Microsoft security is a leaky lifeboat

CrowdStrike CEO appears to have got Microsoft all cross when he dubbed its security approach a “leaky lifeboat”.

George Kurtz told the gathered throngs at XChange Best of Breed conference in Atlanta attributed a majority of cyberbreaches to Microsoft products, compared the software behemoth’s total security offerings to a “leaky lifeboat” and its authentication architecture “a mess”.

“The Microsoft environment is the only environment that I know of that you can take a password and just reuse it. Right? And it’s a huge architectural issue. That was in 1999. You can do that today. … You can take those passwords out of memory and basically just do the same technique in 2022. And it’s even worse now because there‘s a hodgepodge of syncing and you know that you have SAML tickets and golden SAML tickets. I mean, it’s a real mess.”

Kurtz discussed a wide range of security-related issues confronting industry players and customers alike.

A Volish spokesman spat a reaction to Kurtz’s comments: “Microsoft believes security is a team sport and we gather and act on 43 trillion security signals every day to protect customers and partner with fellow defenders across the industry, making the world a safer place. Our customers choose Microsoft because we deliver the most integrated security portfolio. On average, customers save more than 60 percent when they turn to Microsoft for comprehensive security, compared to a multivendor security implementation.”