Computerworld
Quick Menu
Search



Ads by TechWords

See your link here


Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

DHS had little choice but to sign Microsoft deal, despite security flaws

Lack of money, time and flexibility may have been factors in the decision
 

Sign up to receive Government Resource Alerts

July 21, 2003 (Computerworld) -- The fact that the U.S. Department of Homeland Security awarded Microsoft Corp. a $90 million enterprise software deal two days after Bill Gates met with DHS Secretary Tom Ridge in Washington is more than sheer coincidence.
It's now a major security headache for a mammoth new agency that security experts say lacks the wherewithal to have considered alternative sources for its software.
On June 25, Gates met with Ridge and other leaders on Capitol Hill. And on June 27, the DHS signed a contract with the company for server and desktop software for approximately 140,000 users. The DHS described the contract as a critical step in the department's efforts to establish a common computing environment for its 22 formerly independent agencies.
But with the discovery last week of a critical security flaw affecting nearly every version of the Windows operating system -- including Windows Server 2003 (see story), the first product to be sold under Microsoft's so-called Trustworthy Computing initiative -- some security experts are warning that the DHS may have backed itself into a security quagmire.
Options Were Open
"They had a choice, but it would have been costly and time-consuming," said Roger Cressey, former chief of staff of the President's Critical Infrastructure Protection Board.
"The real alternative was to go open-source. But for 22 agencies, an overwhelming majority of which use nothing but Microsoft operating systems, to convert to another platform in an efficient and cost-effective manner would have been hard to accomplish," said Cressey. "DHS has neither the time, the money, nor the flexibility for that. Now it is held hostage to the imperfections of Microsoft code-writing."
DHS CIO Steve Cooper, who's leading the massive integration effort, didn't return Computerworld's calls seeking comment.
Microsoft spokesman Keith Hodson said no software has yet been shipped to the DHS under the recent contract, so the department will receive software with the necessary patches. Hodson also said that as recently as Friday, the DHS reaffirmed its confidence in Microsoft's ability to handle any security problems that arise.
A former senior Microsoft executive who spoke on condition of anonymity said he has "yet to find someone who's come up with a definitive, unbiased white paper on the pros and cons of relying on a single software vendor" for all or most of an organization's IT infrastructure.
Rafael Nunez, a former hacker now employed as a security expert at Scientech Inc. in Gaithersburg, Md., said that although standardizing on a single software platform makes it easier for hackers to penetrate different parts of an enterprise, the DHS would have been far less secure had it deployed open-source software.
"There's a reason thegovernment doesn't buy open-source software," said Nunez. "They don't buy it because they know that every hacker and software cracker can study the code for exploits."




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
Private-sector IT execs see diminished cybersecurity role
DHS had little choice but to sign Microsoft deal, despite security flaws
"In Friday's IT Blogwatch, Richi Jennings watches VCs advise their startup companies to hunker down for a bad recession. Not..." Read more...
"In Thursday's IT Blogwatch, Richi Jennings watches Sarah Palin's alleged email nemesis be indicted, arraigned, released, and fed to the..." Read more...
Read more Government & Regulation posts or See all Blogs
Feds considering changes to H-1B application process in wake of report
Exploit code loose for six-month-old Windows bug
With market meltdown, which tech firms become predator or prey?
More top stories...
The Grill: Privacy is a thing of the past, says private investigator
Report: World Bank servers breached repeatedly
Apple asks judge to make iPhone lawsuit moot
Too much junk food, too little exercise and a 24/7 tether to technology? Your body ain't happy, friend. Let us count the pains.
Instruments on the surface of Mars have detected falling snow that is likely evaporating before it reaches the planet.
One positive development stemming from the collapse of Wall Street may be a boost in interest in computer science and IT careers among students who were previously interested in financial services jobs.
Getting new software installed on Linux doesn't have to be hard, but it can differ depending on what you're installing.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
The File Data Management Zone
Security Management Zone
The SAS Zone
Business Intelligence and Analytics Zone
Windows Protection Zone
The Enterprise Search Zone
Software as a Service Zone
The Security Zone

Ads by TechWords

See your link here
Computerworld Executive Briefing: The Compliance Era
Get this briefing free (a $195 value), for a limited time, courtesy of VeriSign.
The new Computerworld report, The Compliance Era, explains why regulatory compliance has zoomed to the top of the IT agenda and shows how real-world IT executives are dealing with the storage, security and privacy challenges. Get this briefing free (a $195 value), for a limited time, courtesy of VeriSign.
Download this executive briefing download
Using a High-Performance Network Backbone to Meet the Requirements of the Modern Government Data Center
Download this white paper today!
(Source: Juniper) This informative white paper offers insights into the latest trends, challenges, best practices and leading technologies that drive today's public agency data center network. It also reviews steps for implementing a framework that can mitigate risk and support the modern consolidated data center - efficiently and cost effectively.
Download this white paper go
From Laggard to Leader: Transforming the Data Center
From Laggard to Leader: Transforming the Data Center
Register for this complimentary webcast today!
Go to the webcast 
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Business Transaction Management: Facilitating the Management of Virtual Environments
Quick Sizing Guide for SAS Grid Running on HP BladeSystems and EVA Storage
Prudential Financial protects its brand with Symantec Data Loss Prevention solutions
View more whitepapers