I’m off to America! Some tin-pot little IT start-up called Microsoft has invited me to visit their headquarters in Redmond, Washington (pictured) to find out what they’re doing about security, and in particular their Trustworthy Computing initiatives.
Now if you’re a crusty old network administrator like me, you may think that “Microsoft” and “security” in the same sentence is an oxymoron. A decade ago I was building Linux-based firewalls and, like so many people doing the same, I referred to Windows-based computers as “the targets”. And certainly the vast majority of the world’s malware is targeted at Windows.
But I’ve always though that the simplistic “Windows is bad, m’kay” was a bit, well, simplistic. Information security isn’t just about the technology, it’s also about people. Human factors are also the weakest link. And over the years I’ve found that people who throw around those tired platform-wars slogans usually aren’t up to date when it comes to the things they love to hate.
So, I’m off to Redmond later this month to spend three days with some of Microsoft’s engineers and developers, including briefing sessions with senior executives from Microsoft’s Trustworthy Computing Group.
There’s a lot to cover here, so what should I be looking at, do you think? The security of Windows Server, or Windows 7, or of Microsoft’s cloud services? Privacy issues? The fight against foreign governments, criminals and child abusers? Viruses and malware? Identity and authentication? What? You tell me!
What are some of the hard questions I should be asking?
Some of what I do will end up in a special edition of the Patch Monday podcast, and I’m also doing a “Letter from Redmond” for Crikey‘s “Letter from…” column. And I’ll be looking for more writing opportunities.
Dear Editors and Producers, is there anything you’d like me to research and write about? Please let me know if you’d like me to pitch some stories.
I’ll be flying out of Sydney on Monday 24 May, and will be in Redmond from Tuesday to Thursday that week, Seattle time. And yes, Microsoft is paying for the airfares, meals and accommodation, so there’s your journalistic disclosure.
[Photo: Microsoft's Redmond Campus, looking east, courtesy Microsoft Inc.]
Possibly related posts
Tags: azure, crikey, cybercrime, infosec, journalism, linux, microsoft, patch monday, redmond, virus
-
Sounds like you’ll have fun!
I’m curious about the nature of Microsoft’s increasing level of partnership with Facebook, particularly the moves to incorporate document sharing etc. How do they aim to address concerns about data security in light of Facebook’s more open/less private user data arrangement?
-
Ask them how Microsoft Security Essentials….
http://www.microsoft.com/security_essentials/
(which is free) compares to the security solutions of commercially available products such as MacAfee, Trend Micro and the like and why it is that security essentials isn’t installed by default with Windows installations and Microsoft Internet Explorer.
My understanding was that Microsoft intended this to be the case but that there was fierce opposition from those who profit from selling security solutions.
How good is Microsoft Security Essentials ?
-
I have noticed more Program Installers, Driver Installers etc. trying to send packets to Verisign (or the relevant Digital Certificate Issuer) ever since the File Security warning was implemented in to Windows XP (and Vista after reading link below).
This link kind of explains it http://social.msdn.microsoft.com/Forums/en/windowscompatibility/thread/f3980cad-24bf-42bd-9467-1299b75bf6adJust what ramifications does this kind of procedure have for open source software in the future? They will be forced to buy a Digital Certificate or face having their program crippled within the OS?
Will there be a future Windows OS that will not accept a software package unless it has been Signed?
Will this procedure also be enforced upon any Open Source OS’s?I haven’t had time to completely research this phenomenon properly, i read about your trip to Redmond and this was one of the things that stood out to me the most.
-
Short and sharp – given Microsoft’s impending (and delayed) launch of their Mobile 7 platform, what sort of attention have they focused on platform and data security? Given their track record of security with Windows (which is much to do with its popularity rather than obvious weaknesses, to be fair), have they found a need to focus any extra attention on securing their mobile platform from attacks? Are they confident the ‘usual measures’ are enough? Or are have they designed a ‘social communication’ platform that they don’t see as a rewarding target for hackers?
-
I have noticed that a majority (excluding Rocky Heckman) of their security team in Australia are sales rather then knowledge focused.
Is this because a majority of Australian corporates are less mature than the USA?
I am aware that there are several advanced people from Australia (independent of Microsoft) who have presented at their BlueHat event.



ABC The Drum
Crikey
CSO Online
Delicious
Dopplr
Flickr
LinkedIn
newmatilda.com
Patch Monday
Posterous
Qik
Stilgherrian Live (Ustream)
Technology Spectator
Twitter
Viddler
10 comments
Comments feed for this article
Trackback link: http://stilgherrian.com/internet/visiting-microsoft-hq-to-talk-security-what-should-i-ask/trackback/