Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

FBI, Pentagon Quiz Microsoft on XP
dailynews.yahoo.com ^

Posted on 12/23/2001 6:55:43 AM PST by TaRaRaBoomDeAyGoreLostToday!

FBI, Pentagon Quiz Microsoft on XP

WASHINGTON (AP) - The FBI (news - web sites)'s top cyber-security unit warned consumers and corporations Friday night to take new steps beyond those recommended by Microsoft Corp. to protect against hackers who might try to attack major flaws discovered in the newest version of Windows software.

The FBI's National Infrastructure Protection Center said that, in addition to installing a free software fix offered by Microsoft on the company's Web site, consumers and corporations using Windows XP (news - web sites) should disable the product's ``universal plug and play'' features affected by the glitches.

The FBI did not provide detailed instructions how to do this. Microsoft considers disabling the ``plug and play'' features unnecessary.

The company acknowledged this week that Windows XP suffers from serious problems that allow hackers to steal or destroy a victim's data files across the Internet or implant rogue computer software. The glitches were unusually serious because they allow hackers to seize control of all Windows XP operating system software without requiring a computer user to do anything except connect to the Internet.

Outside experts cautioned that disabling the affected Windows XP features threatens to render unusable an entire category of high-tech devices about to go on the market, such as a new class of computer printers that are easier to set up. But they also acknowledged that disabling it could afford some protection against similar flaws discovered in the future.

The FBI, in a bulletin released at 8 p.m. at the start of a long holiday weekend, also warned professional computer administrators to actively monitor for specific types of Internet traffic that might indicate an attack was in progress.

A top Microsoft security official, Steve Lipner, sought to reassure consumers and companies that installing the free fix was the best course of action to protect their systems.

Friday's warning from the FBI's cyber-protection unit came after FBI and Defense Department officials and some top industry experts sought reassurance from Microsoft that the free software fix it offered effectively stops hackers from attacking the Windows XP flaws.

The government's rare interest in the problems with Windows XP software, which is expected to be widely adopted by consumers, illustrates U.S. concerns about risks to the Internet. Friday's discussions came during a private conference call organized by the National Infrastructure Protection Center.

During the call, Microsoft's experts acknowledged the threats posed by the Windows XP problems, but they assured federal officials and industry experts that its fix - if installed by consumers - resolves the issues.

Microsoft declined to tell U.S. officials how many consumers downloaded and installed its fix during the first 24 hours it was available. Experts from Internet providers, including AT&T Corp., argued that information was vital to determine the scope of the threat.

Microsoft also indicated it would not send e-mail reminders to Windows XP customers to remind them of the importance of installing the patch.

Microsoft explained that a new feature of Windows XP can automatically download the free fix, which takes several minutes, and prompt consumers to install it.

``The patch is effective,'' said Lipner, Microsoft's director of security assurance, in an interview with The Associated Press.

Officials expressed fears to Microsoft about possible electronic attacks targeting Web sites and federal agencies during next week's Christmas holidays from computers running still-vulnerable versions of Windows, participants said.

Several experts said they had already managed to duplicate within their research labs so-called ``denial of service'' attacks made possible by the Windows XP flaws. Such attacks can overwhelm Web sites and prevent their use by legitimate visitors.

Another risk, that hackers can implant rogue software on vulnerable computers, was considered more remote because of the technical sophistication needed.

The FBI's cyber-security unit has been concerned about the threat and warned again Thursday that the potential of ``denial of service'' attacks is high. The agency said people unhappy with U.S. policy have indicated they plan to target the Defense Department's Web sites, as well as other organizations that support the nation's most important networks.

-

On the Net:

NIPC.gov

Microsoft Security


TOPICS: Front Page News; News/Current Events
KEYWORDS: techindex
Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 241-247 next last
To: verboten
But when you say "only this time, there is proof that they knew 5 weeks ago" doesn't that imply that asserting that prior bugs were known but not revealed was mere speculation?

I'm not talking about issuing a patch, I'm talking about selling a product they knew was defective.

Are you suggesting that we should allow companies to sell products they know to be defective?

21 posted on 12/23/2001 7:43:34 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 15 | View Replies]

To: Balding_Eagle
I recieved no such notification of an update as my entire puter and XP was brand new.I found the patch/info. because of FR.
22 posted on 12/23/2001 7:44:12 AM PST by TaRaRaBoomDeAyGoreLostToday!
[ Post Reply | Private Reply | To 12 | View Replies]

To: Glenn
You do.

Let me get this straight -- you believe a company can knowingly sell a defective product legally?

23 posted on 12/23/2001 7:44:32 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 19 | View Replies]

To: Dominic Harr
you believe a company can knowingly sell a defective product legally?

As opposed to giving it away like Linux?

Can you cite law or not? Do you believe laws that apply to gas tanks are the same ones that cover software?

24 posted on 12/23/2001 7:46:50 AM PST by Glenn
[ Post Reply | Private Reply | To 23 | View Replies]

To: Glenn
If a car dealer sells me an auto in which the radio doesn't work, and they *knew* it didn't work yet chose not to inform me, I have legal recourse.

That same law applies in this case.

25 posted on 12/23/2001 7:46:50 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 19 | View Replies]

To: Glenn
Most consumer protection laws are enforced by the individual states. Here is the one for Massachusetts, for example:

link

26 posted on 12/23/2001 7:46:51 AM PST by TruthShallSetYouFree
[ Post Reply | Private Reply | To 19 | View Replies]

To: SurferDoc
Is this a vulnerability to networked computers only?

I would have liked to see if our machine had upnp enabled before we downloaded and installed the patch. Never thought to do that.

I believe it is a vulnerability for anyone who is connected to the internet. Get behind a firewall like Black Ice or Zone Alarm.

27 posted on 12/23/2001 7:47:20 AM PST by brewcrew
[ Post Reply | Private Reply | To 20 | View Replies]

To: TruthShallSetYouFree
Well I agree that MS encounters many problems. But the very purpose of the market is to determine through trial and error what is good and what is bad. It is impossible for anyone to predict all things. This does not stop the government from asserting it can, but a realistic consideration tells us that only by giving a product to the world can its strengths and weaknesses be fully determined.

Possibly the reason that a clever 14 year old can break software is because he is 14. His mind has not been subjected to the forces of conformity. He did not attend a college computer class where some ivory tower professor told him how to do things. The 14 year old with his youthful energy tries everything. And in trying everything he stumples across many more truths than the average MS programmer learned in 4 years of college, and 10 years at MS.
28 posted on 12/23/2001 7:48:01 AM PST by verboten
[ Post Reply | Private Reply | To 10 | View Replies]

To: Glenn
So MS defenders don't want Anti-trust laws or consumer protection laws to apply to MS.

What is it about MS that makes people put them above the law?

29 posted on 12/23/2001 7:48:05 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 24 | View Replies]

To: Dominic Harr
That same law applies in this case.

You can't be serious.

30 posted on 12/23/2001 7:50:36 AM PST by Glenn
[ Post Reply | Private Reply | To 25 | View Replies]

To: TruthShallSetYouFree
Thank you for looking that up. I didn't even see a need to 'prove' that, since I know the MS defenders know the truth and are just obfuscating on purpose.

May I quote from your link?

When you buy a product from a merchant, by state law it comes with an automatic warranty which says that the product will function normally, for its intended purpose, for a reasonable period of time. This is an implied warranty of merchantability.

If the product is defective at purchase, or becomes defective during the period of the implied warranty, both the seller and the manufacturer are responsible for making it right.

Under Massachusetts law, a merchant cannot sell a product "as is." A store's regular return policy does not apply in the case of defective goods.

31 posted on 12/23/2001 7:50:48 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 26 | View Replies]

To: Glenn
You can't be serious.

What, that the law should apply to MS?

Believe it or not, yes it should.

32 posted on 12/23/2001 7:51:30 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 30 | View Replies]

To: Dominic Harr
So MS defenders don't want Anti-trust laws or consumer protection laws to apply to MS.

Expectations for software are different than those of autmobiles. You must be awfully new to the industry not to understand that.

33 posted on 12/23/2001 7:51:58 AM PST by Glenn
[ Post Reply | Private Reply | To 29 | View Replies]

To: TaRaRaBoomDeAyGoreLostToday!

Buy a Mac!!!

34 posted on 12/23/2001 7:52:41 AM PST by big'ol_freeper
[ Post Reply | Private Reply | To 1 | View Replies]

To: Dominic Harr
Can you cite this law, please?

Seriously?

Yes, please cite. There is no such law, what you are posting is a figment of your imagination.

35 posted on 12/23/2001 7:54:28 AM PST by Balding_Eagle
[ Post Reply | Private Reply | To 17 | View Replies]

To: Dominic Harr
May I quote from your link?

Apparently, you already did. I'll sue :)

36 posted on 12/23/2001 7:54:54 AM PST by TruthShallSetYouFree
[ Post Reply | Private Reply | To 31 | View Replies]

To: Glenn
Expectations for software are different than those of autmobiles.

You're referring to the EULA, which tries to claim that the software company isn't liable for anything.

Such a contract is illegal and completely unenforcable, like the EULA restriction in MS's 'FrontPage' that says you can't use the software to make a site that criticizes MS.

You can't contractually remove basic consumer rights. If a company knowingly sells a defective product without informing customers of that defect, they have broken the law.

37 posted on 12/23/2001 7:55:03 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 33 | View Replies]

To: Dominic Harr
Let me get this straight -- you believe a company can knowingly sell a defective product legally?

Happens every day.

38 posted on 12/23/2001 7:56:15 AM PST by Balding_Eagle
[ Post Reply | Private Reply | To 23 | View Replies]

To: verboten
The 14 year old with his youthful energy tries everything. And in trying everything he stumples across many more truths than the average MS programmer learned in 4 years of college, and 10 years at MS.

Are you lurking, Mr. Gates? We've stumbled upon an ultimate truth. Start hiring some clever fourteen year-olds. (Probably wouldn't be a bad idea.)

39 posted on 12/23/2001 7:56:48 AM PST by TruthShallSetYouFree
[ Post Reply | Private Reply | To 28 | View Replies]

To: Dominic Harr
MS has known about the exploit for 5 weeks

Wrong!

MS has know about the potential for the problem since the design phase of W2k and ME, more than two years ago.

Steve Gibson tried to warn them in June 2001 but they wouldn't listen. A hacker finally got around to probing the know weakness this past summer. MS was notified some weeks ago.

40 posted on 12/23/2001 7:56:54 AM PST by Amerigomag
[ Post Reply | Private Reply | To 2 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-6061-80 ... 241-247 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson