/05/13 article by Caron Carlson in eweek.com:

http://www.eweek.com/article/0,3658,s%253D701%2526a%253D26875,00.asp

"A senior Microsoft Corp. executive [Jim Allchin] told a federal court last week that sharing information with competitors could damage national security and even threaten the U.S. war effort in Afghanistan. He later acknowledged that some Microsoft code was so flawed it could not be safely disclosed."

and later, directly quoting Allchin...

"Computers, including many running Windows operating systems, are used throughout the United States Department of Defense and by the armed forces of the United States in Afghanistan and elsewhere."

Microsoft proposes to withhold details of the MSMQ protocol (TCP port 1801 and UDP port 3527), the Windows File Protection API, as well as APIs for anti-piracy protection and digital rights management under the security carve-out.

I recall that the Windows NT family of operating systems was designed to meet DOD's C2 security criteria, including the Orange Book (standalone, which they passed), as well as Red Book (networking) and Blue Book (subsystems) criteria which they started working on at least 4 years ago; I don't know if they've yet passed, but I suspect not if it's so flawed that they don't want to disclose the protocol or API! See http://msdn.microsoft.com/library/default.asp? url=/library/en- us/dnproasp2/html/windowsntsecuritysystems.asp

So, one risk of flawed software might be that you have to publicly invoke national security (read patriotism) as a last refuge from legal process.

[Active Quality Software via risks-digest Volume 22, Issue 13]
19:09 # G!


Maximillian Dornseif, 2002.
 
June 2002
Sun Mon Tue Wed Thu Fri Sat
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30            
May   Jul

Search


Subsections of this WebLog


Subscribe to "disLEXia" in Radio UserLand.

Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.