Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Experts Warn of Microsoft 'Monoculture'
The Pittsburgh Post-Gazette ^ | Feb 15, 2004 | JUSTIN POPE -- AP Business Writer

Posted on 02/15/2004 9:59:24 AM PST by Willie Green

For education and discussion only. Not for commercial use.

CAMBRIDGE, Mass. (AP) -- Dan Geer lost his job, but gained his audience. The very idea that got the computer security expert fired has sparked serious debate in information technology. The idea, borrowed from biology, is that Microsoft Corp. has nurtured a software "monoculture" that threatens global computer security.

Geer and others believe Microsoft's software is so dangerously pervasive that a virus capable of exploiting even a single flaw in its operating systems could wreak havoc.

Just this past week, Microsoft warned customers about security problems that independent experts called among the most serious yet disclosed. Network administrators could only hope users would download the latest patch.

After he argued in a paper published last fall that the monoculture amplifies online threats, Geer was fired by security firm @stake Inc., which has had Microsoft as a major client.

Geer insists there's been a silver lining to his dismissal. Once it got discussed on Slashdot.org and other online forums, the debate about Microsoft's ubiquity gained in prominence.

"No matter where I look I seem to be stumbling over the phrase `monoculture' or some analog of it," Geer, 53, said in a recent interview in his Cambridge home.

In biology, species with little genetic variation - or "monocultures" - are the most vulnerable to catastrophic epidemics. Species that share a single fatal flaw could be wiped out by a virus that can exploit that flaw. Genetic diversity increases the chances that at least some of the species will survive every attack.

"When in doubt, I think of, `how does nature work?'" said Geer, a talkative man with mutton chop sideburns and a doctorate in biostatistics from Harvard University. (The interest persists in his hobby of backyard beekeeping.)

"Which leads you, when you think about shared risk, to think about monoculture, which leads you to think about epidemic. Because the idea of an epidemic is not radically different from what we're talking about with the Internet."

Geer isn't the first to argue that the logic of living viruses also applies to the computer variety, and that the dominance and tight integration of Microsoft operating systems and software makes the global computing ecosystem vulnerable to a cascading failure.

Geer's paper did little more than make the point with particular fervor - which only intensified when Geer was fired.

"The hoopla around him losing his job gave the story some extra frisson," said Internet security expert Bruce Schneier, a co-author of Geer's. "He got fired because @stake wanted to be nice to their masters. But it's like the Christian Church boycotting a movie - everybody wants to see it now."

Microsoft, which denies pressuring @stake to fire Geer, says the comparison between computers and living organisms works only so well.

"Once you start down the road with that analogy, you get stuck in it," said Scott Charney, chief security strategist for Redmond, Wash.-based Microsoft.

Charney says monoculture theory doesn't suggest any reasonable solutions; more use of the Linux open-source operating system, a rival to Microsoft Windows, might create a "duoculture," but that would hardly deter sophisticated hackers.

True diversity, Charney said, would require thousands of different operating systems, which would make integrating computer systems and networks virtually impossible. Without a Microsoft monoculture, he said, most of the recent progress in information technology could not have happened.

Another difference: computers can be unplugged from the network and rebooted; organisms cannot.

The theory also has skeptics outside of Microsoft.

Security consultant Marcus Ranum has emphasized that many network threats have little to do with the vulnerabilites of monoculture. Planting three strains of corn offers insurance against some diseases, he notes, but without a fence, deer will eat all three.

But Ranum also says the monoculture story "would barely be news" if @stake "hadn't done a brilliant surgical marketing strike on its left foot by firing Dan."

At an October hearing of the House Government Reform Committee's technology subcommittee, Steven Cooper - the Homeland Security Department's chief information officer - was questioned about the federal government's vulnerability to monoculture.

Cooper acknowledged it was a concern and said the department would likely expand its use of Linux and Unix as a precaution.

The monoculture idea is also influencing how experts look for solutions to security problems.

Mike Reiter of Carnegie-Mellon University and Stephanie Forrest, a University of New Mexico biologist who has been gleaning lessons for computer security from living organisms for years, recently received a $750,000 National Science Foundation grant to study methods to automatically diversify software code.

Daniel DuVarney and R. Sekar of the State University of New York-Stony Brook are exploring "benign mutations" that would diversify software, preserving the functional portions of code but shaking up the nonfunctional portions that are often targeted by viruses.

Geer - who continues to consult, lecture and work with a startup these days - believes monoculture theory points the way to possible solutions that are dramatic, and haven't always been followed. They would require, for example, banning from the Internet computers whose software hasn't been updated with the latest anti-virus patches.

Geer doesn't believe breaking up Microsoft is the answer, even though his paper was published by the Computer and Communications Industry Association, which aggressively backed the antitrust case that tried to split up the company.

But Geer says the company should disentangle its tightly integrated products, such as Microsoft Word and Outlook.

Microsoft contends, as it did during its antitrust trial, that the integration of those products is the heart of what it offers consumers.

Still, Microsoft's Charney doesn't entirely dismiss the idea of examining computer security through a biological lens. "Although biodiversity-monoculture issues may be more complex than people have been thinking about them, it does not mean you can't learn from it and draw some parallels," he said.

Geer calls such comments proof the idea is resonating.

"You see Microsoft talking about it," he said, "when before, they didn't."


TOPICS: Business/Economy; Culture/Society
KEYWORDS: globalism; lowquality; microsoft; monopoly; nosecurity; security
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-69 last
To: HAL9000
The Apple ][ was not a "technological advantage" over the Mac.

If you wanted (or needed) color it was. Apple underestimated this feature for graphics and games and when the color EGA 286's from IBM/Zenith etc came out they answered the only shorcoming of the PC, while Apple seemed to be going backwards to the tiny B/W screen. Resulting sales of the two speaks for itself, people just weren't going pay more for something that didn't run "print shop" in color, the post visi-calc killer app of the day.

61 posted on 02/20/2004 10:34:12 AM PST by Golden Eagle
[ Post Reply | Private Reply | To 58 | View Replies]

To: general_re
Keyword: LOWQUALITYCRAP
62 posted on 02/20/2004 10:35:31 AM PST by general_re (Ubi solitudinem faciunt, pacem appellant. - Tacitus)
[ Post Reply | Private Reply | To 60 | View Replies]

To: general_re
I think we've figured out who keeps spamming the keywords an any thread even vaguely about Windows. Is there a particular reason you like polluting the search function here?

I didn't invent the phrase, but it is synonymous with Microsoft products - and it's a precise and useful way to retrieve articles about worms, viruses, spyware, and other Windows problems. As a keyword, lowqualitycrap works very well, and it doesn't meet the definition of keyword pollution.

If you don't like a particular keyword, you can send a complaint to the moderators. They have the ability to delete keywords, but those situations usually involve keywords that are personal attacks or profanity.

Actually, the biggest problem is threads that contain no keywords at all.

63 posted on 02/20/2004 10:46:16 AM PST by HAL9000
[ Post Reply | Private Reply | To 60 | View Replies]

To: HAL9000
Thank you for not insulting me by denying it. That being said, it is inflammatory and unnecessary, not to mention childish and petulant - I rather doubt you would be so sanguine were someone else running around and attaching the keyword "Macintrash" to any Apple-related thread or "Linuxcommies" to any thread that happened to mention the GPL, but that sort of thing is the inevitable result of making a habit of this. Eventually, others will also abuse the keywords in this fashion, which can only lead to a reduction in the usefulness of the keywords, or a crackdown by the moderation staff once it gets seriously out of hand.

If you wish to search for "Windows" or "Microsoft" or "Virus", allow me to suggest the use of "Windows" or "Microsoft" or "Virus" as keywords. If keywords such as those are not fine-grained enough to capture the threads you are interested in, your browser undoubtedly has a bookmark function whereby you may capture all the threads you wish in order to snicker in secret glee at others, without also turning the keywords into your own private playground. And if you wish to promote the idea that Microsoft products are, in fact, low-quality crap, the proper place to do that is on the thread where your points may be examined, addressed, and rationally discussed. That would be in contrast to promoting an agenda via the keywords, which are intended to serve as a means of indexing and retrieving articles, not as a side-thread for further debate, nor as a platform from which to snipe at people whose choices you happen to disagree with.

I can't make you stop. I really have no interest in trying. I'm not about to ping the mods, because I have other ways of dealing with it than in involving them. But I'm asking you to stop nonetheless - it reflects poorly upon you, it serves no purpose that cannot be served in a less inflammatory way, and it will only lead to further abuses by others.

64 posted on 02/20/2004 11:07:58 AM PST by general_re (Ubi solitudinem faciunt, pacem appellant. - Tacitus)
[ Post Reply | Private Reply | To 63 | View Replies]

To: Golden Eagle
If you wanted (or needed) color it was. Apple underestimated this feature for graphics and games and when the color EGA 286's from IBM/Zenith etc came out they answered the only shorcoming of the PC, while Apple seemed to be going backwards to the tiny B/W screen.

A high-resolution, high-frequency color screen would have been prohibitively expensive in the original Mac, but the operating system did contain some support for color graphics. The original Mac also supported networked laser printers when PCs were restricted to impact dot matrix printers. Given the choice of Apple ][/DOS low resolution color graphics and Mac's crisp, professional looking black and white graphics, most professionals would choose the Mac.

65 posted on 02/20/2004 11:08:56 AM PST by HAL9000
[ Post Reply | Private Reply | To 61 | View Replies]

To: HAL9000
The Mac patterns were hard on the eyes, many people just upgraded to RGB cards in their Apple II's instead, even the IIc's. But that full Apple II market was squandered as the IIGS was way too late and many of us had already gone with PCs. And NOT PCs from IBM.

I for one wish Apple well, always have. They've just never done anything to lure me back. If they lowered their price some, it would help.
66 posted on 02/20/2004 11:38:08 AM PST by Golden Eagle
[ Post Reply | Private Reply | To 65 | View Replies]

To: general_re
But I'm asking you to stop nonetheless - it reflects poorly upon you, it serves no purpose that cannot be served in a less inflammatory way, and it will only lead to further abuses by others.

Thanks for the suggestion, but I respectfully decline. If it's any consolation, I'll make this pledge: The first time that Macs get hit with a real worm, virus or spyware spreading in the wild, I'll post the lowqualitycrap keyword on that thread too.

Since many FReepers are having a rotten, miserable experience with Windows, I simply want to point out that there are better platforms available.

67 posted on 02/20/2004 2:28:21 PM PST by HAL9000
[ Post Reply | Private Reply | To 64 | View Replies]

To: HAL9000
Whatever.
68 posted on 02/21/2004 8:15:41 AM PST by general_re (Ubi solitudinem faciunt, pacem appellant. - Tacitus)
[ Post Reply | Private Reply | To 67 | View Replies]

To: Swordmaker; Ernest_at_the_Beach; martin_fierro

Note: this topic is from February 15, 2004.

Nice to get a five year perspective, not least on the comment stream.
69 posted on 01/03/2010 4:33:51 PM PST by SunkenCiv (Happy New Year!)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-69 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson