April 21, 2008 2:13 PM PDT

Microsoft's 'chain of trust'

by Jon Oltsik
  • Font size
  • Print
  • 2 comments

It's been a few weeks since the RSA Conference 2008 and I'm now preparing for Interop. Nevertheless, I wanted to get in my two cents worth regarding Craig Mundie's RSA keynote address on what Microsoft is calling "End to End Trust."

End to End Trust? What about the often-discussed Trustworthy Computing initiative that Microsoft introduced in 2001? It's still around but Microsoft realized that Trustworthy Computing alone may not be enough. So what else is needed? Craig Mundie mentioned:

• 1. A chain of trust. As the old security saying goes, "the security chain is only as strong as its weakest link." Microsoft has done a good job making Windows more secure with each iteration but it really doesn't matter if the bad guys compromise your data by hacking in at the application layer. Microsoft is suggesting a model where the entire technology stack must adhere to a trust relationship (i.e., each piece is authenticated and validated and all changes must be approved) where every component relies on the others.

• 2. A new identity model. Identity is no longer about user name and password alone. In today's computing environment, you also have to consider device type (i.e., am I communicating via my PC, cell phone, or PDA?), location, and the user's work and personal profile. Yes, this complicates things but there is no getting around the fact that I use the same laptop to do my job during the day and then bid on vintage Gretsch guitars at night.

• 3. Industry participation. Microsoft readily admits that it can't establish end-to-end trust on its own. Of course, Microsoft won't be shy about suggesting technologies for connectivity and standardization, but it really does need help here. It's time that the security industry stop its outright mistrust of Microsoft and extend an olive branch.

In my view, Mundie's keynote was effective in that it really got the industry's attention. Many security professionals and vendors recognize the need for this End to End Trust model while organizations like the Computer Security Institute (CSI), the National Institute of Standards (NIST), and the Trusted Computing Group (TCG) are already working on similar efforts.

In past years, Microsoft keynotes were full of product demonstrations and funny video montages. Its End to End Trust discussions demonstrate a new Microsoft focus--and the remaining problems associated with information security.

Jon Oltsik is a senior analyst at the Enterprise Strategy Group.

Jon Oltsik is a senior analyst at the Enterprise Strategy Group. He is not an employee of CNET.
Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission
Add a Comment (Log in or register)
It's Microsoft Who Can't be Trusted
by prototerm April 21, 2008 4:31 PM PDT
The biggest problem that I have with this whole "chain of trust" concept is that Microsoft has proven again and again that *it* can't be trusted. How can anyone, from the hardware manufacturers to software vendors to end users, trust a convicted monopoly that has demonstrated its fierce resolve to be the *only* supplier of computer software/services in the world? Look at what happened to the OOXML fiasco, where all sense of fair play and honesty (not to mention interoperability) was tossed out of the ..er... window. And that was just the latest in a long sad line of untrustworthy activity. Remember "Plays for Sure"? How many companies felt betrayed after the Zune came out? The history of computing is littered with the corpses of businesses that trusted Microsoft, much to their dismay.

What Microsoft has in mind is a DRM system for software, where companies must pay a fee to be "authorized" (i.e., work on Windows), and free software need not apply. This is not about security, it's about vendor lock-in and the reduction of choice to one company and its faithful partners.

Before I will allow myself, my family, and those who depend upon me for computer help and advice (I'm a consultant) to take part in this Grand Scheme, Microsoft is going to have to earn back my trust. And it won't be easy, given its history. Fool me once, shame you; fool me twice, shame on me.
Reply to this comment
You can't trust closed code
by rcrusoe April 22, 2008 5:44 AM PDT
If you can't review the code you can't trust the software. That's why those three letter agencies don't allow Windows machines on networks with sensitive or classified data.

"You wouldn't want to do it on Windows NT, because you know nothing about what is going on inside NT,"

http://www.news.com/2100-1001-251927.html
Reply to this comment
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement
Click Here

Inside CNET News

Scroll Left Scroll Right