Skip Navigation

Life After Government
The latest on retirement issues

News Feeds

Online Directories
Browse for FREE, download vCards, and create customized mailing lists:
The Federal Technology Source: 3,000 of the most influential people in federal information technology.
The Chiefs Directory: 500 chief finance, information technology, procurement and personnel officers.


« Another Verification Lesson | Main | N.H. Says Real ID 'Repugnant' »

05:44 PM ET

The Chink in OMB's Windows Mandate

When the Office of Management and Budget issued a mandate Tuesday that forces agencies to use a standard configuration of the Windows operating system, its main goal was to improve information security within government. The theory is that OMB, by way of the Department of Homeland Security, can send out mass security patches for newly found vulnerabilities that agencies then can quickly apply, securing systems en masse.

But some critics say this strategy may not significantly improve security.

The problem is the inherent insecurity of Windows operating systems. Microsoft's new operating system Vista is supposed to be more secure, but it has its security problems. That is why the market for anti-virus software, intrusion detection systems and firewalls is so huge, says Eugene Spafford, a professor and executive director of the Purdue University Center for Education and Research in Information Assurance.

Moreover, Ben Fathi, the former head of Microsoft's security group and now the chief of development in the Windows core operating system group, said at the RSA Conference 2007 in San Francisco last month that if Vista had half the security vulnerabilities that Windows XP had, he would consider Vista reaching a "great goal."

"In the first year after Windows XP debuted in October 2001, Microsoft posted 30 security bulletins pegged to the Home version of the then-new operating system," with more than one vulnerability sometimes appearing in a single bulletin, ComputerWorld reported last month.

In a discussion of security experts appearing in the same ComputerWorld article, Graham Cluley, senior technology consultant for Sophos PLC, said:

[I]n the last five years, the number of hackers and researchers who are examining Microsoft's code for vulnerabilities with ever greater intensity has increased. Furthermore, we have seen a number of legitimate security companies (including some who may have a vested interest in debunking Microsoft's status as a security player) put efforts into finding flaws in Microsoft's code.

What isn't in doubt is that there will continue to be flaws found in Microsoft Vista.

Curt Kolcun, vice president at Microsoft Federal, said that agencies are looking to migrate to VISTA due to its improved security features. Agencies are looking to move "in a planned way," Kolcun says. "They'll slipstream this into their build process."

Kolcun estimates 50 percent of the government will move to VISTA by the end of calendar year 2008.

Do you think OMB's mandate will make government IT systems measurably more secure or is Microsoft's Windows platforms too vulnerable? Click on the "Comments" link below to let us know.

By Daniel Pulliam at Link | Comments (2)

Comments

I fear that the OMB Windows mandate is a grave mistake. Windows has been, and by all indications will continue to be, very insecure. Better to permit some experimentation with alternative operating systems, which also avoids the "putting all your eggs in one basket" problem.

Alan Paller and others have said for years that configuration management was one of the great overlooked security vulnerabilities. But a secure Windows configuration is simply impossible, if users are to do anything other than data entry on preformatted screens. Too many Windows functions require admin privileges.

Oh, and the idea that getting patches from DHS is better than getting them from Microsoft is simply laughable.

The self-delusion continues.

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)




©2007 by National Journal Group Inc. All rights reserved.