04 Jul 2011
Microsoft has blamed Sony and security firm RSA for making 'rookie mistakes' that led to both firms' recent and widely-publicised hacking incidents.
John Howie, senior director, online services security and compliance governance at Microsoft said that the security breaches at Sony could have beeen avoided if it had kept its servers patched.
"Sony was brought down because it didn't patch its servers, it ran out of date software and it coded badly. These are rookie mistakes," said Howie.
He added that the breach at secure token specialists RSA could also have been avoided.
"RSA got hacked because someone got socially engineered and opened a dodgy email attachment. A rookie mistake."
He claimed that processes in place at Microsoft meant that such mistakes were extremely unlikely to happen within his organisation.
"At Microsoft we have robust mechanisms to ensure we don't have unpatched servers. We have training for staff so they know how to be secure and be wise to social engineering."
In a statement that could be construed as goading to hackers, he also made the claim that Microsoft's internet capacity renders it almost impervious to denial-of-service (DoS) attacks.
This form of attack has been used in recent months by hacktivist group Anonymous and now-disbanded hacking group Lulzsec to temporarily take down the internet sites of Mastercard, Paypal, the CIA and the Serious and Organised Crime Agency (SOCA).
"We have massively overbuilt our internet capacity, this protects us against DoS attacks," said Howie.
DoS attacks bombard a web-facing server with requests for information until the volume of data that it attempts to pass exceeds its output limit, often causing the server to fail.
"We won't notice until the data column gets to 2GB/s, and even then we won't sweat until it reaches 5GB/s. Even then we have edge protection to shun addresses that we suspect of being malicious," he said.
Not a week after he slams Sony for lax security MS had their own "Safety and Security Center search engine to return adult-oriented results, studded with malware links." IMHO, this guy should be fired by the MS board and/or investors for making such comments given there is no such thing as a truly secure network.
Posted by: B Bergin 12 Jul 2011
Have your say on this article
Newsletters
Latest stories from Hacking
Latest videos
You may also like
Do you think the G-Cloud will be a success?
Rubbish in... rubbish enterprise. Why proper data management is so important (video, 6 min)
This Forrester report compares the costs and benefits of legacy email and productivity software with Google Apps
Upcoming Events
Join us to meet other professionals tackling this issue, and hear from Goy Roper, interim head of ICT of Norfolk County Council how his organisation deployed a flexible and intelligent network to cope with the challenge
Date: 07 Mar 2012
Time: 9am
The implementation of robust, relevant digital strategies is more crucial than ever to the success of insurance businesses
Date: 01 Mar 2012
Time: 09:00am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?