All the latest UK technology news, reviews and analysis

Microsoft 'code scrub' ridiculed

by Gareth Morgan

06 Feb 2002

Be the first to comment

  • Tweet this

Microsoft's efforts to secure its operating systems and software have met with widespread scepticism among industry experts.

Richard Purcell, the software giant's head of corporate privacy, revealed earlier this week that each division is to take one month off to perform a "code scrub" which will examine all the operating systems and applications software code to ensure that it is free of flaws.

But the news was greeted with disbelief. As security expert Neil Barrett explained, checking the code is fairly simple, but fixing the holes could be very time consuming.

Source code can be run through programs which ensure that it is hole free, but Microsoft will be faced with problems once it has uncovered any vulnerabilities. "If a number of vulnerabilities are uncovered, the development work required to produce fixes could take far longer," he said.

The company must also be sure that it can check all the source code. "Much of the source code for libraries was written years ago and may be lost," explained Barrett.

In addition, Microsoft can only check for known vulnerabilities. There are about half a dozen known exploits based around either the interface between two programs, or the interface between user and program, said Barrett.

"We can check these easily. But there may be many more that we currently don't know about," he pointed out.

Microsoft's UK office refused to confirm whether the "code scrub" was underway, and would not specify what would be involved in such a procedure.

"I'm unaware of [Purcell's] comments. If he had said such a thing, he would have had a good reason," insisted John Noakes, UK .Net development manager at Microsoft.

He claimed that the code for both Windows XP and Visual Studio .Net, which is released on 13 February, had undergone extensive security checking as it was being developed.

"We have done penetration testing, and had external companies testing the releases in live environments," said Noakes.

Microsoft is aware of the challenge facing it. Chief technology officer Craig Mundie presented a paper to the recent World Economic Forum, which reported that it may take as long as "10 to 15 years" to reach the company's goal of 'Trustworthy Computing'.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Web Graphic Designer

A leading global provider of critical information to...

Midweight UI Designer

Playstations and table football in the kitchen? Standard...

Systems Engineer - 2nd/3rd Line Support - Microsoft + Citrix OR VMware

Systems Engineer - 2nd/3rd Line Support - Microsoft OS...

Senior Network Engineer

A leading global provider of critical information to...

To send to more than one email address, simply separate each address with a comma.