[Gllug] Re: M$ "Bounty"
Richard
richard at sheflug.co.uk
Fri Nov 7 12:27:09 UTC 2003
> > From a business perspective, it's also a very wise move on their part.
> > Good publicity, probably fewer worms to fight over the next few months...
>
> Okay, it might be some good PR on their part, but they're basically trying to
> fight the symptoms, not the cause. Their time would be better spent doing some
> code audits, and fixing (potential) vulnerabilities.
Reading this weeks edition of www.computing.co.uk on the table in front
of me ... and I quote ... interview by Juan Carlos Lopez Navarro..
page 05.. "Windows and Linux to go head-to-head...
Juan asks Bill what he thinks..
Juan: "What do you really think developers can do to really harden
their stance on security, and what is Micro$oft doing to help?
Bill: "You don't need perfect code to avoid security problems. There
are things we are doing to make code closer, in terms of appropriate
tools - for example, 'securiotics'."
If you put this up against the OpenBSD development model - for example
- you tend to think along the lines of M$ 'neuriotics' and neuroses
about fair competition rather than a proper development cycle.
<folds box and wanders away from Hyde Park corner in the direction of
Oxford Street>
--
Richard
--
Gllug mailing list - Gllug at linux.co.uk
http://list.ftech.net/mailman/listinfo/gllug
More information about the GLLUG
mailing list