The distribution Thursday of portions of the secret programmer's instructions for two versions of the Windows operating system poses vexing legal and security challenges for Microsoft.
Computer security experts said on Friday that having even relatively small parts of the blueprints for Microsoft's Windows 2000 and Windows NT operating system as easily available reference material for potential vandals and troublemakers could complicate the company's already difficult task in securing its software.
Microsoft has been intensively criticized on security issues in recent years and the company has devoted increasing resources in an effort to restore its credibility with its customers.
The posting of the information on the Internet does not present any direct threat to the hundreds of millions of users of Microsoft's software, but it may fuel the fire among those who say that Microsoft, based in Redmond, Washington, has done a poor job of protecting computer users from hackers and invasions of viruses and worms. The company may also face a debate over its contention that the secrecy of its proprietary software offers a computer security advantage over the publicly available text of open-source programs like Linux.
Microsoft's executives said on Friday that they were working with federal law enforcement officials to attempt to understand how the software instructions, known as source code, had appeared on a variety of Internet peer-to-peer file sharing systems.
"We take this seriously," said Tom Pilla, a Microsoft spokesman. "It's illegal for third parties to post or make our source code available. From that standpoint we've taken appropriate legal action to protect our intellectual property."
Word of the theft of Microsoft's source code spread rapidly on Thursday afternoon after it was first reported on a Web site, Neowin.net, and then widely discussed on the Slashdot Web site, which is widely read by the nation's programming community.
By late Thursday evening dozens of copies of different text files ranging in size from 200 megabytes to one gigabyte were being downloaded by thousands of Internet users.
Computer programmers who examined the software instructions -- the basic texts from which the Windows operating systems programs are assembled -- reported that at least some versions of the program had come from a Microsoft partner, Mainsoft Corp, a software company whose headquarters are in San Jose, California.
Several computer security experts speculated that the Microsoft operating system source code had been stolen from a Mainsoft computer via the Internet and then posted on peer-to-peer file sharing networks.
Neither Microsoft nor Mainsoft would confirm this report. Mainsoft, however, released a statement acknowledging the firm had a source code licensing agreement with Microsoft.
"Mainsoft takes Microsoft's and all our customers' security matters seriously, and we recognize the gravity of the situation," Mike Gullard, chairman of Mainsoft, said in the statement. "We will cooperate fully with Microsoft and all authorities in their investigation."
Even though Windows 2000 and Windows NT are older versions of the company's operating systems, they are still widely used by corporations around the world.
"This raises real national security concerns," said William Cook, a partner at Wildman Harrold in Chicago and a former federal computer crime prosecutor. "The fact that Microsoft's software is so widely available will have an impact across the computer security industry."
A number of computer security and legal experts said that Microsoft's biggest challenge as a result of the incident may unfold in the future as skilled programmers begin to examine the texts in search of material that may be embarrassing or damaging to Microsoft.
"There have been lots of stories about the existence of undocumented features" in Microsoft's operating system that were intended to harm competitors, said Bruce Schneier, founder and chief technical officer of Counterpace Internet Security, a computer security firm in Mountain View, California.
In 1999, Microsoft suffered a black eye when a Canadian programmer, examining a portion of its software, discovered an element inside the company's Windows operating system labeled NSAKey. At the time, Microsoft said the reference was not an indication that the company was engaged in a conspiracy with the National Security Agency, a federal intelligence operation. The label, however, undercut the company's credibility within the computer security community, where it was widely criticized at the time. In addition to the NSAKey incident, the Diebold Corp, a manufacturer of automated teller and voting machines faced criticism after the programmers' instructions for its voting machines were circulated on the Internet. Technical experts said the code revealed flaws that might make the machines vulnerable to manipulation, a charge that Diebold denied.
A number of computer experts said that Microsoft had no choice but to rush to court to try to limit the spread of the software instructions through temporary restraining orders.
"The horse is out of the barn," said Jim Brelsford, a partner at the law firm Jones Day in Menlo Park, California. "But you have to do this to protect your trade secrets."
‘REGRETTABLE’: TPP lawmaker Vivian Huang said that ‘we will continue to support Chairman Ko and defend his innocence’ as he was transferred to a detention facility The Taipei District Court yesterday ruled that Taiwan People’s Party (TPP) Chairman Ko Wen-je (柯文哲) be detained and held incommunicado over alleged corruption dating to his time as mayor of Taipei. The ruling reversed a decision by the court on Monday morning that Ko be released without bail. After prosecutors on Wednesday appealed the Monday decision, the High Court said that Ko had potentially been “actively involved” in the alleged corruption and ordered the district court to hold a second detention hearing. Ko did not speak to reporters upon his arrival at the district court at about 9:10am yesterday to attend a procedural
Thirty Taiwanese firms, led by Taiwan Semiconductor Manufacturing Co (TSMC, 台積電) and ASE Technology Holding Co (日月光投控), yesterday launched a silicon photonics industry alliance, aiming to accelerate the medium’s development and address the energy efficiency of artificial intelligence (AI) devices like data centers. As the world is ushering in a new AI era with tremendous demand for computing power and algorithms, energy consumption is emerging as a critical issue, TSMC vice president of integrated interconnect and packaging business C.K. Hsu (徐國晉) told a media briefing in Taipei. To solve this issue, it is essential to introduce silicon photonics and copackaged optics (CPO)
The High Court yesterday overturned a Taipei District Court decision to release Taiwan People’s Party Chairman Ko Wen-je (柯文哲) and sent the case back to the lower court. The Taipei District Prosecutors’ Office on Saturday questioned Ko amid a probe into alleged corruption involving the Core Pacific City development project during his time as Taipei mayor. Core Pacific City, also known as Living Mall (京華城購物中心), was a shopping mall in Taipei’s Songshan District (松山) that has since been demolished. On Monday, the Taipei District Court granted a second motion by Ko’s attorney to release him without bail, a decision the prosecutors’ office appealed
GRAFT PROBE: Critics questioned Ko claiming he did not know about the Core Pacific floor area ratio issue until this year, citing a 2021 video in which he was asked about it Taiwan People’s Party (TPP) Chairman Ko Wen-je (柯文哲) was released without bail early yesterday, while his deputy during his tenure as Taipei mayor was detained and held incommunicado after being questioned since Friday over graft allegations related to a shopping center redevelopment project. Prosecutors on Saturday filed a request with the Taipei District Court to officially detain Ko and former Taipei deputy mayor Pong Cheng-sheng (彭振聲) over allegations surrounding the redevelopment of Core Pacific City, also known as Living Mall (京華城購物中心). The court yesterday determined that the evidence provided by prosecutors was insufficient to justify the detention of Ko and ordered his