Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

FBI, Pentagon Quiz Microsoft on XP
dailynews.yahoo.com ^

Posted on 12/23/2001 6:55:43 AM PST by TaRaRaBoomDeAyGoreLostToday!

FBI, Pentagon Quiz Microsoft on XP

WASHINGTON (AP) - The FBI (news - web sites)'s top cyber-security unit warned consumers and corporations Friday night to take new steps beyond those recommended by Microsoft Corp. to protect against hackers who might try to attack major flaws discovered in the newest version of Windows software.

The FBI's National Infrastructure Protection Center said that, in addition to installing a free software fix offered by Microsoft on the company's Web site, consumers and corporations using Windows XP (news - web sites) should disable the product's ``universal plug and play'' features affected by the glitches.

The FBI did not provide detailed instructions how to do this. Microsoft considers disabling the ``plug and play'' features unnecessary.

The company acknowledged this week that Windows XP suffers from serious problems that allow hackers to steal or destroy a victim's data files across the Internet or implant rogue computer software. The glitches were unusually serious because they allow hackers to seize control of all Windows XP operating system software without requiring a computer user to do anything except connect to the Internet.

Outside experts cautioned that disabling the affected Windows XP features threatens to render unusable an entire category of high-tech devices about to go on the market, such as a new class of computer printers that are easier to set up. But they also acknowledged that disabling it could afford some protection against similar flaws discovered in the future.

The FBI, in a bulletin released at 8 p.m. at the start of a long holiday weekend, also warned professional computer administrators to actively monitor for specific types of Internet traffic that might indicate an attack was in progress.

A top Microsoft security official, Steve Lipner, sought to reassure consumers and companies that installing the free fix was the best course of action to protect their systems.

Friday's warning from the FBI's cyber-protection unit came after FBI and Defense Department officials and some top industry experts sought reassurance from Microsoft that the free software fix it offered effectively stops hackers from attacking the Windows XP flaws.

The government's rare interest in the problems with Windows XP software, which is expected to be widely adopted by consumers, illustrates U.S. concerns about risks to the Internet. Friday's discussions came during a private conference call organized by the National Infrastructure Protection Center.

During the call, Microsoft's experts acknowledged the threats posed by the Windows XP problems, but they assured federal officials and industry experts that its fix - if installed by consumers - resolves the issues.

Microsoft declined to tell U.S. officials how many consumers downloaded and installed its fix during the first 24 hours it was available. Experts from Internet providers, including AT&T Corp., argued that information was vital to determine the scope of the threat.

Microsoft also indicated it would not send e-mail reminders to Windows XP customers to remind them of the importance of installing the patch.

Microsoft explained that a new feature of Windows XP can automatically download the free fix, which takes several minutes, and prompt consumers to install it.

``The patch is effective,'' said Lipner, Microsoft's director of security assurance, in an interview with The Associated Press.

Officials expressed fears to Microsoft about possible electronic attacks targeting Web sites and federal agencies during next week's Christmas holidays from computers running still-vulnerable versions of Windows, participants said.

Several experts said they had already managed to duplicate within their research labs so-called ``denial of service'' attacks made possible by the Windows XP flaws. Such attacks can overwhelm Web sites and prevent their use by legitimate visitors.

Another risk, that hackers can implant rogue software on vulnerable computers, was considered more remote because of the technical sophistication needed.

The FBI's cyber-security unit has been concerned about the threat and warned again Thursday that the potential of ``denial of service'' attacks is high. The agency said people unhappy with U.S. policy have indicated they plan to target the Defense Department's Web sites, as well as other organizations that support the nation's most important networks.

-

On the Net:

NIPC.gov

Microsoft Security


TOPICS: Front Page News; News/Current Events
KEYWORDS: techindex
Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100 ... 241-247 next last
To: TruthShallSetYouFree
Microsoft's error is not one of intentions, but of poor implementation. Yet, again.

I agree. I'm having a hard time seeing this as a defective product issue. To me, the test is wheather the product performs as advertised when used as intended. I wouldn't consider a lawnmower defective if it wouldn't run because someone snuck into my garage and filled the gas tank with water.

61 posted on 12/23/2001 8:15:41 AM PST by tacticalogic
[ Post Reply | Private Reply | To 51 | View Replies]

To: Petronski
LOL!!!May be...I downloaded it twice, before and after Norton Internet Security which came with my puter.
62 posted on 12/23/2001 8:16:09 AM PST by TaRaRaBoomDeAyGoreLostToday!
[ Post Reply | Private Reply | To 54 | View Replies]

To: Dominic Harr
And "not allowing anyone from outside to take total control of you machine" is clearly a fundamental part of the 'purchase of an OS' transaction.

And that is where the argument lies. I can see some valid points on both sides. To be fair MS has had this problem with IIS server. So I'd have to say that anytime you connect to the internet you open up all sorts of vulnerabilities. Again, if you want safety you purchase Volvo and Linux.

Why do ya'll want MS to be immune to the law?

I don't. But the law today is mostly garbage. It has been clutered with all sorts of violations of common sense. MS should not be above the law, nor below it. But no one should be subjected to the laws we have today.
63 posted on 12/23/2001 8:17:55 AM PST by verboten
[ Post Reply | Private Reply | To 44 | View Replies]

To: tacticalogic
Even Mac's need a ton of driver and other updates...But Mac's firewall is the best.
64 posted on 12/23/2001 8:18:24 AM PST by TaRaRaBoomDeAyGoreLostToday!
[ Post Reply | Private Reply | To 61 | View Replies]

To: TaRaRaBoomDeAyGoreLostToday!
I'm not a computer wiz, but I think what I did was sign up for their free update notification service.

Go START, HELP AND SUPPORT, and the chose KEEP YOUR COMPUTER UP-TO-DATE. Then follow instructions.

I usually skip these 'Lets Bash MS Some More' threads because it brings out the more emotional(liberal) side of FR posters, leaving the rational thinking side of the brain to rest a bit.

One thing I've noticed was how RealPlayer (for example) can invade my computer memory and screen area and yet no complaining from anyone. Its the devil to get it out, and I haven't really got their infectus software tamed. Yet MS, which has consistantly, over the years, made major improvements to it's OS gets slammed.

The improvements are of such magnitude that I can now run really crappy 3rd party software (I have no choice but to do so) and WIN will just ignore all of the bugs in it. My computer has crashed maybe once or twice in the past 18 months. The crappy 3rd party software has caused about 200-300 crashworthy problems in that time. Task manger has allowed me to pinpoint them and 'cut-off' the offending file, or whatever. Like I said I'm not a wiz, but like everyone else I know when things aren't working.

Flame away, but when something works as good as WIN 2000 and now XP, I'm an avid supporter. It's made my life much easier.

65 posted on 12/23/2001 8:18:40 AM PST by Balding_Eagle
[ Post Reply | Private Reply | To 22 | View Replies]

To: Glenn
"Yes. You do."

Aw, don't spoil the fun. Let him keep digging himself in deeper and deeper and deeper. It'll be fun to watch the New Dominick go "Mnfph pfmfpfh mnftp!" when people taunt him after his attacks come home to roost and he's... well, why ruin the surprise. :)

66 posted on 12/23/2001 8:18:42 AM PST by Don Joe
[ Post Reply | Private Reply | To 19 | View Replies]

To: Dominic Harr
this has got to stop
67 posted on 12/23/2001 8:19:19 AM PST by TruthShallSetYouFree
[ Post Reply | Private Reply | To 59 | View Replies]

To: TruthShallSetYouFree
Is the whole world their beta-testers? (Even I know the answer to that is yes.)
Confirming, Yes is the answer. Unfortunately, more and more are doing it, not just MS. Not just S/Ware either. And another trendy change lately, they are not printing manuals to go with their products, "It's online, after you install the product" is the most common reply I get these days. Of course it's useless until you get the product up and running, in most cases. Blackbird.
68 posted on 12/23/2001 8:19:46 AM PST by BlackbirdSST
[ Post Reply | Private Reply | To 10 | View Replies]

To: Dominic Harr
"What is it about MS that makes people put them above the law?"

What is it about MS-haters that makes them think they are above the law?

69 posted on 12/23/2001 8:20:39 AM PST by Don Joe
[ Post Reply | Private Reply | To 29 | View Replies]

To: TaRaRaBoomDeAyGoreLostToday!
Why are they doing this spying thing? A person only has to use linux for communications. The only people they are hurting are the honest people. The FBI, out of their LUST to spy on it's own citizenry, are introducing this huge hacker backdoor.

The FBI is a fountain of undiluted incompetence.
70 posted on 12/23/2001 8:21:16 AM PST by Texas_Longhorn
[ Post Reply | Private Reply | To 1 | View Replies]

To: verboten
It has been clutered with all sorts of violations of common sense.

Is the basic law that a company can't knowingly sell defective goods a violation of common sense?

I'd say that is a very important, basic one. And MS has just violated it terribly.

With IIS, the buffer over-run vulerabiliy was known to the public. In this case, only MS and the one security company knew.

MS knowingly continued to sell a defective product. All they had to do was inform their customers to *turn the thing off*.

For their profits, they didn't.

71 posted on 12/23/2001 8:21:30 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 63 | View Replies]

To: TaRaRaBoomDeAyGoreLostToday!
Query has anyone had problems after applying the patch.

I started receiving an lsass error on boot and the system would not boot unit I did a system roll back and unistalled the patch.

72 posted on 12/23/2001 8:22:19 AM PST by dts32041
[ Post Reply | Private Reply | To 1 | View Replies]

To: Don Joe
What is it about MS-haters that makes them think they are above the law?

Ya'll have been threatening me with lawsuits to shut me up for almost 2 years now.

Do you really think anyone cares?

I'd consider it a badge of honor if MS tried to sue me for informing people of MS's law-breaking.

MS 'business tactic' #324 -- sue people.

73 posted on 12/23/2001 8:24:58 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 69 | View Replies]

To: Mixer;innocentbystander;bush2000
"If this doesnt wake up the world and make them all switch to Linux I dont know what will."

Um, perhaps the availabiltity of applications?

My sides, my sides, etc.

PS: don't jive me with any of that "Star Office" crap either, sonny.

74 posted on 12/23/2001 8:25:52 AM PST by Don Joe
[ Post Reply | Private Reply | To 48 | View Replies]

To: Don Joe
So tell me why MS didn't inform it's customers to turn this 'feature' off 5 weeks ago, when they found out about it?

Why did they continue to sell this to millions?

75 posted on 12/23/2001 8:27:47 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 74 | View Replies]

To: Dominic Harr
I didn't threaten you with anything, sonny. I merely expressed my opinion. *You* didn't like my opinion, so you libeled me by fraudulently accusing me of threatening you.

You're a sad piece of work, Batchmo.

PS: you're not my "critic". You're merely a pesky nuisance.

76 posted on 12/23/2001 8:30:01 AM PST by Don Joe
[ Post Reply | Private Reply | To 55 | View Replies]

To: Don Joe
I didn't threaten you with anything, sonny.

You and innocentbystander have explicitly threatened me with a lawsuit in the past.

Innocent has also threatened to beat me up.

Your posts -- several of them -- was *clearly* more of the same.

Here on FR, threatening the other side in a debate with a lawsuit is called 'losing the debate'.

77 posted on 12/23/2001 8:31:43 AM PST by Dominic Harr
[ Post Reply | Private Reply | To 76 | View Replies]

To: SevenDaysInMay
"Until softwear companies are held financially responsible for their defective products, we will always absorb the significant costs of producers' negligence."

Um, panties in a knot?

78 posted on 12/23/2001 8:32:38 AM PST by Don Joe
[ Post Reply | Private Reply | To 60 | View Replies]

To: Dominic Harr
Why did they continue to sell this to millions?

Keep talking, Dominic. I can use the sleep.

79 posted on 12/23/2001 8:32:39 AM PST by Glenn
[ Post Reply | Private Reply | To 75 | View Replies]

To: Dominic Harr
I don't know how much experience you have with MS bugs, but this is SoP for MS.

The MS SOP is: sell the Beta Version with fingers crossed.

80 posted on 12/23/2001 8:33:08 AM PST by bimbo
[ Post Reply | Private Reply | To 6 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100 ... 241-247 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson