Mundie talks about Trustworthy Computing one year on
IDG News Service - MOUNTAIN VIEW, Calif. -- A year ago last week, Microsoft Corp.'s chief technical officer, Craig Mundie, gave a presentation at the company's Silicon Valley campus that served as the public unveiling of a widespread initiative to improve the security and reliability of Microsoft's products.
Mundie returned to the same stage yesterday to give an update on how well the company is achieving its goals one year on. His conclusion: A world of Trustworthy Computing, as the effort is called, is still a long way off.
Hackers and security holes are getting ever more sophisticated, networks are becoming always-on and more pervasive. At the root of the problem, Microsoft laments, is that both consumers and business users are stuck in Microsoft's past, running operating systems that date back to earlier days of the Internet.
"We're dragging around behind us a giant tail of systems that were, of course, built and deployed a long time ago," Mundie said, referring to research data from IDC that shows that most of its customers have yet to adopt Microsoft's more recent and better-fortified operating systems, Windows 2000 and Windows XP.
"In practice, it's impossible for us to remediate the threats that are possible in systems that were built in 1991, deployed in 1995 and still in use today," said Mundie, speaking at one of the company's monthly speaker series events here.
The same advice that Mundie offered here last year during his presentation at the Trustworthy Computing Conference is, upgrade, upgrade, and upgrade.
In the past year, Microsoft has enacted a new business licensing plan that aims to get companies to follow its advice (see story). The Software Assurance plan requires companies to pay software licensing fees each year in order to receive all of Microsoft's latest software and security updates. The plan is that customers will always run the current operating system, ensuring that they are always as secure as can be. The company has also pushed its Windows Update technology on consumers and businesses, which allows Microsoft to automatically deploy security patches and feature updates to customers when they become available.
Microsoft's fear is that customers could lose faith in computers due to the host of security breaches that gain public attention. That fear led to a widely circulated memo from Bill Gates, the company's chairman and chief software architect, about Trustworthy Computing, as well as a tab of $100 million and growing to cover security training for Microsoft developers and to rearchitect its operating systems.
"The concern that has emerged is, will



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts