Sign in
Randy Holloway at Microsoft
Blogging from the field.
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Blog Home
Email Blog Author
Share this
RSS for posts
Atom
RSS for comments
Search
Tags
No tags have been created or used yet.
Archive
Archives
March 2007
(1)
February 2007
(13)
July 2006
(1)
March 2006
(1)
October 2005
(1)
September 2005
(1)
August 2005
(1)
July 2005
(1)
June 2005
(2)
May 2005
(4)
April 2005
(12)
March 2005
(21)
February 2005
(1)
January 2005
(8)
December 2004
(6)
November 2004
(18)
October 2004
(6)
July 2004
(3)
June 2004
(22)
May 2004
(6)
April 2004
(8)
March 2004
(15)
February 2004
(6)
January 2004
(5)
December 2003
(18)
November 2003
(16)
October 2003
(38)
September 2003
(20)
August 2003
(26)
July 2003
(26)
June 2003
(38)
May 2003
(35)
Steve Ballmer at the CIO Summit
MSDN Blogs
>
Randy Holloway at Microsoft
>
Steve Ballmer at the CIO Summit
Steve Ballmer at the CIO Summit
RandyHolloway
16 Oct 2003 10:35 AM
Comments
1
Right out of the gate at the CIO Summit, Microsoft assumed the role of being their own worst critic. In light of the security concerns over the past year, this makes a lot of sense. I have an appreciation for the approach that they took in communicating about the security problems. If you don't critically analyze your performance in an area, it is impossible to learn and change behavior. Steve Ballmer's main point is that Microsoft must do a better job of helping customers to secure their IT infrastructures without slowing down technology innovation. To quote Steve, he said "we're not living up to your expectations, but we have less vulnerabilities than virtually any other system available." But no excuses were being made, and there was a real sense that Microsoft takes this problem very seriously. They also claim to recognize that they need to do more. Based on the talk, I think they're taking a balanced approach. They will continue to focus on new products but get better preventive measures in place for product engineering to mitigate the introduction of vulnerabilities into their software. Steve also talked about the issues with both new systems and "down-level systems". Microsoft is trying to continue to support older versions of Windows and to ensure that they can be secured, but there are real limits that actually affect customers. During the Q&A, one customer talked about upgrading a few hundred Windows NT workstations (by 2005!), and their concern about continued support to keep NT4 secure. It points out that much of the IT world simply cannot move at Microsoft's pace.
Ballmer had some other interesting comments, and as you would expect he made some provocative statements. He referenced
Bill Joy's recent comments on monoculture
, and said that that it was "hogwash". His reasoning is that even with multiple platforms the problem space for security doesn't really change that much, and that more platforms actually could increase the complexity of dealing with the problem. He also made reference to a discussion with a Homeland Security official, saying that security in the technology realm has a strong parallel with national security under the threat of terrorism. He said that "the bad guys only have to get it right one time, but the good guys have to get it right every time." Towards the end of the talk, Steve said "if i could write a check for a billion dollars and most of our customers would be secure overnight, I'd write the check and go explain it to the analysts." I believe him, but the problem is that fixing the problem won't be that cheap or that easy.
1 Comments
Blog - Comment List MSDN TechNet
Comments
Loading...