Read Satya Nadella's Microsoft memo on putting security first
theverge.com
theverge.com
For example, how do you reward employees for investing in security, besides punishing them for security breaches?
I've seen this sort of message come from CEOs but sub organizations optimize for what they're measured against. It's rarely security, tech debt, maintenance, etc.
Sure it doesn't kill all kinds of exploits, but it would already be an improvement.
The first kind of security involves increasing the security for as many people and systems as you can.
The second kind of security involves making your numbers look good by saying "We don't support that any longer."
Microsoft seems interested in the second kind. They are going to ditch support for widely used legacy systems, so they are not blamed when those systems get hacked.
Microsoft should offer support every Microsoft product ever released that still has 1 million active users. Imagine Microsoft using a single Hyper-V install, then letting you run any Microsoft product that is commonly used for $5 to $25 each. That would pay for a lot of security and profit. Just firewalling the legacy systems in the way Cisco does with ACLs would greatly improve their security. A more comprehensive next-generation firewall would be better. Their software engineers could look at every likely vulnerability for their products, and offer one of several kinds of patches: (1) A firewall patch that makes such exploits unlikely to get through, (2) a patch to the hypervisor that inspects the VM and prevents or removes the exploit, or (3) a patch to the software itself that removes the vulnerability. These could work together, with the software itself detecting the problem and asking the hypervisor to do the cleanup. Using this combination of methods, Microsoft's engineers should be able to deal with every known exploit.
Microsoft should support ripping disk images and making them into VMs, so that legacy systems can easily be moved into this new secure ecosystem that I propose.
There was (and is?) little to no incentive to compete on security. Security is expensive, hard to measure, and generally only visible when it annoys you or when it fails (sometimes catastrophically.)
We may not get it in x86 but I have hope for ARM, which actually had a prototype implementation (Morello).
I mean, clearly he has no idea how Windows is working.