Martin Courtney

Too much security can be a bad thing

Efforts to build solid security into software prior to release could have some unwelcome consequences

Written by Martin Courtney

According to at least one expert, Microsoft’s newly launched Windows Vista is full of security holes. Plus ça change. But if web-enabled operating systems or applications could ever be made watertight, would they actually be a good thing for either developers or users of enterprise software?

Kapersky Lab’s virus analyst Alisa Shevchenko recently praised Microsoft for taking a closer look at security, and appeared certain that Vista’s developers made “a concerted effort to integrate protection against cyber threats” within the operating system.

That seems a fair assumption to make, given the vast array of programming talent at Microsoft’s disposal. However, even if Microsoft has done its level best, that is no guarantee that Vista will not be plagued by the same level of web-borne threats as XP.

It has often been suggested that application developers themselves should take responsibility for ensuring software security, rather than leaving it to third-party add-ons to fill in the gaps. There have even been calls for software companies to shoulder the burden of compensation should enterprise customers suffer data loss, outages or other revenue-sapping catastrophes as a result of hackers breaking into their systems because of vulnerable software defences.

This is partly the reason behind development tools like those being offered by Borland and Cenzic, which are designed to identify and fix vulnerabilities in source code before final versions of software are released.

But vulnerability checking within web applications can only go so far – it can never deliver a completely safe end-product that is immune to the ravages of everything the hacker community can throw at it. Any aspiring cyber terrorist needs something to shoot at before figuring out the best way to take aim, so it remains impossible for programmers to anticipate every form of attack that might ever be directed at their application.

Perhaps more importantly, stronger security always seems to come at the expense of usability, with productivity constantly being hampered by pop-up windows warning of potential threats and asking what the user would like to do.

The ability to eliminate software vulnerabilities prior to release could have another, more catastrophic affect on the development community. Many programmers rely on work writing patches and bug fixes to make a living – if the day finally comes when this skill is no longer needed, they may well have to start looking for alternative sources of work.

Tags:

reader comments

related articles

Picture of Vista logo

Vista vulnerable to malware

Sophos finds three of top 10 malware threats can bypass Vista security 01 Dec 2006

 

Vista crack programs hiding malware

Trojans being bundled with piracy software, claims researcher 26 Jan 2007

Business review: Windows Vista

Microsoft’s new Windows client brings improvements in security, usability and administration 29 Nov 2006

Vista security finds defenders

There are divided views on Microsoft's Vista disclosure 23 Oct 2006

today's top stories

Analysis: The true cost of printing

Organisations need to get a better sense of how much they spend on printing before finding ways to reduce it 05 Sep 2008

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Looking to the future - exclusive Michael Dell interview

Dell's chief executive talks to Computing about the way the company continues to adapt to major changes in the industry 04 Sep 2008

Interview: Delivering power where it's needed at Betfair

The online gambling firm is putting its money on grid computing and virtualisation to underpin global expansion 04 Sep 2008

E-paper displays are an open book

A display revolution is on the way - but only once the user interface issues are solved 04 Sep 2008

Most commented stories

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Would you use a mobile phone as an alternative to cash?

Would you use a mobile phone as an alternative to cash?

When mobile phones include inbuilt payment technology - would you use one instead of cash?

Previous poll results

Latest audio and video articles

BlackBerry BoldVideo

Video Review: BlackBerry Bold

Technology editor Daniel Robinson takes a hands-on look at the latest device from Research in Motion 01 Sep 2008

Podcast imageAudio

Computing podcast 4 September 2008

Find out what Michael Dell told Computing, and listen to our take on the latest browser wars 04 Sep 2008

Latest in-depth articles

A meetingAnalysis

Turning adversity into an advantage

IT chiefs under pressure to make cost cuts can turn the situation to their benefit 04 Sep 2008

CloudAnalysis

How to introduce cloud computing into your organisation

Best practice advice from Forrester Research 04 Sep 2008

Primary Navigation