Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Beating Feds to the Punch

    Written by

    Dennis Fisher
    Published January 6, 2003
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      In most security circles, the federal government does not exactly enjoy what one would call a stellar reputation. Years of missteps and wrongheaded attempts to rein in innovation, not to mention leaky security in its own networks, has done little to help the government win the hearts and minds of security experts and technologists.

      In fact, the mere mention of the words “Clipper chip” in certain company is enough to provoke lengthy diatribes against Big Brother and impassioned defenses of capitalism and the free-market economy.

      Consequently, when the Presidents Critical Infrastructure Protection Board last fall published its plan for defending and strengthening the nations fragile networks, it was greeted with a healthy dose of skepticism—if not outright hostility. Many in the security community, as well as the high-tech industry at large, derided the strategy as too soft and lacking clear direction.

      There was, however, one underlying theme in the strategy that may have gone unnoticed: If the software industry doesnt begin producing more reliable, secure software on its own, the government will force it to do so.

      While this may seem like more government heavy-handedness, some top industry security officials believe its a step in the right direction.

      “I do think theres a subtext in that if the industry doesnt face up to this, we will face some legislation,” said Mary Ann Davidson, chief security officer at Oracle Corp., in Redwood Shores, Calif. “Its been the dirty little secret—or not so secret—of the industry for a long time. Now, the government really means it this time, I think.”

      Speaking on a wide range of topics during an in-depth interview with eWeek recently, Davidson said software vendors failure to deliver secure products has sparked an endless loop of patches, more and more security solutions, and a constant scramble to keep networks safe. All this has led to a lot of anger from customers and justifiably so.

      “As a result, you have security vendors claiming they can cure cancer, but they cant protect you against software vendors building insecure products,” Davidson said. “Some of these products that claim they can do all this, thats fine, but I believe that no vendor can abdicate its responsibility to build secure software. The industry needs to make products secure by default. More software products should be like that.”

      That effort to make software secure by default is a key tenet of Microsoft Corp.s Trustworthy Computing initiative. After years of criticism from customers, the press and even the government, Microsoft has put quite a bit of muscle and money behind the effort, hoping to make the security and reliability of its products a selling point for Microsoft instead of for its competitors.

      Davidson, for one, said she believes that having the worlds largest software vendor make security a top priority can mean only good things for the industry and customers.

      “The fact that Microsoft has gotten on the bandwagon is having an effect. Theyre sincere, and theyre doing good things,” Davidson said. “Theyre doing it because the customers got angry. Even Microsoft cant ignore the Department of Defense. There were enough customers clamoring for change.”

      Oracle, which has always counted the federal government as one of its biggest customers, last year took its own shot at making security a selling point. Its ad campaign proclaimed the Oracle9i database to be “Unbreakable,” a tag line that initially gave Davidson nightmares. But in the end, she said she believes the campaign had a positive effect on the company by drawing attention to security and reliability.

      “[Oracle CEO] Larry Ellison proposed it, and when it got to me, I said, What are you thinking? But its about information assurance. It got this topic out there and focused our attention internally,” Davidson said. “It was really good for the company. Now, customers want to know how were building our products. There are certainly some moments when I break out the Valium, but it made my life easier in the end.”

      The “Unbreakable” campaign, aside from drawing the attention of crackers and vulnerability researchers, also gave Davidson and Oracle an opportunity to look at the way the company writes code and how that code is reviewed and tested before release.

      “We grew up from the server side of things, and were building software for paranoids that protects the crown jewels,” Davidson said. “If someone can break into a default installation, we log that as a bug. This [is] part of our release criteria. Of course, we hold it up. Thats a release showstopper. The sooner you can find that, the better off you are. But this was a nice focal point for us. We looked at all of our products and said, Why dont we extend [“Unbreakable” to all our products]?”

      However, Davidson said she believes that projects such as Trustworthy Computing and Oracles internal security programs should not be differentiators in the marketplace.

      “In the long run, I dont want [security] to be a competitive advantage. This should be table stakes,” Davidson said. “Its a very interconnected world. Having the government step up makes a big difference. It changes the way you build products.

      “The government has been one of our bread-and-butter markets. Theres no other database [aside from Oracles] that can be used in a national security context. We absolutely do not lose business based on security.”

      Dennis Fisher
      Dennis Fisher

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×