security & scaling at microsoft

59
Security & Software Disasters & changing perception Eric Mittelette & Stanislas Quastana | Microsoft

Upload: cass-phillipps

Post on 28-Jan-2015

104 views

Category:

Technology


0 download

DESCRIPTION

Eric Mittelette and Stanisloas Quastano share stories of Microsoft Security and Scalability lessons learned at FailCon France 2012.

TRANSCRIPT

Page 1: Security & Scaling at Microsoft

Security & SoftwareDisasters & changing perception

Eric Mittelette & Stanislas Quastana | Microsoft

Page 2: Security & Scaling at Microsoft

Do you remember those dark days ?

May 4th 2000July 13th 2001

September 28th 2001January 25th 2003August 13th 2003

Page 3: Security & Scaling at Microsoft

As Microsoft employees we do

Page 4: Security & Scaling at Microsoft
Page 5: Security & Scaling at Microsoft
Page 6: Security & Scaling at Microsoft
Page 7: Security & Scaling at Microsoft
Page 8: Security & Scaling at Microsoft
Page 9: Security & Scaling at Microsoft
Page 10: Security & Scaling at Microsoft

15 minutes before SQL Slammer infection

Page 11: Security & Scaling at Microsoft

SQL Slammer (aka Sapphire) infection

Page 12: Security & Scaling at Microsoft

Blaster (aka LOVE YOU SAN)

Page 13: Security & Scaling at Microsoft
Page 14: Security & Scaling at Microsoft
Page 15: Security & Scaling at Microsoft
Page 16: Security & Scaling at Microsoft

Why we fail ?

Page 17: Security & Scaling at Microsoft

Reason 1 : features, features, features….

Page 18: Security & Scaling at Microsoft
Page 19: Security & Scaling at Microsoft
Page 20: Security & Scaling at Microsoft

Reason 2 : Security was not in Developer’s DNA

Page 21: Security & Scaling at Microsoft

Reason 3 : Everything was installed and started by default

Ex: IIS Web Server

Page 22: Security & Scaling at Microsoft
Page 23: Security & Scaling at Microsoft

Which response ?

Page 24: Security & Scaling at Microsoft

“Computing is already an important part of many people’s lives. Within ten years, it will be an integral and indispensable part of almost everything we do. Microsoft and the computer industry will only succeed in that world if CIOs, consumers and everyone else sees that Microsoft has created a platform for Trustworthy Computing”

Page 25: Security & Scaling at Microsoft

“We have done a great job of having teams work around the clock to deliver security fixes for any problems that arise.

Our responsiveness has been unmatched – but as an industry leader we can and must do better”

Page 26: Security & Scaling at Microsoft

“Flaws in a single Microsoft product, service or policy not only affect the quality of our platform and services overall, but also our customers’ view of us as a company”

Page 27: Security & Scaling at Microsoft
Page 28: Security & Scaling at Microsoft

“So now, when we face a choice between adding features and resolving security issues, we need to choose security”

Page 29: Security & Scaling at Microsoft

So what we did ?

Page 30: Security & Scaling at Microsoft

Stop all developmentThe 1st time in our history

Page 31: Security & Scaling at Microsoft

Every Microsoft developer : back to school !!!Mandatory annual security training

Page 33: Security & Scaling at Microsoft

Dear developers

Few security bugs in your code = more money in your pocket

Page 34: Security & Scaling at Microsoft

SDLC is the Microsoft security audit & expertise substance published as a methodology

Page 35: Security & Scaling at Microsoft

Security Team created

Page 36: Security & Scaling at Microsoft

Final Security Review mandatory

Page 37: Security & Scaling at Microsoft

Did it work ?

First results

Page 38: Security & Scaling at Microsoft
Page 39: Security & Scaling at Microsoft
Page 40: Security & Scaling at Microsoft

Helping IT customers in their job

Page 41: Security & Scaling at Microsoft

As you see, we did a lot of things

But…

Page 42: Security & Scaling at Microsoft

“Security is a journey, not a destination”

Page 43: Security & Scaling at Microsoft

10 years later

Is it better ?

Page 44: Security & Scaling at Microsoft
Page 45: Security & Scaling at Microsoft
Page 46: Security & Scaling at Microsoft

“Security is a journey, not a destination”

Page 47: Security & Scaling at Microsoft

Sometimes it’s better to be the first…

Page 48: Security & Scaling at Microsoft

Security is an industry problem not a single company issue

Page 49: Security & Scaling at Microsoft

Really ?

Page 50: Security & Scaling at Microsoft
Page 51: Security & Scaling at Microsoft
Page 52: Security & Scaling at Microsoft
Page 53: Security & Scaling at Microsoft
Page 54: Security & Scaling at Microsoft
Page 55: Security & Scaling at Microsoft

same feature but 10 years later

Page 56: Security & Scaling at Microsoft

“Security is a journey, not a destination”

Page 57: Security & Scaling at Microsoft
Page 58: Security & Scaling at Microsoft

“Security is a journey, not a destination”

Page 59: Security & Scaling at Microsoft

Thanks you

@EricMitt & @SQuastana