{"id":774,"date":"2001-11-15T15:29:54","date_gmt":"2001-11-15T20:29:54","guid":{"rendered":"http:\/\/hill-kleerup.org\/blog\/wp\/?p=774"},"modified":"2001-11-15T15:29:54","modified_gmt":"2001-11-15T20:29:54","slug":"ignorance_stren","status":"publish","type":"post","link":"https:\/\/hill-kleerup.org\/blog\/2001\/11\/15\/ignorance_stren.html","title":{"rendered":"Ignorance, Strength"},"content":{"rendered":"<p><b><a href=\"http:\/\/www.theregister.co.uk\/content\/55\/22816.html\">&#8220;Your Ignorance is Our Strength<\/a><\/b><\/p>\n<p>A good article in <i>The Register<\/i> on Mico$oft&#8217;s &#8220;Security through Obscurity&#8221; initiative.  It basically says that M$ is trying to keep others from revealing security problems with its products, under the guise of keeping hackers from finding out.<\/p>\n<p class=\"block\">Elias Levy, security expert and former moderator of the BUGTRAQ list considers this Framework is akin to developing an &#8220;Information Cartel&#8221; with the result of improving the image of software vendors by withholding potentially embarrassing information that could adversely-impact sales. Simple Nomad also noted that the controversial Digital Millennium Copyright Act (DMCA) could be invoked by Microsoft and target independent researchers and non-Framework members publishing vulnerability information about its products, just as Adobe did this past summer. In this case, the company would join Adobe in using law and criminal procedure as poor replacements for quality control and effective software testing. Perhaps by joining the Framework, you are immune from DMCA liability provided you only report your vulnerabilities to Microsoft? Will security researchers be forced to join the Framework or be litigated out of business?<br \/>\n[&#8230;] Releasing better products would go a long way in preventing the constant patch triage that Microsoft admins face on a weekly basis. The problem is not the periodic misuse of vulnerability information in the public domain, but the delusional position of Microsoft that their products aren&#8217;t to blame for these recurring, high-profile security incidents. Novices can write code to exploit Microsoft products because Microsoft makes it so easy for them to do. If the software monopoly effectively addressed the underlying root causes of its software problems instead of merely treating each symptom as it was reported, today&#8217;s novices would not have historical blueprints to learn from in building new attacks that exploit similar historical vulnerabilities in Microsoft&#8217;s products. Code Red was not a &#8220;new&#8221; exploit but the latest in a series of buffer overflow problems affecting IIS for years. <br \/>\n[&#8230;] Under Microsoft&#8217;s Framework, the preferred method of dealing with this is to keep folks in the dark and only issue the barest shred of useful information, if they chose to release it at all. Something somewhere, at some time, is going to attack you. Beyond that, we can&#8217;t tell you more because we either don&#8217;t know or don&#8217;t want to give anyone any ideas. Trust us, we will get back to you as soon as possible.<\/p>\n<p>Well, at least the government is cracking down on these guys, breaking their monopoly and making sure they treat the public fair&#8211; &#8230; uh, what&#8217;s that?  Oh.  Sorry.  Never mind.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;Your Ignorance is Our Strength A good article in The Register on Mico$oft&#8217;s &#8220;Security through Obscurity&#8221; initiative. It basically says that M$ is trying to keep others from revealing security&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[20],"tags":[],"class_list":["post-774","post","type-post","status-publish","format-standard","hentry","category-hi-tech"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":5858,"url":"https:\/\/hill-kleerup.org\/blog\/2004\/07\/09\/security_is_a_c.html","url_meta":{"origin":774,"position":0},"title":"Security is a &#8220;competitive advantage&#8221;","author":"***Dave","date":"Fri 9-Jul-04 9:44am","format":false,"excerpt":"Micro$oft is selling security as a \"competitive advantage\" that it has over the industry. Attendees at last year's event, in New Orleans, cheered when Microsoft Chief Executive Officer (CEO) Steve...","rel":"","context":"In &quot;Hi-Tech&quot;","block_context":{"text":"Hi-Tech","link":"https:\/\/hill-kleerup.org\/blog\/category\/hi-tech"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":40859,"url":"https:\/\/hill-kleerup.org\/blog\/2014\/01\/23\/ignorance-is-strength.html","url_meta":{"origin":774,"position":1},"title":"Ignorance Is Strength!","author":"***Dave","date":"Thu 23-Jan-14 2:46pm","format":false,"excerpt":"If you explain things to kids, you see, then they don't learn to Simply Obey Parents Because God Says So (and to Simply Obey God, Too). \u00a0So don't explain, command. Then, when they're adults, they won't understand the reasons for rules they are given (by governments, preachers, etc.), just that\u2026","rel":"","context":"In &quot;~PlusPosts&quot;","block_context":{"text":"~PlusPosts","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/plusposts"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":132217,"url":"https:\/\/hill-kleerup.org\/blog\/2016\/12\/11\/the-willful-ignorance-of-the-president-to-be.html","url_meta":{"origin":774,"position":2},"title":"The Willful Ignorance of the President-to-Be","author":"***Dave","date":"Sun 11-Dec-16 12:41am","format":false,"excerpt":"I get it. Donald Trump is a busy man. He's got victory rallies to go to. He has tweets to make. He has interviews with billionaires and generals to hold. He has business deals to wheel. He's Executive Producer for the New Celebrity Apprentice TV show.But you'd really think that\u2026","rel":"","context":"In &quot;~PlusPosts&quot;","block_context":{"text":"~PlusPosts","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/plusposts"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":32271,"url":"https:\/\/hill-kleerup.org\/blog\/2013\/01\/22\/java-vulnerabilities-remain.html","url_meta":{"origin":774,"position":3},"title":"Java vulnerabilities remain","author":"***Dave","date":"Tue 22-Jan-13 10:36am","format":false,"excerpt":"Turned off at home. Poking our security group about it at work.Reshared post from +Les JenkinsThat's not good. The patch they released apparently wasn't enough to close the hole. Embedded Link Critical Java vulnerabilities confirmed in latest version Security researchers have confirmed that the latest version of Oracle's Java software\u2026","rel":"","context":"In &quot;~PlusPosts&quot;","block_context":{"text":"~PlusPosts","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/plusposts"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":3072,"url":"https:\/\/hill-kleerup.org\/blog\/2002\/08\/13\/pro_choice.html","url_meta":{"origin":774,"position":4},"title":"Pro-choice?","author":"***Dave","date":"Tue 13-Aug-02 3:19pm","format":false,"excerpt":"Does anyone else find hilarious that a Micro$oft-run (effectively) organzation (a) is being touted as \"grass roots\" (maybe more like kudzu), and (b) is calling itself the Initiative for Software...","rel":"","context":"In &quot;Hi-Tech&quot;","block_context":{"text":"Hi-Tech","link":"https:\/\/hill-kleerup.org\/blog\/category\/hi-tech"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":132840,"url":"https:\/\/hill-kleerup.org\/blog\/2017\/02\/13\/the-intellectual-source-code-of-trumpism.html","url_meta":{"origin":774,"position":5},"title":"The Intellectual Source Code of Trumpism","author":"***Dave","date":"Mon 13-Feb-17 6:14pm","format":false,"excerpt":"I'm not a believer in the Big Conspiracy. That said, strange circumstances make strange bedfellows, and there's a wide array of folk in and around the Trump White House that have their own particular vector of zaniness and\/or menace.One such person seems to be Michael Anton, who is presently the\u2026","rel":"","context":"In &quot;~PlusPosts&quot;","block_context":{"text":"~PlusPosts","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/plusposts"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts\/774","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/comments?post=774"}],"version-history":[{"count":0,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts\/774\/revisions"}],"wp:attachment":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/media?parent=774"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/categories?post=774"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/tags?post=774"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}