July 21, 2003 (Computerworld) --
The fact that the U.S. Department of Homeland Security awarded Microsoft Corp. a $90 million enterprise software deal two days after Bill Gates met with DHS Secretary Tom Ridge in Washington is more than sheer coincidence. It's now a major security headache for a mammoth new agency that security experts say lacks the wherewithal to have considered alternative sources for its software. On June 25, Gates met with Ridge and other leaders on Capitol Hill. And on June 27, the DHS signed a contract with the company for server and desktop software for approximately 140,000 users. The DHS described the contract as a critical step in the department's efforts to establish a common computing environment for its 22 formerly independent agencies. But with the discovery last week of a critical security flaw affecting nearly every version of the Windows operating system -- including Windows Server 2003 (see story), the first product to be sold under Microsoft's so-called Trustworthy Computing initiative -- some security experts are warning that the DHS may have backed itself into a security quagmire. Options Were Open "They had a choice, but it would have been costly and time-consuming," said Roger Cressey, former chief of staff of the President's Critical Infrastructure Protection Board. "The real alternative was to go open-source. But for 22 agencies, an overwhelming majority of which use nothing but Microsoft operating systems, to convert to another platform in an efficient and cost-effective manner would have been hard to accomplish," said Cressey. "DHS has neither the time, the money, nor the flexibility for that. Now it is held hostage to the imperfections of Microsoft code-writing." DHS CIO Steve Cooper, who's leading the massive integration effort, didn't return Computerworld's calls seeking comment. Microsoft spokesman Keith Hodson said no software has yet been shipped to the DHS under the recent contract, so the department will receive software with the necessary patches. Hodson also said that as recently as Friday, the DHS reaffirmed its confidence in Microsoft's ability to handle any security problems that arise. A former senior Microsoft executive who spoke on condition of anonymity said he has "yet to find someone who's come up with a definitive, unbiased white paper on the pros and cons of relying on a single software vendor" for all or most of an organization's IT infrastructure. Rafael Nunez, a former hacker now employed as a security expert at Scientech Inc. in Gaithersburg, Md., said that although standardizing on a single software platform makes it easier for hackers to penetrate different parts of an enterprise, the DHS would have been far less secure had it deployed open-source software. "There's a reason thegovernment doesn't buy open-source software," said Nunez. "They don't buy it because they know that every hacker and software cracker can study the code for exploits."
DHS had little choice but to sign Microsoft deal, despite security flaws
"In Friday's IT Blogwatch, Richi Jennings watches VCs advise their startup companies to hunker down for a bad recession. Not..."
Read more...
"In Thursday's IT Blogwatch, Richi Jennings watches Sarah Palin's alleged email nemesis be indicted, arraigned, released, and fed to the..."
Read more... Read more Government & Regulation posts or See all Blogs
One positive development stemming from the collapse of Wall Street may be a boost in interest in computer science and IT careers among students who were previously interested in financial services jobs.
Computerworld Executive Briefing: The Compliance Era
Get this briefing free (a $195 value), for a limited time, courtesy of VeriSign. The new Computerworld report, The Compliance Era, explains why regulatory compliance has zoomed to the top of the IT agenda and shows how real-world IT executives are dealing with the storage, security and privacy challenges. Get this briefing free (a $195 value), for a limited time, courtesy of VeriSign. Download this executive briefing
Using a High-Performance Network Backbone to Meet the Requirements of the Modern Government Data Center
Download this white paper today! (Source: Juniper) This informative white paper offers insights into the latest trends, challenges, best practices and leading technologies that drive today's public agency data center network. It also reviews steps for implementing a framework that can mitigate risk and support the modern consolidated data center - efficiently and cost effectively. Download this white paper
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center Register for this complimentary webcast today! Go to the webcast
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Eliminate SPAM, Gain Productivity Learn all about the dangers and the costs of spam in all its forms – from stock-touting to spreadsheet. Also, understand the drawbacks of traditional hardware- and software-based defenses – and the unique benefits of MessageLabs multi-layered, managed Anti-Spam solution; as illustrated by a real-world case study where MessageLabs stopped spam cold.
Download this white paper now! See more Whitepapers
As the volume of information inside enterprises explodes, most executives recognize the importance of a Google-like search solution for business content. To this end, Google has developed Universal Search for Business, powered by the Google Search Appliance, which searches all enterprise content through one secure box. Attend this webinar to learn how your business can benefit from universal search capabilities.