About InfoWorld : Advertise : Subscribe : Contact Us : Awards : Events : Store
InfoWorld HomeNewsTest CenterOpinionsProduct GuideTechIndex
 COLUMN ARCHIVE  FORUMS
 

COLUMN

 
Security Adviser
P.J. Connolly

Proof in the pudding

THE BAD NEWS is there are now two more things for security administrators to worry about: Macromedia Flash and Microsoft's .Net Framework. The good news is that you don't have to spend much time worrying about them ... yet.

   ADVERTISEMENT
  

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

RELATED LINKS
»  IE 7 bug reopens debate over patch responsibilities
»  Woman ordered to pay for file-sharing will appeal
»  McAfee to buy SafeBoot for $350M
»  Security RSS feed 

IDG ENTERPRISE NETWORK
Research Reports  (CIO)
Ask the Expert  (CIO)

TOP NEWS 


IT SOLUTION SEARCH
In early January, reports surfaced that each of these "environments" had become the subject of independently designed proof-of-concept viruses. I figured it was only a matter of time, given that the dot-bomb effect must have left thousands of Flash programmers with time on their hands in the one case, and in the other, that almost anything coming out of Redmond these days has a big, fat target painted on its side.

Nevertheless, it's an interesting way to start the new year. Even though these viruses are lab critters of the first order -- they aren't loose, and the creators gave the concerned vendors a heads-up and example code before calling the press -- they simply shouldn't come as news to anyone. If there is a way to subvert computer security, no matter how closely controlled or poorly documented the vulnerability, it will be found and used.

Granted, I've seen plenty of Flash implementations that have grabbed every scrap of my computer's resources while I frantically tried to shut my browser window, so I wouldn't mind seeing a mass roundup and re-education of anyone noting Flash skills on his or her résumé. Although this would do wonders for San Francisco parking, it won't solve the security problem. If you use Flash on your site and you're not actively securing the content, this is your wake-up call.

I could go on in a similar vein regarding the .Net Framework; but discussing the ills of Microsoft products can be a full-time job, and this column is already a day late thanks to some unplanned downtime. I'm positive that Microsoft's developers aren't clowns, and I'm sure that when company representatives tell me that security is a priority, those words are the absolute truth. After all, not many people wake up in the morning and decide: "Hey, today, I'm going to write some really crappy software that's riddled with security holes."

I don't write code for a living, but I do know that programming is more art than science. Software is very much like a house of cards in that one false move can collapse the entire structure. But as a reader pointed out in response to some remarks I made in regard to IIS (Internet Information Server), when was the last time you heard of a virus taking out an AS/400, iSeries, or whatever IBM's calling it this year?

Granted, there are a lot more Windows boxes out there than there are AS/400s, and like any predator, computer attackers go after the easiest prey first. This alone would seem a compelling rationale to find alternatives to Microsoft's computing platform, but whoever said humans were rational?


P.J. Connolly (pj_connolly@infoworld.com) covers collaboration, networking, OSes, and security for the Test Center. Get this column free via email each week. Sign up at www.iwsubscribe.com/newsletters .




RELATED SUBJECTS

Security

MORE >


SPONSORED WHITE PAPERS
EMC - Lower costs and improve reliability-Get the EMC CLARiiON white paper!
Ciphertrust - Are you ready for Sobig.G? Learn how to protect your email systems.
CDW - Personal attention. CDW. The Right Technology. Right Away.
EMC - Explore key performance features and capabilities of EMC ControlCenter 5.1.1.
Intel - Free Intel white paper shows you how to deploy a secure wireless LAN
Cisco - FREE WHITE PAPER: BLUEPRINT to design and implement secure VPNs
Verity, Inc. - "Mass Consolidation Hits the Web-Search Market"
McDATA - Download a FREE storage consolidation white paper from McDATA(R).
Lucent Technologies - Overcoming Common Firewall Limitations
Lucent Technologies - Leverage Your Mobile High Speed Data Access. Download Free White Paper!
Nokia - Get the scoop! Mobilizing business white papers & case studies.
BMC Software - Maximize the Potential of Enterprise Data: Free white paper!
Network Associates - Free white paper - Strategies for Optimizing Network Costs and Benefits
Entrust - Manage identities across applications. Improve productivity.
Stalker Software - CommuniGate Pro - Transform your Email and Calendaring
Remedy - A NEW Gartner Research Note:Producing Quality IT Services

Search the IDG White Paper Library:


SPONSORED LINKS

INFOWORLD MARKETPLACE


» IT Compliance Conference: Nov. 5-7 in San Diego
Best Practices, Peer Experiences, & Expert Advice for Building a Defensible IT Compliance Program
» FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
» IT Audit Checklists
Prepare for your next internal IT audit. Checklists cover security, risk management, PCI, and more.
» FREE White Paper: Mitigating Rock Phish Attacks
Standard anti-phishing methods cannot defeat complex Rock Phish attacks. Learn how to fight back...
» Apply BPM and ITIL at your IT Help Desk
ServiceWise brings BPM to complete IT service while eliminating integration cost. Learn more here.




 HOME  NEWS  TEST CENTER  OPINIONS  PRODUCT GUIDE  TECHINDEX   About : Advertise : Subscribe : Contact Us : Awards : Events 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy

All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses, phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

Computerworld :: Network World :: CIO :: PC World :: Darwin :: CMO :: CSO
IT Careers :: JavaWorld :: Macworld :: Mac Central :: Playlist :: GamePro :: GameStar :: Gamerhelp
ITWorld Canada :: Computerwoche :: Techworld UK :: tecChannel :: IDG.se :: IDG.no