We Are Morons: a quick look at the Win2k source (2004)
kuro5hin.org
kuro5hin.org
* Virtually every Microsoft senior developer has been trained on software security
* All shipping code is checked in-house, including some homegrown static analysis tools
* Most shipping products have had line-by-line source code reviews done by at least two different firms (we did some of this work for Vista).
During the Summer of Worms in '03, when Microsoft security lapses were front-page material on CNN, Bill Gates told the press that Microsoft was going to totally overhaul security and code quality. They weren't kidding. Microsoft now outspends everybody on that.
Note: I'm a Mac person.
Up voted none the less.
Note: I'm a Mac and a PC person.
It's irrational, yes. But that's human nature for you.
What's surprising, and perhaps sad, is that operating systems have aroused people's passions so intensely that it has become one of those volatile topics, like the canonical religion and politics, that one must treat very carefully, and certainly not bring up at dinner.
People look to form tribes using whatever brands they can - be they personalities, cars, clothes, or programming languages.
Kneejerk "Microsoft rules" or the opposite should be downvoted, even if followed by "I'm a Mac person". I'd like to think that's what would happen as well.
I'm impressed. You probably can't tell me, but just in case... how much do you charge for this?
Considering how many LOC there are in Vista, either you're far cheaper per LOC than I expected, or Microsoft put up a huge amount of money.
Our practice focus is on code-assisted penetration testing; in other words, we'll read your code, but mostly to get a sense of what it does and how it's articulated. Then we'll write software to beat the shit out of it.
The nice thing about this is, projects are scoped by what the code does, and how exposed it is to attack, not by some arbitrary number.
I'd love to talk about the specifics of what we did for this customer, but I'm only able to say "Vista" because Microsoft publicly said we worked on it.
2) None of the examples I gave go against user happiness, quite the opposite really. If you think something should be painful, you're less likely to notice when you're doing it wrong.
So let's stipulate that neither of us want to piss off users, neither of us are vouching for Microsoft's long term strategy, and neither of us are arguing against open source. We're not talking about whether you should use Linux or you should use Microsoft.
We're talking about, this is what it looks like when a company redlines security and code quality. Many of us have companies that ship code. It's worth knowing what the ends of the spectrum look like.
I simply don't believe that any other team, open source or commercial, would do something like this. I've seen too many of both kinds of teams blow off actual documented vulnerabilities to think that they'd hurt their own progress to chase down hypothetical ones.
The rest of the discussion is academic to me. By all means, use Linux. We do for our Rails app. Hooray for open source.
A code review.
You can't measure Microsoft's expenses against the expense of developing Linux. Linux was not cheap to make either - just the time is distributed across a lot of books instead of one set.
But it might be interesting to find out how much companies spend on security in the linux kernel. IBM, for example, is supposed to have spent billions on linux.
I often hear that argument made and yet in the time I've been using Linux (since 1994) the total number of Linux users has increased by many orders of magnitude but I have seen no corresponding increase in the number of security issues. I think that it's because Linux is (much) more secure by design and process but I guess I'll just have to wait until the apocalyptic Xth user moves to Linux and I start having to worry about viruses, malware etc. to see if I'm right or wrong.
The issue here is simple. People will target Linux when it stops being so overwhelmingly profitable to target Windows. We're nowhere near "peak oil" for Windows malware. It is, as Joel Spolsky points out, just economically irrational to target anything other than Windows.
This is the difference between safety and security. You are indeed safer on a Mac, just like you're safer living out in the country, even if your city house has a serious alarm system and bars on the basement windows.
I'm not so sure about that. Some malware installs itself by exploiting vulnerabilities. (Not all of it, though - there's plenty of Windows malware that gets installed by social-engineering the user.) But, in order to stay installed, most malware depends on other properties of the OS to conceal itself and stay installed. Windows makes this much easier for a programmer than Linux does.
Data point: Microsoft released a security assessment tool - they even open sourced it (note: title is misleading): http://it.slashdot.org/article.pl?sid=09/03/22/147202
But Vista was more of a fail I guess.
* I'm a GNU/Linux person
For Microsoft or for everyone?
A mediocre programmer might come up with the same fix, but not recognize that the fix was an ugly hack, and not comment as such.
// TODO:
Which has the added benefit (in Eclipse) of creating a tiny blue box in the vertical source error/warning/status bar (I'm not sure what it's official name is) so I have a visual cue to see where I have unfinished business (Kludges are unfinished business that you might get to next day or never, but even if it's a glorious hack, if you think its a hack and not a "proper" way to do it, its still unfinished business. In a prior project we used to use "glorious hack" as a special comment to use as the first places to investigate when something broke.The measure of a good programmer is not whether he or she recognizes when they're writing bad code, but whether the final result is free of bad code, and thus more maintainable.
I would argue that someone commenting known bad code, but leaving it there in perpetuity is no better than someone unknowingly writing bad code (although the comments could serve as signposts to help someone else find and fix your bad code - but how often has that ever actually happened?).
Now, i never really got the idea of source pollution if the source is never grabbed to begin with. All projects that rely purely on the GPLv2 have the same 'legal requirement', unless that code generates more code. Then, well, let the lawyers decide that one. I'm thinking of the license from gcc and like.
Every commercial codebase has hacks and special cases. Limited developer resources, deadlines and idiotic external constraints (hello third party libs/apps!) simply force that.
There is an art to capturing stupid stuff that is beyond your control at the integrating level (with checks, logging and exceptions at that level) without allowing this to contaminate the deeper levels of your system. That's another story entirely.
If you want to read some highly amusing comments in source, read http://www.jwz.org/doc/censorzilla.html - the list jwz published of the stuff that had to be removed from the Netscape source code before it was open-sourced.
Wine.
If I was them, I wouldn't be interested in copying it, but I would be interested in seeing how things were actually done (to confirm inferences as well as resolving puzzles.) But I believe that even seeing code leaves you open to a copyright infringement suit, which is why people do clean room reverse engineering. So, I wouldn't even look at it if I was them - despite my interest :-(.