So-called security experts go for easy headline

WinInfo | at | by Mike

So-called security experts are now damning Microsoft's entire Trustworthy Computing initiative because of fallout from the SQL Slammer worm, which brought the Internet to its knees last weekend by compromising a vulnerability in SQL Server 2000 (SQL Server 7 and other Microsoft products were also affected). Certainly, the worm was ill-timed for the company, coming as it did just a year after it announced the Trustworthy Computing initiative, but does one worm really break a company-wide movement? Sound-bite friendly Russ Cooper is one security expert who thinks so. "Trustworthy Computing is failing," he said this week. "I gave it a 'D-minus' at the beginning of the year, and now I'd give it an 'F."' Them's fighting words, Russ, and I suspect Microsoft takes issue with your grading system, as they should. Certainly, Trustworthy Computing is an ongoing effort, but locked down products such as Windows Server 2003 (and its bundled IIS 6.0) and Exchange Server, shipping this year, show how the company is focusing on security. I don't think a single vulnerability--especially one that was patched several times, regardless of how difficult it was--proves otherwise. And anyone saying so now is just trying to grab any easy headline.