Post #141,358
2/12/04 6:36:15 AM
|
Wife heard this on news in Australia today
EDITORIAL Peril in Microsoft's Laxity Microsoft's announcement Tuesday that it will warn consumers about a "critical" problem in its Windows software \ufffd more than six months after it learned about the flaw \ufffd illuminates the danger of leaving national cyber-security largely unregulated and unwatched.
Microsoft says it waited to publicize the security flaw because it wanted to ensure that a single, downloadable update would solve any related problems. Its "patch" is now available at [link|http://www.Microsoft.com|http://www.Microsoft.com] /security/.
But computer security experts such as Marc Maiffet, whose company, eEye Digital Security Inc. of Aliso Viejo, discovered the flaw, deride the half-year delay between eEye's discovery and Tuesday's disclosure as "just totally unacceptable" because it left hundreds of millions of computer users vulnerable to hackers eager to break into their computers and steal their files, delete their data or filch their financial records.
It isn't easy to find and fix flaws in the millions of lines of coding that make up Windows. In a Times interview Wednesday, Maiffet compared the struggle to "trying to weed 1,001 needles from a haystack."
Moreover, Microsoft understandably doesn't want to tip off hackers that certain lines in its coding are particularly vulnerable to abuse. There's no excuse, however, for Microsoft's failure to find some responsible way of promptly alerting its customers when such serious flaws are found.
A delay of this kind would, after all, expose a manufacturer of cars or other vital consumer products to potentially crippling lawsuits. Individual users of newer Microsoft operating systems such as Windows XP can and should enable their PCs to automatically fix their software with updates as soon as the company posts them. But because large companies cannot easily update computers in their internal networks, or "intranets," Microsoft should, at the very least, promptly disclose possible software flaws to those companies' information technology managers.
On Feb. 23, Microsoft Chairman Bill Gates is expected to face thousands of computer security experts at San Francisco's Moscone Center and tell them that his company is doing everything possible to bolster cyber-security. They should realize, however, that Gates' boyish charm alone will do little to protect their data.
Doug M
|
Post #141,376
2/12/04 9:38:33 AM
|
Re: Wife heard this on news in Australia today
I've often wondered why software vendors are not subjected to the same quality controls as makers of toasters, TVs, razors, not to mention cars.
-drl
|
Post #141,377
2/12/04 9:40:41 AM
|
'cuz software ain't killed nobody ---- yet
"All men are like grass, and all their glory is like the flowers of the field; the grass withers and the flowers fall, but the word of the Lord stands forever." 1 Peter 1:24-25
|
Post #141,383
2/12/04 9:58:34 AM
|
That we know of.
----------------------------------------- "If you don't vote, it's your fault!"
jb4
|
Post #141,433
2/12/04 12:46:19 PM
|
we know of a few
try this [link|http://www.google.com/search?hl=en&lr=&ie=UTF-8&oe=utf-8&q=radiation+overdose+software|search] No doubt there have been deaths in other fields attributed to "operator error" when the root cause was really a software problem.
Have fun, Carl Forde
|
Post #141,601
2/13/04 10:01:35 AM
|
But how many, highly publicized with blame laid at MS feet?
"All men are like grass, and all their glory is like the flowers of the field; the grass withers and the flowers fall, but the word of the Lord stands forever." 1 Peter 1:24-25
|
Post #141,403
2/12/04 11:01:45 AM
|
Fly by wire disorientation
A 757 had its pitot inlets taped over. The software could not make intelligent guesses about sensor readings that were clearly nonsense, and so set off a string of false alarms, including the stick-shaker for imminent stall. The pilots became so confused and disoriented by the computer that they crunched a perfectly good 757 into the ocean, killing everyone.
The computer killed those people.
-drl
|
Post #141,984
2/16/04 2:46:43 PM
|
Um, link?
AFAIK, only the Boeing 777 is "fly-by-wire". And even then, the pilots can override the system. Airbus is (in)famous for their aircraft being fly-by-wire and taking control completely away from the pilots. (Aside: and that is why I was terrified last week flying in an A320-214).
Which accident are you referring to?
bcnu, Mikem
I don't do third world languages. So no, I don't do Java.
|
Post #142,002
2/16/04 6:29:42 PM
|
Try
[link|http://z.iwethey.org/forums/render/content/show?contentid=137695| here].
|
Post #142,048
2/17/04 9:18:04 AM
|
Thanks.
bcnu, Mikem
I don't do third world languages. So no, I don't do Java.
|
Post #142,009
2/16/04 9:32:42 PM
|
Re: Um, link?
The point I was making - the software should have known that the information from the sensors was garbage. Instead is just put it out there as gospel, as if they were flying in the atmosphere of Titan. They died form bad software (BTW you're right about FBW my bad).
-drl
|
Post #142,051
2/17/04 9:22:51 AM
|
That wasn't software.
That was pilot error.
bcnu, Mikem
I don't do third world languages. So no, I don't do Java.
|
Post #142,058
2/17/04 10:22:04 AM
|
Re: That wasn't software.
No way. It was pitch black. No horizon, no lights. You rely on instruments. The control system for the avionics should have been smart enough to flag ridiculous readouts.
-drl
|
Post #142,083
2/17/04 2:01:27 PM
|
As Todd noted.
The pilot screwed up on his pre-flight. Even a second lesson student pilot knows to check the static ports (even if it is inconvenient).
bcnu, Mikem
I don't do third world languages. So no, I don't do Java.
|
Post #142,121
2/17/04 11:47:15 PM
|
Re: As Todd noted.
Have you ever prepared the coffee machine and then left it sit? Put sugar instead of coffee in the filter? Forgot to add water? Dump in coffee without putting in a filter first? Made yourself a nice pot of very weak coffee a.k.a. hot water? I've done all these things and that's just one device. Things like coffee making are so automated, you skip a step or get them in the wrong order once in a while. It's not too much to ask of software to understand when it's producing nonsense. The transcript of the flight clearly shows that the pilots were confused by their instruments and this lead to their deaths.
-drl
|
Post #142,140
2/18/04 5:40:42 AM
|
Yes, to me this particular 'test' seems as basic as it gets.
The additional means for "testing for a plugged pitot" is so trivial I won't even suggest (one of about 10 obvious ways) - simple enough even for a digital device to deal with. Not 'pilot error'; stupid fucking Design Error from the get-go.
And this chestnut is especially inexcusable because: EVERYONE KNOWS how easy it *could* be plugged, visibly OR virtually undetectable, except by a lo-pressure CHECK. Add one decision block to flow-chart:
Pitot tube: [blocked] [unblocked] -- with logic to be sure and tell Captain >WHICH mode< the silicon is banking on, just now. <<< Hell, make it audio; purred a la Santa Baby.
Now we're fucking FLYING via Redmond-grade dumbth! push-to-test; release-to-detonate
|
Post #142,142
2/18/04 6:18:16 AM
|
Re: Yes, to me this particular 'test' seems as basic as it g
There are many cases of mishaps caused by human automation failure - several for example in which flaps were not set before takeoff. Failing to set flaps before takeoff is something no pilot would ever "forget" to do because it means near certain death after V1.
The problem lies with checklists and training. After so much training the checklist can be as good as useless. On the first lunar landing, two critical maneuvers were jeapordized because of an omitted item that had been repeated countless times in the simulator.
One good thing about electronic flight control is that the checklist can be audited in real time. Still, if I were flying, I'd rather have dials. Something about the physical moving needle adds a level of attention.
-drl
|
Post #142,154
2/18/04 10:12:12 AM
|
Flying Dumbth.
I'm fascinated to watch companies like Cirrus embrace the notion of putting more and more electronic devices in the cockpit of small aircraft. IMO, a GPS is a good thing, but that is the only thing electronic I want in the cockpit when I'm flying. And I'm not going to use it for approaches.
It is indeed "dumbth" to rely on electronic devices at all in the cockpit. You do have to trust your instruments in IMC, but I'll be damned if I'll ever trust computer software, or hardware for that matter, enough to fly by it.
And I stand by my earlier statement. The pilot fucked up major when he took off without doing a decent preflight. It *was* his fault and usually I am loathe to blame pilots. But this case is as clear-cut as you can find.
AFA the pitot icing up, guess what the airspeed indicator becomes when that happens? Think that's too hard for a pilot to figure out? I don't.
bcnu, Mikem
I don't do third world languages. So no, I don't do Java.
|
Post #142,264
2/18/04 10:16:22 PM
|
Re: Flying Dumbth.
The CRT displays are to blame - they look weird and artificial and there must be an extra step when interpreting them. Needles are physical, you *know* when they are wrong - it's not just the reading.
-drl
|
Post #141,402
2/12/04 11:00:09 AM
|
MS patch
if it comes out before the first exploit then it seems like it came out in time
A
Play I Some Music w/ Papa Andy Saturday 8 PM - 11 PM ET All Night Rewind 11 PM - 5 PM Reggae, African and Caribbean Music [link|http://wxxe.org|Tune In]
|
Post #141,414
2/12/04 11:41:56 AM
|
Nope...
The exploit has been used to dupe people big time already.
-- [link|mailto:greg@gregfolkert.net|greg], [link|http://www.iwethey.org/ed_curry|REMEMBER ED CURRY!] @ iwethey
"Lately, The only thing keeping me from being a Serial Killer is my distaste for manual labor." -- Dilbert Calendar, January 4, 2004
|
Post #141,455
2/12/04 1:34:46 PM
|
$hill$hill$hill$hill$hill$hill$hill$hill$hill$hill$hill!
|
Post #141,606
2/13/04 10:31:28 AM
|
Odd that some guys here don't understand the conditional
Play I Some Music w/ Papa Andy Saturday 8 PM - 11 PM ET All Night Rewind 11 PM - 5 PM Reggae, African and Caribbean Music [link|http://wxxe.org|Tune In]
|
Post #141,931
2/16/04 11:59:24 AM
|
IYO does this justify the 6 months?
if so I have a question about driving drunk and getting home before killing anybody.
FAQ! We're scrod!
|
Post #141,933
2/16/04 12:00:17 PM
|
oops, dupe post
FAQ! We're scrod!
|
Post #141,932
2/16/04 11:59:30 AM
|
IYO does this justify the 6 months?
if so I have a question about driving drunk and getting home before killing anybody.
FAQ! We're scrod!
|
Post #141,406
2/12/04 11:19:06 AM
|
That article was in the Los Angeles Times . .
. . editorial pages (B12) this morning.
[link|http://www.aaxnet.com|AAx]
|
Post #141,475
2/12/04 2:43:38 PM
|
Re: Was repeated on morning news just now
It seems to be getting big coverage here & MS is being castigated in the news items.
Doug M
|