Microsoft security foundation is cracked

eWeek | at | by Mike

I'm not attacking Microsoft's coding prowess or the sincerity of the Trustworthy Computing initiative. In fact, since the inception of Trustworthy Computing, the code coming from Microsoft has been, for the most part, much better and clearly designed with security in mind. But that isn't enough.

The code that has been passed on from Windows NT to Windows Server 2003 is just too old, too big and too interconnected to ever fully secure. There's only one way the Trustworthy Computing initiative could work, and that's to build a new operating system from the ground up, with no legacy Windows code whatsoever. But that's probably not going to happen.