Home > Trustworthy Computing: Examining Trust

Featured News

Trustworthy Computing: Examining Trust

3/11/2008

When Richard Kemmerer first joined the board of Microsoft's Trustworthy Computing Academic Advisory initiative as one of its inaugural members, he had a caveat for the software giant.

"One of the things I told (Microsoft) was that if you're looking for a yes man, you're barking up the wrong tree, looking in the wrong place, you got the wrong guy. I'm going to call it like I see it."

'Still a Long Way To Go'
Looking back over five years as a member of the panel, which is charged with, among other things, shoring up security, Kemmerer--who is currently a professor of computer science at University of California at Santa Barbara--said he still feels the same way in making what he calls a fair assessment of software and security personnel in Redmond. While he's swift to laud the accomplishments made with the project and with the evolution of Microsoft products and services, he said, "Where security is concerned, there is still a long way to go."

Indeed, as Microsoft celebrates half a decade of the program's existence calling upon expertise from Kemmerer and other scholars and experts from as far away as Tokyo and London, there remains a basic inconsistency between convenience of use and computer security that many believe can never be fully rectified. In the same way that a car alarm may lock a person out of a car for security reasons, Microsoft applications such as Internet Explorer have been known to inflict similar headaches on users recently. Additionally, some IT practitioners have suggested that Microsoft needs to help educate end users in a manner far more comprehensive than its monthly security bulletins.

To that end, Microsoft's position is that it's the IT community's job to stay on top of things and that the aim of the Trustworthy Computing movement is to gather the best objective research to achieve that goal.

"Organizations will need to continue to adapt their processes and technologies to effectively manage data protection as security and privacy threats continue to converge," said David Ladd, principal security program manager for Microsoft. "They will need to find ways for their privacy and security professionals to work together and work more closely with the parts of their organization that collect and use data."

In tandem with helping the software concern identify potential technical and policy hurdles that make security implementation an arduous task, Ladd said the board is doing "great work" to keep Redmond up to date on current and potential issues related to the abuse and theft of personally identifiable information. That said, even Ladd was willing to concede that security and reliability are a going concern, much in the way any business operation is.

"Since the formation of (the board) in February 2003, the group has provided Microsoft with a long-range, strategic international perspective and guidance about security and privacy trends," Ladd added. "They've done this with a focus on supporting Microsoft's efforts to better protect customers through investments in technology innovation and fundamentals, such as the



Recommended Reading
  • RIAA Outsources Fingering of Students Who Share Music Illegally

    The RIAA is outsourcing the hunt for music thieves. Its largest target currently is those who operate from within colleges and universities, a move that has piqued the attention of Educause.

  • Microsoft Expands Education Footprint in Asia Pacific Region

    Microsoft Chairman Bill Gates announced new partnerships to extend accessibility and computer literacy in the Asia Pacific region during a speech in Jakarta at a government leader gathering earlier this week.

  • IT Struggling Over Security, Compliance

    IT pros are having a hard time balancing security, software patch management and IT auditing with a host of other duties, according to a survey released Monday by Shavlik Technologies.

  • Toronto College Upgrades Network with Gigabit Ethernet Wireless Links

    Toronto-based George Brown College has gone public about its deployment of six BridgeWave GE60 wireless links to upgrade its campus-wide network.

  • Gates Highlights R&D at CES08, Unveils Microsoft Touch Wall

    Microsoft's Chairman Bill Gates spent a lot of time Wednesday talking about "empowering the workers" at the Microsoft's 12th annual CEO Summit 2008 in Redmond, WA, where he gave a keynote speech. However, Gates wasn't talking about political revolutions or even pay raises for office workers before the CEO crowd. Instead, he was referring to new software technologies that can better enable collaboration, social networking and decision-making on the job.

  • Vista Vulnerability Study Puts Microsoft on Defensive

    Microsoft and some independent security researchers had the blogosphere buzzing Wednesday over a series of denunciations after one company claimed that the Vista operating system was more vulnerable to malware and other exploits than previous operating systems.