Topbar

ITWeb - The Technology News Site

LIMITED OFFER
Subscribe
to Brainstorm Magazine for R199.95 today and get 11 issues PLUS a FREE APC Biometric Password Manager (valued at over R450.00) absolutely FREE.
Click here.

back to the ITWeb home page Sales info
SEARCH 
BUSINESS
UCS cements deal with Cordys
ICT skills shortage to cost SA
more in business...  

advertisement


Loading...
FINANCIAL
RICA continues to hammer Vodacom
Datacentrix mulls shareholder deal
more in financial...  
COMPUTING
Blatter upbeat on 2010
Countdown to virtual classroom
more in computing...  
INTERNET
Social networks an attack vector
Chrome positioned for PC battle
more in internet...  
ENTERPRISE
Open Text supports standard
SolTech appoints director
more in enterprise...  
NETWORKING
Sizwe has African ambitions
Google cancels free airport WiFi
more in networking...  
TELECOMS
ICASA has political backing
ICASA was sidelined
more in telecoms...  
CHANNEL
Epson seeks new territories
Huawei appoints XON
more in channel...  

advertisement

Back to the Reuters Home Page 1 April 2003 
Ĺ  Reuters
IT experts do not trust Microsoft - report
BY REUTERS
[Seattle | Reuters News Service, 1 April 2003] - Three-quarters of computer software security experts at major companies surveyed by Forrester Research do not think Microsoft's products are secure, the technology research company said yesterday.

While 77% of respondents in the IT field said security was a top concern when using Windows, 89% still use the software for sensitive applications, Cambridge, Massachusetts-based Forrester said in a report titled, "Can Microsoft Be Secure?"

The survey polled 35 software security experts at $1 billion companies.

Forrester analyst Laura Koetzle said: "Too few firms are taking responsibility for securing their Windows systems."

Koetzle said 40% of firms were not planning to make security improvements themselves and only 59% of those who suffered security attacks had made changes to the way they use Microsoft software.

Microsoft, the world's largest software-maker, launched a company-wide initiative over a year ago to make its software more secure and trustworthy in the face of attacks that targeted the vulnerability and wide reach of its software.

"We understand that achieving the goals of Trustworthy Computing will not be an easy task and it will take several years, perhaps a decade or more before systems are trusted the way we envision," a Microsoft spokesman said in response to the report.

"We are working to address existing security concerns, including patch management... This is only the beginning and we are confident that customers will continue to see additional progress over time."

In the most dramatic incidents, such as the Nimda and SQL Slammer worms that exploited holes in Microsoft software, patches were available from the Redmond, Washington-based company well before the attacks happened. In many cases, however, the patches were not implemented by system administrators and engineers.

Koetzle noted that while Microsoft's patches for the last nine high-profile Windows security holes predated such attacks by an average of 305 days, too few customers applied the fixes because "administrators lacked both the confidence that a patch won't bring down a production system and the tools and time to validate Microsoft's avalanche of patches".

Microsoft argues that it is doing a better job of informing customers about security holes in its software, but many customers are questioning the amount of work needed to implement additional patches and fixes to Microsoft's software.

When the SQL Slammer worm, which slowed Web traffic worldwide and shut down automatic teller machines across the US, hit in January, Microsoft had already provided a security patch that the worm targeted in July 2002.

But because the patch was difficult to install, Microsoft scrambled to create an installation program that would make it easier for companies to implement the patch.

"Microsoft must develop new simple, consistent tools for applying patches and mitigating security platform risks," Koetzle said.

Koetzle also said that IT professionals should work more closely with Microsoft and companies that write software for Windows to make sure computer systems are more secure, instead of blaming Microsoft for security breaches.

  MORE SOFTWARE NEWS
   MOST POPULAR
  MTN, Neotel boost national capacity
  Neotel network takes a knock
  Fifa careful on Satyam troubles
 Reuters News Service
Copyright 2003 Reuters Limited. All rights reserved. Republication and redistribution of Reuters content is expressly prohibited without the prior written consent of Reuters. Reuters shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

Quick Print
Send to a friend
Send to a cell phone
Personal Archive

Register | Learn more...
Latest Blogs:
TownBoy
TownBoy-“Mobile Mumbles - Part 2”(Weapons of Mobile Destruction
Bullfrog
I am bestowed by the ironies of my life.....
jelo
The OpenSource Hoohah
www.blogit.co.za
Give us feedback

ITWeb BI 2010 Conference

ITWeb BI 2010 Summit
23 - 25 February 2010 | The Forum, Bryanston
Booking fee:
R4 155.00 (excl VAT)
ITWeb’s annual BI conference is the meeting place for anyone in BI. Hear from international decision management expert James Taylor, plus 8 case studies, including FNB, Standard Bank, Shoprite and SARS.

Don't miss out on THE annual meeting place for all those involved in the BI space. Secure your place today!

Diamond sponsor

Platinum sponsor

to the top of this page

Copyright (c) 1996 - 2010 ITWeb Limited. All rights reserved.

Would you like to see your news here? Contact us for more details at itnews@itweb.co.za

Striata Rackspace Sophos BBG Technologies