https://www.schneier.com/blog/archives/2005/08/new_windows_v...
https://www.schneier.com/blog/archives/2005/08/new_windows_v...
I'm really not a fan of the classic British press discreditation technique of yelling "U-TURN" every time someone says something slightly different.
We shouldn't lose sight of who is really to blame for this problem. It's not the system administrators who didn't install the patch in time, or the firewall and IDS vendors whose products didn't catch the problem. It's the authors of the worm and its variants, eEye for publicizing the vulnerability, and especially Microsoft for selling a product with this security problem. You can argue that eEye did the right thing by publicizing this vulnerability, but I personally am getting a little tired of them adding weapons to hackers' arsenals. I support full disclosure and believe that it has done a lot to improve security, but eEye is going too far. As for Microsoft, you can argue that the marketplace won't pay for secure and reliable software, but the fact remains that this is a software problem. If software companies were held liable for systematic problems in its products, just like other industries (remember Firestone tires), we'd see a whole lot less of this kind of thing.
"The problem" here is "the Code Red worm".
One component of Schneier's recommendation is protecting researchers who practice full disclosure ("...attempt to muzzle security researchers who find problems"), but that's not really the core of his message in this post.