Slashdot Log In
BBC Bill Gates Interview Part 2: Security
Posted by
timothy
on Tue Feb 01, 2005 06:17 AM
from the these-are-not-the-holes-you're-looking-for dept.
from the these-are-not-the-holes-you're-looking-for dept.
securitas writes "In the second of two parts, the BBC's Stephen Cole of the technology show Click Online interviews Bill Gates about Windows, viruses, security, spam, 'trustworthy computing', Longhorn and being anti-competitive. Sample quote: 'Certainly you can never underestimate the level of malicious people out there who are going to try to take advantage of whatever things there are. That's why we made trustworthy computing the top priority.' Streaming media in Real format is also available. [Video: Broadband | Narrowband]
You can read the first half about the 'digital lifestyle' in Part 1: Bill Gates plots a Windows future. Here is the Slashdot discussion of the first part of the interview."
This discussion has been archived.
No new comments can be posted.
BBC Bill Gates Interview Part 2: Security
|
Log In/Create an Account
| Top
| 289 comments
| Search Discussion
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
It takes one to know one! (Score:5, Funny)
"Certainly you can never underestimate the level of malicious people out there"
And he can?
It takes one to know one!
Re:It takes one to know one! (Score:4, Insightful)
(http://www.uberm00.net/ | Last Journal: Monday January 19 2004, @09:27PM)
Trustworthy Computing isn't a way to secure your computer. It's a way to take its control away from you. [againsttcpa.com]
Security? Ha! (Score:5, Funny)
(http://mboverload.no-ip.org/tech.html | Last Journal: Tuesday July 13 2004, @01:54PM)
Re:Security? Ha! (Score:5, Funny)
(http://www.initialized.org/)
I suppose that Linux users really are virgins, then.
Re:Security? Ha! (Score:4, Insightful)
(http://srj.ath.cx/)
What he did say was "we can always do better" and "There is a lot more to do."
He also went on to say that Longhorn should be more secure.
Since none of you actually think about anybody but yourselfs in terms of what people want, let me explain it to you.
Most people (see: Users, Windows), don't want to give up usability for security. I currently use Linux, and have for years. I'm pissed off about the recent local root exploits and thought about switching to a BSD (namely OpenBSD), for security. But, after talking to a good friend of mine decided that I didn't want to compromise some of the usability of Linux for the security of *BSD.
Sure Windows sucks for a lot of reasons, but there's obviously more reasons that people are still using it.
It's the same reason that people drive cars with automatic tranmissions. A manual transmission has a number of benefits, but people just don't want the hassle.
Windows is prone to a lot of problems due to the default "administrator" account. But do you really think people want to log in to it to install software? Do you think they actually understand the difference? I doubt it.
Re:Security? Ha! (Score:5, Insightful)
Once you've seen a child having to become adminstrator to play a Microsoft game, you quickly realise just how serious Microsoft are about security and usability.
Re:Security? Ha! (Score:4, Informative)
(http://slashdot.org/)
Some criteria:
1) When app installs, all file and registry changes are contained in app directories and reg keys, unless such changes constitute system upgrades (MDAC, etc.) Start menu, etc. excluded.
2) App is fully usable under "user" level account (no write-backs to protected dirs, or HKLM registry).
3) App is fully usable under "fast user switching"
4) App cleanly fully uninstalls.
Actually, the full list is much longer, but the point is that MS gives brownie points to the dev. firms that can make apps run under "user" permissions. My guess is the game firms don't care about that level of certification, but for corporate-level apps, it makes all the difference. If you pass all of those tests, you can generally be assured of running under Citrix, Terminal Server, REALLY "locked down" desktops, etc.
Y'know, just once... (Score:1)
Because I doubt he will.
Fixed (Score:4, Funny)
Billy's "todo" list (Score:5, Interesting)
"Yeah, stability, we aren't really keen on that right at the moment, actually that's way down the list."
Thanks Bill, but with an inbox full of virus I get the feeling your "top priority" isn't as "top" as we would like.
Dupe... (Score:1, Informative)
1. Submit links from high score comments
2. ???
3. Instant Karma!
Just shows that slashdot editors don't read their site at all... (and don't bother to check stories with links to their sites either)
Good quote about Microsoft (Score:5, Funny)
"Certainly you can never underestimate the level of malicious people out there who are going to try to take advantage of whatever things there are."
Translation of Bill's answers (Score:5, Insightful)
(http://www.drydeadfish.co.uk/ | Last Journal: Wednesday November 02 2005, @09:09AM)
A: [translated from Billspeak to reality]:
I'm not going to answer that. I mean, come on, we all know that Windows wasn't designed with security in mind. So, I tell you what, I'm going to turn your negative into a positive, like a good salesman.
Here, for a start, I'll get you to focus on the nasty people out there that are exploiting Microsoft software - they're the bad guys, ok, not us!
Next, I'll tell you about auto-update, and that millions of people are using it. You don't have to worry because Windows updates itself. It takes away the hassle, right? And doesn't it make you 'feel' safer?
And of course, Microsoft has marketed the fact that security is its business. Even if Microsoft software isn't secure, we like to give that impression.
Q: "Nevertheless, a lot of our viewers still say to us: 'Microsoft didn't take that threat seriously enough and we are having problems.'"
A: [translated from Billspeak to reality]:
Ok, I don't want to answer that either, as it makes us look bad - and how can I refute something that's a fact?
Instead, I'll get you to focus (yet again) on the positive fact that Microsoft makes it easy to sit back and do nothing, letting Windows auto-update itself. Remember, Microsoft software is used because it's easy to use (not because it works).
I couldn't be bothered to read any further.
Do we even need interviews ? (Score:3, Funny)
Sorry Bill but you're full of shit (Score:5, Insightful)
If they cared about security (remember them saying that Windows XP was the most secure operating system ever?) they would have shipped it with the firewall on by default and most services off by default.
Why oh why did they think it was a good idea to have an RPC server on by default when there's probably less than 1% of users who would use the feature?
How many insecurities has Internet Explorer had since it was launched with XP? I lost count. Even now, there are still holes in there wide enough to drive a truck through but they are not patched. Microsoft want to keep things quiet until they get around to fixing the bugs, and they only fix the bugs when they see the problem being exploited in the wild.
And, thanks to Microsoft integrating the Internet Exploder engine so tightly into their OS, if a bug affects IE then it probably also affects Outlook, Outlook Express, MS Help and gawd knows what else.
This is security?
Ha!
Re:Sorry Bill but you're full of shit (Score:5, Interesting)
(http://rtfm.insomnia.org/~qg/ | Last Journal: Wednesday November 16 2005, @07:11AM)
That's not an argument at all. You wanna know what's fucked. Try debugging an application that is in no way network related on a machine that has Microsoft's firewall software enabled. It doesn't work. Why? Cause to initiate a debugging session visual studio actually sends packets out to the network adapter and back onto the machine. If you're blocking the remote debugging (say, because you don't want people brute forcing the trivial security that stops them from debugging processes on your machine) you can't even do local debugging. That's fucked behaviour and demonstrates that Microsoft really doesn't give a shit about security at all.
Re:Sorry Bill but you're full of shit (Score:4, Insightful)
Umm no it can't. IE is integrated into the kernel. iexplore.exe is just a shell that calls the kernel to render pages. Konquerer is just another application, and you can easily uninstall konquerer as well as the libraries and use other applications as suppliments, as long as you remove the MIMEs.
However there is nothing to stop an application from calling the konquerer or gecko libraries, or requiring their installation. It's simple enough with shared libraries to do.
Pre-Scripted Questions? (Score:2, Insightful)
(http://gnuosphere.blogspot.com/)
The only challenging question was around the Euro case and Billy completely dodged the question as expected.
Surely Bill often agrees to interviews with stipulations concerning what questions can be asked in advance - lame, but that's what you get with power. I find it odd that the BBC gets a 2-part interview with Gates and the topic of free software isn't brought up at all. Perhaps Bill is afraid to let slip another ignorant 'commie' remark.
There is only one word to describe this interview...
B O R I N G
But where's the beef? (Score:4, Insightful)
However, I'd really like to know what are they going to DO about it, apart from the traditional "we'll train our programmers". This is a key question especially considering that they have millions of code lines written before security was any kind of priority.
I predict no radical changes to the number of discovered Microsoft software security flaws in the short term.
advertising your weakness (Score:5, Funny)
(http://www.spambutcher.com/)
Best quote (Score:1)
'nuff said.
Trust (Score:5, Insightful)
An illuminating quote to choose because it is a complete non sequitur. And perhaps this isn't that obvious to everybody, even in sceptical
In reality, there is no requirement for Microsoft to trust the software on my machine in order for me to trust it. The two relationships are quite distinct. I may choose to trust software that Microsoft has never heard of. Conversely, I may distrust software that MS has endorsed.
The "trustworthy computing" soundbite has to be this vague because to pin down who is trusting whom to do what would immediately give the game away. The game is, of course, to encourage users to give up control of their PCs.
jeremy paxman (Score:1)
(http://www.microsoft.com/)
'And Europe too fined you for being anti-competitive. Did you ever pause for a moment and think: 'are we being anti-competitive?'
We wouldn't have got the lame response waffling about the PC industry, we would've could a half-honest response. Instead they chose Stephen Cole, a bumbling idiot with a lisp.
Re:jeremy paxman (Score:5, Insightful)
(http://www.stupids.org/ | Last Journal: Thursday July 03 2003, @11:37AM)
Honestly, Paxman is brilliant, but I could have interviewed Bill Gates better than that. (and that's saying something)
someone didn't buy microsoft dictionary (C) (Score:1)
(http://www.scenepointblank.com/)
Good ideas implemted incroectly. (Score:5, Insightful)
(http://tsfraser.googlepages.com/index.html)
Anything I want. (Score:1, Funny)
Set up like a bowling pin (Score:2)
(http://www.indyassociates.com/)
It *will* happen and it *will* be a cataclysm for MS.
Pilgrims Progress Approach Vs Infect,Scan,Remove (Score:5, Informative)
(http://itheresies.blogspot.com/ | Last Journal: Wednesday April 28 2004, @12:06AM)
In comparison, right from the outset, open source desktop platforms and applications have relied almost wholly on closing the infectable vectors, the exploited vulnerabilities used by malware, as quickly as possible.
Read the following Usenet thread from 2000 that covers the argument in detail [google.com]. David Harley and Robert Moir are two Anitvirus industry leaders. It also includes the prediction that Microsoft would eventually get into the antivirus industry.
If you have a spare hour, listen to Dr Dobbs' technetcast [ddj.com]:
Slashdot Interview!! (Score:4, Interesting)
Can't we organize a Slashdot interview of BG? (titter
Click Online (Score:3, Informative)
(http://joe-baldwin.net/ | Last Journal: Saturday September 02 2006, @11:58AM)
But his doodles indicate . . . (Score:1)
Certainly untrustworthy (Score:1)
Longhaul! (Score:2)
(http://rtfm.insomnia.org/~qg/ | Last Journal: Wednesday November 16 2005, @07:11AM)
Book 'em (Score:1)
The way to control it is to lock malicious hackers up for a long long time. The message has to go out that, contrary to the movie War Games, this is not a game, and you may end up in jail for ten years.
The sentence this week for one of the MS Blaster perps (18 months) was inadequate, but a start. It's not really enough of a punishment. They need to know: release a virus and ten years of your life will be snuffed out.
Vigorous prosecution put the kibosh on phreaking, and it will do so for malicious hacking too. Of course it will never be eliminated, but incarceration and social ostracism will take most of the wind out of their sails.
Trustworthy Computing? (Score:1)
Microsoft definition of trusted.. (Score:1, Informative)
It means nothing of the sort, it means industry trusting microsoft to deliver DRM crippled content, this way Microsoft can tie up everyones computer by sayiung 'you can trust us' so that nothing can run or be stored without industry (the 'rights' holders) giving their OK, this will remove the risk of virus and malware attacks because they just won't be able to run.
Interestingly, Microsoft hasn't actually done anythg special to secure it's OS, it's just endorsed pretty much any DRM scheme indistry cares to propose -they aim to secure a 'trusted' status simply by telling enough of the people who matter (CEOs and Governments) that they can't possibly trust anything open that doesn't come from Microsoft.
It's like I always say, Microsoft is all about redefinition. If something comes along that Microsoft think is a threat ('Innivation', 'open', 'trusted') they just decide what THEY want the word to mean and then feed that to anyone who'll listen.
Quote from the first part of the interview (Score:2)
(http://jamesholden.net/)
Trojaned windows media files anyone? ;-)
Some reality distortion here.. (Score:5, Insightful)
(http://iki.fi/teknohog/ | Last Journal: Tuesday August 14, @06:49PM)
Secondly, if they truly were the best, they wouldn't have all those security problems, now would they?
This is my ongoing number one gripe about Microsoft: they cannot admit their mistakes. Though every OS has security issues, MS is practically the only one that keeps lying about it. Technical quality aside, I'll rather deal with honest people and honest businesses.
boring Bill... (Score:1)
(http://www.mnmlnoise.com/)
They've made progress (Score:1)
If you look at things like spam, we feel very good about the progress there.
Thanks to poor design, Outlook now helps spammers(worms and viruses) innovate more than ever.
---
This was interesting also, regarding the timeline for longhorn: We're targeting 2006 but that isn't in any sense an exact date.
For a 'genius', he certainly understands that a year is not the same as an exact date.
---
I wish I could get an exact date....
Well, Mr Gates (Score:2)
(http://etoy.com/)
I trust my computer just fine; thank you very much.
Now if you, your company, Disney, the MPAA & RIAA etc. don't trust my computer that's really not my fucking problem. Doncha think?
Yes, I am aware that you sayd trustworthy and no trusted computing. Nevertheless, a faint, cold fear thrills through my veins when I observe execs, pr shills, spin doctors and other professional liars preparing the rethoric ground to matter of factly take my computer away.
Bill thinks we're lucky (Score:1)
"People would be very lucky if other sectors of the economy worked as well as the PC industry."
But not very lucky if other products worked as well as windows [engineers-...tional.com]
HULK SMASH! (Score:1)
This would be slightly funny if not for the fact that I HAVE to read this at work, as my home computer (which is outside of a well defended government network) is a wriggling mass of Trojans/Worms/viruses/spyware/adware... I am running 10 or 12 different anti-virus software in a futile attempt to clean it up. It is screwed. I have a feeling I will have to FORMAT and lose all my data (20GB + 120GB + 60GBx2).
All I have to say is "Trojan Downloader" sucks some ass big time, it can really ruin your day. If you see anything popup about a "INF installer" while you are surfing with IE (which I will NEVER EVER do again, well at work maybe), pull the plug. Press the off switch. cut the line.
I have disinfected most of the baddies, but more always seem to come up... The best part is the more I "disinfect" and basically delete files, inevedibly critical system files get chewed... so now XP is wildly unstable as well, not to mention my internet connection is also severered (which may be a blessing in discise).
So right now I have a process called svchost.exe runing my CPU at 99% and at least one bit of adware hidden away somewhere I cannot fathom. The one good side to this coin (not for me), is that I am seriously considering an OS move, I am so mad. I have downloaded the latest versions of KNOPPIX 3.7, GENTOO 4.3, XANDROS 201, and Simply MEPIS 4.4 but probably due to my CD-ROM sucking none will live boot except XANDROS, and it requires an HD install to run. I am still trying to save my data, but i am getting more discuraged by the minute. Anyway thats my lame story as sucky as it is.
BTW I know it is off topic but could any of you LINUX people out there tell me wtf isolinux errors mean on live boot attempt? Specifically the one that says something about a very dammaged bios or something like that and "Trying to wing it" and then repeat. Sucks. Anyway my response to BILL would be I just finished TRYING to get rid of HUNDREDS (if not thousands) of malware files off my computer because XP is SOOOO secure. I think he needs to windows update his reality.
DarthVain
I wonder if he still programs? (Score:1)
And The Operative Word Is... (Score:2)
Lessee now, first I put a ton of money into some Senators' pockets...
Then I get them to declare all the Linux freaks "Communists" and "enemy combatants" and get them all shipped to Gitmo...
Then I accuse Larry Ellison of financing terrorist groups...
Then I give a few million more dollars to some charity to make me above criticism...
Then...
Profit!!!
This Is Certainly True... (Score:2)
Unfortunately for him it applies to Gates...
Security is Number 1! (Score:1)
Haven't they been saying this for years? Since 2001 or so? How many thousands of viruses has microsoft's OS been nailed with since then?
Palladium, anyone?
Really, for a company whose software spreads viruses like a whore on a submarine for the last 20 years to claim that all of a sudden it thinks security is important at least implies that security wasen't number 1 until now...
Boy that make me feel safe using windows! Thank God!
In Bizarro world MS is THE security company (Score:2)
(http://slashdot.org/ | Last Journal: Monday October 29, @07:20AM)
And I am a Microsoft stockholder and wish them only the best - stockprice-wise. Let's face facts; Micosoft conquers by being average at best and benignly negligent at worst. This is a business not an artform and when they say something about security it can ONLY be interpreted in the context of what is good for Microsoft, not you.
Not flamebait (Score:1)
Stephen Cole:
Are you a victim perhaps of your own success? Being the biggest, you are always going to be under attack.
Bill Gates:
And we're always able to do the best R&D, the best innovation, get the best partnerships.
Certainly our position is one that people envy.
Bill Gates, you rock! Even though you had a nice net to fall back upon, you worked hard so you deserve it but I sitll dont like windows.
Doesn't he mean "overestimate?" (Score:3, Insightful)
(http://adam.blinkinblogs.net/ | Last Journal: Friday January 20 2006, @06:46PM)
If you can "never underestimate" said level, it drops to zero... I think he means that you can never OVERESTIMATE the level - which means that no matter how many people you think will try to break your stuff, there will always be a couple more, or their skill will always be a little greater.
If he honestly thinks that the level of malicious crackers in the world is so low as to be unable to underestimate it, he shouldn't be in the computing business (yes, yes, I know - he shouldn't be in it at all, but whatever).
If he means level like "stoop to their level"-type level, well, perhaps, but you don't have to be "evil" to be good at breaking things...
Aren't you forgetting Something? (Score:1)
I just read an *entire* Slashdot thread about Windows OS security and didn't read a single mention of OS X!!!
IMO the Windows OS vs. Linux OS paradigm ("simple" vs. secure) lost all meaning about 2 years ago...
I'm writing this on a PC, but darn, the more I read the words of Gates and Balmer, the more depressing it is to know that I've been paying to make these guys rich for most of my life, and for a crappy product at that. Meanwhile, I see Apple come out with great new stuff, such as the upcoming Tiger [apple.com].
And unlike Microsoft, Apple is led by a man I have no desire to shoot.
My next comp will most definately be a Mac.
wmv? (Score:1)
(http://www.solidz.com/)
Re:BBC Bill Gates Interview Part 2: Security (Score:2)
(http://libtom.org/)
That longhorn "incorporates all the users desires" and that making "windows update automated was #1 priority".
Re:BBC Bill Gates Interview Part 2: Security (Score:4, Insightful)
You do not need for systems to be backward compatible with ancient binaries. As long as you have the source code, you can simply re-compile it against your latest kernel and libraries, and it will Just Work. If something really has changed so much that it won't compile without editing, then it was already broken in the first place.
Stable closed-source drivers running in or with a closed-source kernel will never exist. Perfection can only be achieved when the driver developer and the kernel developer each have access to the other's code. Anything less than the full, annotated source code is just incomplete documentation.
Closed source is destroying computing. If everything is closed source, then it makes sense to build machines with the kind of processor and the I/O ports in the same addresses. Otherwise you need to supply different versions of essentially the same software just to work with different manufacturers' computers. {Think back to the cassette-based software on the 8-bit computers of the 1980s, and the racks in W.H.Smith full of similar games in versions for the Oric, the Spectrum, the Commodore 64, the BBC model B and the Amstrad CPC464. Come to think of it, why didn't they just record all the different versions on the same cassette one after another, for crying out loud?} All machines built the same way is one way to do it. It is not the only way. You can eliminate architecture-dependence by distributing the source code. Then, any architecture for which a suitable compiler exists can potentially run it.
If there were more machine architectures -- by which I mean physically different instruction sets and/or port addressing schemas -- out there, then we would instantly reduce the susceptibility of the worldwide user base to viruses, worms and trojans. Call it electronic biodiversity. In an environment like that, software would pretty much have to be open source to survive; it would hardly be economically viable for a vendor to release many versions of the same software. You would obtain a package in source form, audit it if desired, compile it, then have to perform some deliberate hardware action {like pressing a small, recessed button; or moving a jumper on the motherboard} to allow it to be installed.
Microsoft will get their comeuppance, though. Sooner or later they will have to launch a new version of Windows that will totally break compatibility with legacy software. Buyers will now have the choice: spend a lot of money buying the latest Windows system, not be able to use any of your old Windows software, have most of your old documents rendered totally unreadable and worry about the next time Microsoft pulls this kind of stunt; or spend not mu
[tt]:BBC Bill Gates Interview Part 2: Security (Score:5, Funny)
(http://trolltalk.com/ | Last Journal: Saturday November 17, @09:46PM)
Both Bill Gates and drug dealers
Re:Annoying (Score:3, Insightful)
(http://srj.ath.cx/)
The marketshare of Windows is the reason for many "hardware advancements". Without a standardised operating system, hardware would have never been standardisted, and thus would have been unable to progress.
How the solution to crappy software si faster updates.
Almost any company will only make products that are as good as the customer wants them. This is why people buy economy priced cars and everyone is not driving BMWs. Sure a BMW is better, but it costs a lot more to produce and few people are willing to spend the extra money to own one. Would you be willing to pay three times as much for Windows if it were a much better product? I doubt it. Everyone complains because it costs $99 now.
How the price of windows is pretty much dependent on how big you are (compare the retail price with the price paid by big companies)
This is true for everything, in every business. When you buy in bulk, you get discounts. It's a common business practise.
So, screw the little and small, cuddle the big !
Would you buy a car that your neighbour built himself for one fifth the price of a "mass produced" car that you knew you'd never be able to find anyone to work on it? That doesn't make any sense. When you're buying a product that is going to need support you'll generally want a product that will have support available. Buying/using products that aren't widely used isn't a great practise. Especially in business.
An if anybody try to complain, file a lawsuit for patent infringment..... surely there is a patent covering what you are doing now !
Big companies will have a cartel of patents, only the small fish will be left out. A pity that the "people" do not know/care about this.
Big companies get patents because they come up with original ideas and they patent them. It isn't their fault that someone else didn't come up with the idea first or was too lazy to patent it.
Just remember that Microsoft was, at one time, a small company. They obviously did *something* right.
Quit your bitching, because it really doesn't matter. Microsoft is here, they own a majority of the desktop market, and they're not going away anytime soon. Linux, or other free software, is not a viable replacement at this point. I believe everyone already knows that.
Microsoft is not the first huge company to dominate an entire market.
Re:Even better (Score:1, Funny)
I'm confused by your analogy. Do you mean that Ashcroft initially ignored his assistant's rack, and now, after realizing that everybody else thinks it's important, is feverishly and unsuccessfully trying to enhance it?
Sounds like he is preparing to run for office (Score:2)
Reminds me of a few friends who are in office and how they answer questions, even non-political ones.
InnerWeb
Re: Microsoft Security... (Score:2)
No, no. The message is: Microsoft will not solve such problems. Microsoft has enough money to buy up e.g. an anty-spyware company, and maybe this way the raise in publicity and the PR will make problems go away. You know: don't see it, doesn't exist.
Re:Linux users always crack me up (Score:2)
Sure, my 12-year-old niece can download and play MP3s in XP, do her homework in MSOffice, install software, etc. But does she update her virus checker, scan her system for spyware, apply regular software updates, etc. etc? Of course not...
I don't doubt your Windows system has been trouble free but you've had to spend a lot of time and effort keeping it that way.
Linux currently has the advantage that it's not targetted for spyware, worms and viruses and in reality, it probably never will be simply because it's very difficult (if not impossible) to find the same version of a single component that runs on most of the Linux machines that connect to the Internet. How can you exploit a vulnerability if only a very small number of people have that vulnerability on their systems?
I'm not denying that Linux can be exploited through buffer overflow attacks on daemons and I probably spend as much time as you applying updates, configuring firewalls and trawling system logs on my Linux systems.
But let's dispel this fantasy that any OS is "easy" - the real problem is that so many Joe Sickpacks have believed the MS hype of "easy Windows" which is why there is now such a huge population of poorly protected PCs out there to spread all manner of unwanted programs.