Archive for March, 2009

Security is a never ending journey

I’m at the 2009 Microsoft MVP Sum­mit. Around 2000 MVP’s descend on Microsoft’s Red­mond Cam­pus for four days of ses­sions with var­i­ous prod­uct teams. The ses­sions include a lot of two way feed­back, which can be bru­tal from both sides. It’s a lot of fun. Today I went to sev­eral secu­rity ses­sions. I got to hear Steve Riley talk and then answer ques­tions from an audi­ence that included Jes­per Johans­son. It was amaz­ing. At one ses­sion Ziv Mador and Steve Adeg­bite were talk­ing about the Con­ficker worm and Microsoft’s response to the vul­ner­a­bil­ity the worm ini­tially used to spread itself. It was fas­ci­nat­ing to hear the process they went through to iden­tify the vul­ner­a­bil­ity and patch it then have to wait and see the exploits devel­oped when the bad guys reverse engi­neer the patch. Dur­ing the ses­sion Steve Adeg­bite said some­thing that really res­onated with me. He said “Secu­rity is like a never end­ing marathon.” I think that is one of the best state­ments I’ve heard regard­ing secu­rity. Secu­rity is hard work. You have to give it 100% all the time. There are no short­cuts. You will never be fin­ished. To some that sounds depress­ing. Steve Adeg­bite said it was a chal­lenge he and his team rel­ished. I got the sense that almost every­one in the room agreed. I realised I was sit­ting in room full of the cream of the crop in the Win­dows secu­rity world. It was fun hob­nob­bing with the cream of the crop. Thank you Microsoft.