The much-vaunted security of Microsoft's next-generation Web-services platform is good, but the company still has to iron out some kinks, one security consultant said Thursday.
H.D. Moore, a hacker and senior security analyst for Digital Defense, told attendees of the CanSecWest security conference here that the .Net Framework could nearly eliminate some types of vulnerabilities that plague Microsoft products today, but that the server software is still easy to misconfigure, especially since much of the documentation teaches insecure programming.
"It doesn't make a difference how secure products are initially, but how you program them that counts," Moore said. "And developers are being told the wrong things to do in a lot of situations."
|