Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Flaws threaten Microsoft
GlobalTechnology.com ^ | Friday, Nov. 7, 2003 | Associated Press

Posted on 11/08/2003 11:34:09 PM PST by zeugma

Flaws threaten Microsoft

SEATTLE — Microsoft Corp.'s offer this week of cash bounties for informants who help it collar virus-writers reflects more than just an escalation of the war on those who would exploit the dominant power in software.

The campaign reveals just how much of a threat to Microsoft's bottom line security flaws now represent.

When the Blaster worm hobbled hundreds of thousands of computers around the world in August — only the latest plague to exploit a flaw in Windows operating systems — it also hurt Microsoft's ability to book new contracts with corporate customers.

For the first time, it seemed, flaws in Microsoft's software were translating into flaws in the company's business model.

"It's now starting to move from being a problem that they used to hear anecdotally to a problem they can now measure the impact of," said Michael Cherry, an analyst with Directions on Microsoft, an independent research firm.

The cost of patching up Windows computers, for instance, is diverting money from tech budgets that might otherwise have been earmarked for new software contracts, he said.

In its latest quarterly results, Microsoft said revenue from multiyear contracts dropped $768-million (U.S.) from the previous quarter. The drop in so-called "deferred revenue" — money received for contracts that will be counted toward its earnings over time — was about $450-million lower than the company anticipated.

Some of that was due to overly optimistic projections, said chief financial officer John Connors. But another reason, he said, was that Microsoft's sales people were so busy helping corporate clients shore up their networks that they could not close new deals.

Even before the Blaster attack, security was gnawing at Microsoft's stature. It had been cited among the reasons that various government agencies in the United States and abroad have become more serious about adopting alternatives such as the open-source Linux operating system.

Security, simply put, is beginning to play a larger role in decisions about what software companies buy.

Boscov's department stores are in the process of switching from Microsoft software on many of its servers to Linux-based offerings provided by IBM Corp. Harry Roberts, chief information officer for Boscov's, a regional chain based in Reading, Pa., said cost was by far the biggest reason.

But the company also had been hit hard by the Nimda worm in 2001, causing about $50,000 in staff time to repair damage to the network, he said. "We do have a bad taste in our mouth."

Analysts say Microsoft's software is targeted most by hackers and virus writers because it is so prevalent. But that's of little consolation to customers angry about the persistent security concerns.

"When enterprises have these big problems, they're very leery," said John Pescatore, vice president for Internet security at the Gartner consulting firm. That wariness could prompt companies to delay software upgrades from every third to every fourth year, for example, a threat for Microsoft. "That's what kills software companies," he said.

After the Blaster attack, Microsoft issued bulletins for another five critical flaws in versions of Windows. And it was not the only Microsoft-centric Internet plague this year. The Slammer worm severely clogged on-line traffic in January.

Mr. Pescatore likened the recent problems to the situation two years ago, when the Code Red and Nimda viruses exploited flaws in Microsoft software. The network pain produced by the twin scourges prompted Microsoft chairman Bill Gates in January 2002 to identify security as the company's top priority.

Among the recent steps Microsoft has taken to improve security is its announcement that it will have a free update to its flagship Windows XP desktop operating system next year. The improvements are to include disabling certain features that can allow hacker break-ins. The upgrade, or service pack, will also include an improved firewall.

As it adjusts, the challenge for Microsoft has been to alter its mind-set — from an emphasis on winning new customers to the need to satisfy its now-huge existing customer base, said Joe Wilcox, an analyst with Jupiter Research.

"Microsoft needs to sit back and kind of rethink how to operate in more of a maintenance market," Mr. Wilcox said. "And what that really means is that customer satisfaction has to be the number one priority."



TOPICS: Business/Economy; News/Current Events; Technical
KEYWORDS: blaster; codered1; codered2; computersecurity; iloveyou; linux; melissa; microsoft; networksecurity; nimda; opensource; slammer; trojans; virus; viruses; worms
Navigation: use the links below to view more comments.
first 1-2021-4041-45 next last
...reveals just how much of a threat to Microsoft's bottom line security flaws now represent.

For the first time, it seemed, flaws in Microsoft's software were translating into flaws in the company's business model.

About time.

1 posted on 11/08/2003 11:34:09 PM PST by zeugma
[ Post Reply | Private Reply | View Replies]

To: rdb3
Penguin Ping Please
2 posted on 11/08/2003 11:34:55 PM PST by zeugma (If you eat a live toad first thing in the morning, nothing worse will happen all day.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
Considering Steve Ballmer's more recent remarks, I'm not about to take any claim of heightened security at Microsoft seriously...

See: http://www.freerepublic.com/focus/f-news/1002404/posts

See also:


3 posted on 11/08/2003 11:38:32 PM PST by Prime Choice (The judiciary is supposed to be 1/3rd of the checks and balances; not a special interest trump card.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
RedHat anyone????
4 posted on 11/08/2003 11:47:48 PM PST by clee1 (Where's the beef???)
[ Post Reply | Private Reply | To 1 | View Replies]

To: clee1
RedHat anyone????

Red Hat is about to become a lot more expensive.

5 posted on 11/08/2003 11:57:41 PM PST by HAL9000
[ Post Reply | Private Reply | To 4 | View Replies]

Comment #6 Removed by Moderator

To: Tim Dr Hook McCracken
Red Hat Drops Free Linux!

Uh, not exactly.

They're re-naming their free line to 'Fedora'.

And they're focusing their business on 'Enterprise-class' work. They obviously think they can compete with IBM, Sun and MS for a chunk of that market. It's a tactical choice, the same one made by IBM. It makes sense, for IBM, who makes most of their real money from hardware and software infrastructure.

I'm not sure I think it's a smart choice for Red Hat, but it is their choice.

And this once again underscores perhaps the biggest single reason to use Linux -- Linux will go on. If you're not happy with this, you can go with one of a dozen other distros.

If you were on a highly proprietary OS, like Solaris or Win2K3Server, and they made some move like this, you'd be screwed.

7 posted on 11/09/2003 12:35:48 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 6 | View Replies]

To: Dominic Harr
In a totalitaran environment you don't need to be afraid to make "mistakes"
8 posted on 11/09/2003 12:46:57 AM PST by Truth666
[ Post Reply | Private Reply | To 7 | View Replies]

To: Dominic Harr

The battle between Microsoft and freedom loving persons

1. Microsoft sells Windows with security holes that are not revealed
2. One of these security holes is exposed by a freedom loving person.
3. Microsoft makes no clear statement about which Windows versions are affected.
4. Microsoft orders an update.
5. This way Microsoft ensures that the exposed hole is closed and at the same time a few new holes are added.
6. Freedom loving persons start looking for holes from scratch.
9 posted on 11/09/2003 12:48:33 AM PST by Truth666
[ Post Reply | Private Reply | To 7 | View Replies]

To: Truth666
"2. One of these security holes is exposed by a freedom loving person"

You sound like one of these mentally deranged hackers that have created so many problems for so many for no reason at all. Get a life.

10 posted on 11/09/2003 1:24:11 AM PST by at bay (no deals, Jacquelyn, only choice of lobster, steak or chicken for last dinner party of one)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Truth666
Criminal behavior = Freedom.

You're a jerkoff.

11 posted on 11/09/2003 1:46:29 AM PST by freebilly
[ Post Reply | Private Reply | To 9 | View Replies]

To: Truth666
I know that you are simply a troll, but...

2. One of these security holes is exposed by a freedom loving person.

Do you vote Libertarian?

12 posted on 11/09/2003 5:00:36 AM PST by Dr Warmoose
[ Post Reply | Private Reply | To 9 | View Replies]

To: zeugma
bump
13 posted on 11/09/2003 5:25:03 AM PST by Chief_Joe (From where the sun now sits, I will fight on -FOREVER!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
Microsoft is itself responsible for this situation. They created an architecture which allows executable content to be placed on machines without the consent of the user. They papered it over with a transparently flawed content-signing model.

Microsoft has been negligent. By ignoring the obvious consequences of their decisions on customers, a court might find them to have been civilly or criminally negligent.

Why did it happen? Because Microsoft managers are in it for the money only, are short sighted, and are more concerned with surviving in the organization long enough to vest their stock options, than in being customer or even corporate advocates.

Who will suffer? Well, we all will. But ultimately, Microsoft will, and its preeminence will be lost.
14 posted on 11/09/2003 6:12:08 AM PST by Tax Government
[ Post Reply | Private Reply | To 1 | View Replies]

To: zeugma
I wish those Penguin Pings included apps. Much as I would love to switch to a different OS till there are real pro-music apps ready to use I just can't. Especially since win2003 server is so fast and solid...and no, I am NOT a M$ fan.
15 posted on 11/09/2003 6:17:14 AM PST by TheStickman
[ Post Reply | Private Reply | To 2 | View Replies]

To: Tax Government
The users are to blame.

People keep finding excuses not to migrate off Microsoft, like a battered wife sticking with her abusive husband.

If they do it much longer, Microsoft will find a way to force people to use their server software, and, while they can never really "kill" Linux, will minimize its impact.

Wake up people. This is the time to get off Microsoft, while the gettin' is good!

16 posted on 11/09/2003 6:31:55 AM PST by B Knotts (Go 'Nucks!)
[ Post Reply | Private Reply | To 14 | View Replies]

To: John Robinson; B Knotts; stainlessbanner; TechJunkYard; ShadowAce; Knitebane; AppyPappy; jae471; ...
The Penguin Ping.

Wanna be Penguified? Just holla!

Got root?

17 posted on 11/09/2003 8:11:07 AM PST by rdb3 (We're all gonna go, but I hate to go fast. Then again, it won't be fun to stick around and go last.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: zeugma
wariness could prompt companies to delay software upgrades from every third to every fourth year

That's what I expect. This effect will probably kick the serious revenue from Longhorn down the calendar another year or so. By the time Longhorn comes out, most of the Bad Stuff will have been wrung out of Windows 2003 server and the virus-writers will be finding it tougher to find new holes in it. The first few guys who put Longhorn out there will get whacked a few times, and everybody knows it. Most people will hang back and wait to see how many arrows in the back the pioneers get.

18 posted on 11/09/2003 11:07:56 AM PST by Nick Danger (With sufficient thrust, pigs fly just fine.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Dominic Harr
Uh, not exactly. They're re-naming their free line to 'Fedora'.

Rrrrrright, Harr. Fedora is going to end up like Mozilla. Tepid support. Not widely used.
19 posted on 11/09/2003 1:12:44 PM PST by Bush2000
[ Post Reply | Private Reply | To 7 | View Replies]

To: Bush2000
You always amaze me in how little you need to know before you feel the need to speak.


Red Hat is changing their classic distro into a community project. It will be closer to Debian now in that it is developed by the community for the community. It will feature the more cutting edge features and be where r&d occurs. The Linux enthusiast doesn't demand production stability.

That's where the Enterprise Red Hat distro comes in. Features are second in priority to stability, security, and support.

Updates for the Enterprise version will be tested and certified by Red Hat. The same patches will be made available for Fedora, but without warrenty.

Fedora is free. Technically, so is Enterprise. You can still download the packages. You can still copy the CDs and give them away legally.

But of course, you don't care.It's your agenda to bash Linux and you've done that. Run along now, Sparky.
20 posted on 11/09/2003 4:33:30 PM PST by shadowman99
[ Post Reply | Private Reply | To 19 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-45 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson