
Subscribe to
Computerworld November 26, 2001 (Computerworld) -- This Wednesday marks Day 30 since the Nimda.e worm showed up on the Internet. Microsoft and a few of its security cronies would have us believe that 30 days is about the right amount of time for everyone to shut up about any particular security vulnerability. The idea, floated by the group after Microsoft's Trusted Computing Forum this month, is that the IT industry should agree on a "grace period," during which the affected software vendor can fix the problem and issue patches without worrying about information on the vulnerability leaking out. After all, what could happen in 30 days?
Well, at the U.S. District Court for the Southern District of Florida, 30 days is long enough to turn the clock back 30 years.
Two days after it was discovered in the wild, Nimda.E hit the court's offices in Miami. By the following Monday - Day 8 - PCs were crashing left and right.
On Day 10, the court reverted to doing everything the old-fashioned, noncomputerized way. It might have been 1971 instead of 2001. Forms were filled out by hand, and clerks used phones instead of networks to get information on defendants and cases in other cities.
By Day 15 - halfway through the 30-day "grace period" - the court's Web site still was not back up, and IT staffers were still cleaning Nimda.E off PCs one at a time.
Oh yeah, keeping a lid on a security problem for 30 days - that'll sure protect us.
But it's not intended to protect us, is it?
Microsoft has a problem, and nobody in Redmond doubts it. Hardly a week goes by without some Microsoft product - Web browser, Web server, office application, e-mail client, operating system - hitting the news because it has a security vulnerability.
But the 30-day gag rule that Microsoft and its tame security partners are proposing won't reduce the risk for the users of those products. It will just reduce the risk to Microsoft's reputation from the weekly public relations problems.
That 30 days isn't just for coming up with a patch. It's an entire month to spin the bad news.
No wonder Microsoft wants the whole industry to take the 30-day pledge. The company with the security problem gets to tell its version of the story publicly when it issues its patch. Competitors promise to keep their mouths shut for a month after it's discovered.
Meanwhile, nobody is suggesting that crackers will observe any 30-day moratorium after they discover a security hole. Of course they won't - no matter how nicely Microsoft asks them. They'll write their worms, their viruses, their tools and their sample code to exploit whatever vulnerabilities they find.
And in a matter of hours, word of the exploit will reach every creep who wants to break into, corrupt or shut down our systems.
We, of course, won't hear about it from official industry sources for another 29 days after that.
But somehow, we can be pretty sure the crackers will make us aware of it.
And when they do, instead of having the best, most accurate and most complete information on our security exposure, we'll get some kind of vague, limited bafflegab from security experts. It won't keep the bad guys from knowing anything - they'll already have the information.
All it will do is keep us from making informed decisions for ourselves about exactly how severe the risk is, what our security options are and which actions are most appropriate for each situation.
As I write this, they're still cleaning up the mess and reliving the '70s down at the federal court offices in Miami. One user told a reporter, "It's kind of nice not having computers."
Maybe it is for him. The rest of us would rather have what we need to keep our systems running - and not have to wait 30 days for it.
Frank Hayes, Computerworld's senior news columnist, has covered IT for more than 20 years. Contact him at frank_hayes@computerworld.com.
|
|
Print this Story |
|
Send Us Feedback |
|
E-mail this Story |
|
Digg this Story |
|
Slashdot this Story |
|
|
|
|
|
|
|
|
All Zones Application Performance Zone Enterprise-Class Security Zone Enterprise Solutions Zone The File Data Management Zone Grid Computing on Windows Zone Security Management Zone ITIL Best Practices Zone The SAS Zone Storage Virtualization Zone The Data Center Management Zone |
|
|
| ||||||||
| ||||||||
| ||||||||
|



Security Management ZoneSecurity management is the process of developing a comprehensive data protection plan. It takes into account all potential threats, the existing network environment, the future needs of the organization, and lays out a multi-tiered blueprint to integrate the security technology needed to combat these threats. CDW can help keep your network and data secure. Visit the CDW Security Management Zone now See All Zones
|
Fired up about IT? Join Sharkbait and share your true tales of IT. SharkBait is the place for you to sound off about everything IT the good, the bad, and the rest of the weird stuff you deal with every day. New baits |
Computerworld Technology Briefing: An open-source path to optimal virtualization Looking for a virtualization strategy that offers both the flexibility and reliability to meet the demands of mixed-source environments? Look no further than the fast-emerging open virtualization approach backed by some of the biggest names in enterprise computing. Together they are pointing the way toward higher data center performance without higher costs.Download this briefing
|

In SecurityThere's plenty of talk about how to behave during a Customs search of your computer and gear, but Jon Espenschied's got tips for securing your data (and privacy) before you reach the border. Click here to read the latest column by Jon Espenschied |
![]() |
Layered Security Solutions
Although basic network security issues have changed very little over the past decade, the
network security landscape has changed dramatically. Today's IT professionals still have the
primary responsibility of protecting the confidentiality of corporate information, preventing
unauthorized access, and defending the network against attacks. Security experts and analysts agree that a security solution comprised of multiple layers is the best defense against today's increasingly sophisticated attacks.Download this white paper
|
Universal Threat Management - Because Conventional UTM is Not Enough!
This white paper, written by Mark Bouchard of Missing Link Security Services, examines the challenges confronting today's enterprises with respect to managing threats on a network. It also discusses the need for "Universal Threat Management", which is a security solution approach for all physical locations within an enterprise that require threat protection.Download this white paper |
Selecting the Right Threat Management Solution
This short demo will guide you through key considerations for selecting a solution to manage threats on a network. Learn about the popularity of Unified Threat Management (UTM), and how it fits into an overall security solution. Explore critical elements of a network-wide solution for multisite and large network-size deployments and identify the four key features of a threat management solution.View this demo
|
| About Us Advertise Contacts Editorial Calendar Help Desk Jobs at IDG Privacy Policy Reprints Site Map |
|
CIO The Industry Standard |

