You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft told to take some virus blame

Virus writers most hated but Gates and co don't escape completely...

Tags: sophos, virus, virus writers, microsoft

By Dawn Kawamoto

Published: 19 August 2005 08:10 GMT

One-third of business users blame Microsoft for the recent worm outbreak, despite the company's security efforts, according to a poll.

Thirty-five per cent of respondents to an informal web survey of customers by security company Sophos said the software maker was ultimately at fault for the recent rash of worms spawned by variants of Zotob. In the poll results, released on Thursday, 45 per cent placed the blame squarely on the virus writers, while 20 per cent laid blame on their systems administrators for not patching systems fast enough.

Graham Cluley, Sophos senior technology consultant, said in a statement: "The majority of users believe that the virus writer has to take the ultimate blame for deliberately creating and unleashing this worm to wreak havoc on poorly protected business. But what is most surprising is that so many people blame Microsoft for having the software flaw in the first place."

Microsoft is not alone. Companies are increasingly calling on software developers to improve their security battle-testing of products before release.

A Microsoft representative said on Thursday: "No software is 100 per cent secure, and this is collectively being felt by the industry. Over the last year, Microsoft has made improvements with security."

The software giant, for example, has launched its Security Development Lifecycle, the representative said. The move modified Microsoft's software development process to improve the way it integrates security best practices from the start.

Microsoft has also seen security improvements with its Windows XP operating system and the Service Pack 2 update, analysts said.

In the most recent worm outbreak, malicious attackers began circulating variants of Zotob and other viruses that exploit a plug-and-play feature in some Windows versions. The onslaught came shortly after Microsoft's regular monthly patch release, which included a fix for the problem. The flaw allows remote attack in Windows 2000 and not Windows XP SP2, according to Microsoft.

Cluley said: "Microsoft is stuck between a rock and a hard place when it comes to vulnerabilities. When it goes public about its security holes, a virus can be written to exploit them and many businesses may not have rolled out the patch. If it kept quiet... everyone would ask why Microsoft hadn't warned anyone of the vulnerability."

Dawn Kawamoto writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...


  • Jobs
Technical Support with French

Technical knowledge for troubleshooting problems with:-Work stations with ZENworks for Desktops V7-MS Windows XP (Registry, Policy packages,.ZenWorks ...

Infrastructure Engineer

You should have strong technical skills and any knowledge of the following would be beneficial - WIndows XP, MS Office, Citrix, LAN and WAN, Active ...

IT Support Team Leader - 1st Line,Windows XP,Novell NetWare,MS Office

IT Support Team Leader - 1st Line Support, Windows XP, Novell NetWare, MS Office 2003/2007University College Birmingham is seeking to recruit an ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: