Solution Builder - Channel Insider
Empowering the next generation Channel
 

Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • Control VM Sprawl, What You Don’t Know Can Hurt You
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily
  • LSI 6Gb/s Portfolio Expands to Include SATA+SAS HBAs
  • Reduce the cost of managing your mobile workers.
  • Find out 7 Ways to Drive Data Center Efficiency
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™



  •  

    Microsoft Partners Assess Fallout from Code Leak

    in Solution Builder


    Article Rating:starstarstarstarstar / 0
    Article Views: 1428

    Rate This Article:
    Add This Article To:
    As security experts download, peer at, and analyze leaked source code, the industry still buzzes over last week's Windows security breach. But what impact will the leak have on Microsoft's relationships with channel partners?

    With security experts busily downloading, peering at, and analyzing leaked source code, the industry is still buzzing with controversy over last week's Windows security breach. But what about the impact of the leak on Microsoft's relationships with channel partners? Will Microsoft still be able to trust its partners, and vice versa? Will application security be harmed, or possibly ultimately helped? Opinions range all over the map.

    Now, a security researcher nicknamed GTA has posted a comment to an Internet newsgroup, claiming that he's discovered the first security exploit based on the leaked code.

    "People are gobbling up the code in the newsgroups," noted Jay Jacobsen, an independent security consultant who is also an anonymous participant in newsgroups. "Over 50,000 source code files were leaked. I don't know what the percentage is, in terms of Microsoft's total source code, but that's a whole lot of code," he added.

    Jacobsen, who is CEO of Edgeos, Inc., also predicted that Microsoft might find it tougher to trust its partners, now that MainSoft has been implicated in the code heist. "Many of Microsoft's fans tend to be very loyal. The breach is more likely to cause a lack of trust on Microsoft's part than the other way around."

    Resource Library:
    Next page: What partners are saying

    What partners are saying

    In a series of interviews, many Microsoft partners did seem to be adhering to a true blue attitude. "Microsoft is in an unfortunate position. However, I'm very confident in the seriousness of Microsoft's commitment toward security," said Ezra Davidson, VP for business development at SynCast, a Microsoft customer and corporate development partner.

    On the other hand, trust is "definitely the biggest problem," in the view of Richard Cruit, CEO/CTO of Blue Sky Factory, a Microsoft ASP partner.

    "The Cold War is the best analogy. The code leak has the same impact as if a government spy leaked state secrets. The allies of that country start to question the government's ability to hold a secret," Cruit illustrated.

    By and large, the Windows code leak didn't take anyone by surprise. "The Internet is so easy to use, and so easy to transfer information over, that it's fairly amazing that Microsoft hasn't experienced a 'bad apple' situation before," observed Sean MacIsaac, CTO of Intwine, another solutions partner.

    Partners vary widely, though, in their expectations of security fallout. "The leak does have a chance of hurting security. It seems to have constituted only a small portion of Windows code, and people probably won't be able to do anything that malicious. But this does make us more vulnerable," according to Blue Sky Factory's Cruit.

    "There may be a period of time when code is more vulnerable to viruses and worms," acknowledged Steven Lupinski, CEO of eServer. Also as Lupinski sees it, though, products might eventually become more secure than prior to the leak, as Microsoft is forced to address pre-existing security holes.

    How can Microsoft do a better job of battening down the hatches? Partners raised suggestions ranging from disciplinary action to placing identifier tags on code.

    Next page: Battening down the hatches

    Battening down the hatches

    "I'm not sure exactly how this breach happened – whether a Microsoft employee passed any code around, or whether one of more partners were involved. But Microsoft needs to clearly communicate that source code is very important, and that they need to be careful with it. Maybe Microsoft could threaten to terminate relationships with any partners that leak code," Lupinski recommended.

    Some partners, though, would like to see greater openness by Microsoft from the outset. "I am a fan of open source code. Most developers go with the assumption that vulnerabilities exist in all software code, anyway. We can get at 80 percent of all source code through reverse engineering. However, we'd like to like to be aware of the vulnerabilities from the beginning. Then you'd see the code getting locked down, and becoming safer as a result," according to one developer at a small, Microsoft-certified consultancy on the West Coast.

    "So a lot of people out there in the trenches are saying, 'Let's open it up!' Right now, we're going through a fairly extensive procedure to fix (Windows) code. In contrast, with open source, people can address vulnerabilities in a matter of hours," added the developer, who asked not to be identified.

    "We're a small company in comparison to our partners. Microsoft can be very aggressive in protecting its image, if you know what I mean," the developer contended.





    Discuss Microsoft Partners Assess Fallout from Code Leak
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Solution Builder Articles          >>> More By Jacqueline Emigh
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    Enterprise Mobility Zone
    The Enterprise Mobility Zone (EMZ) blog is a tool designed to help senior IT executives discuss, create and deploy next-generation mobile strategies in their organizations.
    Go beyond yesterday's tactical approach to mobility!
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com