Quantcast Revisiting the Software Monoculture - Anil Dash

Revisiting the Software Monoculture

Three years ago, Dan Geer led a team of security experts in authoring a paper about the threat of a software monoculture. The paper, entitled "CyberInsecurity: The Cost of Monopoly" received a tremendous amount of attention, praise, and criticism for its detailed description of the threat posed by the ubiquity of Microsoft's Windows operating system.

In addition to garnering all this attention, the paper resulted in Geer being fired from his position. Wired News covered the story well:

"No matter where I look I seem to be stumbling over the phrase `monoculture' or some analog of it," Geer, 53, said in a recent interview in his Cambridge home.

In biology, species with little genetic variation -- or "monocultures" -- are the most vulnerable to catastrophic epidemics. Species that share a single fatal flaw could be wiped out by a virus that can exploit that flaw. Genetic diversity increases the chances that at least some of the species will survive every attack.

"When in doubt, I think of, `how does nature work?'" said Geer, a talkative man with mutton chop sideburns and a doctorate in biostatistics from Harvard University.

"Which leads you -- when you think about shared risk -- to think about monoculture, which leads you to think about epidemic," he said. "Because the idea of an epidemic is not radically different from what we're talking about with the Internet."

Because the paper was so provocative, influential, and insightful, I was glad to see Geer's ideas, and the threat of technological monoculture revisited with great effect recently by eWeek's Ryan Naraine, in "Microsoft Monoculture Myopia". (The piece is also pleasing because it has a sort of b-movie horror flick title to it.)

I found this article to be among the more exceptional bits of journalism that eWeek has done, so I emailed Ryan to ask him some questions about how the article came to be. I was also curious what inspired the magazine to revisit a topic that was initially raised three years ago but has been, to some degree, forgotten by a lot of the trade press.

Q: What inspired you to revisit the Geer report now? Was this an editorial assignment delivered to you, or something you wanted to follow up on yourself?

RN: I covered the fallout from the original report three years ago and have always been very interested in this topic. Late last year, in an essay published at Login, Geer did his own follow-up and I got the idea to wait for September and do an anniversary-type piece. I pitched it to my editors and they liked it enough to put on the eWEEK cover.

Q: This is a pretty controversial topic -- partisans on both sides of the debate can get pretty strident about the conversation. Is that a positive or a negative trait for a story?

RN: Even in the research stage, I'm hoping to find people to disagree and get into a debate so I can fully understand all sides. From that standpoint, it's a positive trait. Most times, it becomes a bitter "he-said, she-said" and people get entrenched and stops listening to each other. That can be aggravating and can sometimes leak into the reporting. My favorite interview for this piece was the Continental Airlines guy (Andre Gold) who was able to explain the risks of both sides without being a 'fence sitter'.

Q: Both Geer's paper and your article make explicit comparisons to biological monocultures, and the parallels between a software virus and a literal virus. Have you thought about the parallels to a sociological monoculture?

RN: One of the guys I interviewed (report co-author John S. Quarterman) raised this fleetingly but it wasn't something we spent much time discussing. John talked about the societal downsides of everyone listening/wearing/watching/doing the exact same thing. He also pointed me to the devastating effects of the Boll Weevil in the early 20th century that was caused entirely by monoculture.

Q: Are there any other similar monocultures in technology that you'd want to write about in the future?

RN: Yeah, the blog echo-chamber. :) Not really, I haven't given much thought to it. I write entirely about security so my focus these days is very narrow.

Thanks to Ryan for taking the time to comment on the article. I found the entire discussion to be a very useful way of re-engaging in the topics raised by the original Cyberinsecurity paper. The one line that lingers with me is Geer's comment from the Wired News story: "Genetic diversity increases the chances that at least some of the species will survive every attack."

Related Entries

1 Comment

To Windows, stop OS monopoly. But then, I’m so used to this. It’s just too bad for Geer and the price he had to pay in exposing something a lot should know about.

Leave a comment

Explore This Site

Recent Comments

  • Busby Seo Challenge’s guy recommends the excel that runs on vista. I think it’s the 2007...

  • Anil, you are right on every point! I’ll add that the motivation appears to be greed; the bott...

  • Hi there Anil. My two teenage daughters rushed out to the bookstore the other night and came back wi...

  • If I’m ever arrested on COPS I’ll be sure to shout your name, Ronnie Dobbs-style. Maybe ...

    Victor Agreda Jr
    Me and Your Bicycle
  • Thanks very much Anil! Also, you may want to know I also credit you for turning me on to ABBA. Or bl...

Recent Entries

  • Me and Your Bicycle

    My friend Mat Honan amused and beguiled you a few months ago with Barack Obama is Your New Bicycle. As is the course of...

  • Nine Years, and a New Look

    Last month marked the ninth anniversary of me starting this blog, more or less continuously updating since then. As I begin my tenth year here...

  • What was that about lists?

    I forgot to mention one point when I was blathering about lists earlier this week: The easiest way to get on them is by asserting,...

  • The KLF Burn A Million Quid

    I've been a fan of The KLF since I was a teenager, and just last week was reminded of one of their most amazing...

  • Lists and Being On Them

    Hey, NowPublic made a list of the 50 most influential web people in New York, and I'm on it at number six. So, thanks to...

What I'm Up To

Wednesday

  • Anil tweeted, "Voters, remember: A key part of our next President's responsibilities will be to name the Chief Justice of American Idol."

Tuesday

  • Anil tweeted, "@jakedobkin Your "Dramatic Chipmunk" t-shirt is just an artifact of an unfunny, tired meme. Whereas a shirt with me on it... oh, wait."

Monday

  • Anil tweeted, "Holy fuck, people, just because a song mentions "America" and is played in a public venue doesn't mean we have to doff our hats and stand."

Sunday

  • Anil tweeted, "I have this horrible vision of the future where the family from these "don't throw away the rollover minutes" commercials gets a sitcom."

Saturday

  • Anil tweeted, "Everybody tweet me links to headlines saying "Biden: His Time" or similar lunacy!"
  • Anil tweeted, "Saw a bunch of paparazzi milling about on the sidewalk, presumably waiting for someone. Looks like chickens in the yard waiting for feed."

Today

1999 2000 2001 2002 2003 2004 2005 2006 2007 2008
  Jan Jan Jan Jan Jan Jan Jan Jan Jan
  Feb Feb Feb Feb Feb Feb Feb Feb Feb
  Mar Mar Mar Mar Mar Mar Mar Mar Mar
  Apr Apr Apr Apr Apr Apr Apr Apr Apr
  May May May May May May May May May
  Jun Jun Jun Jun Jun Jun Jun Jun Jun
Jul Jul Jul Jul Jul Jul Jul Jul Jul Jul
Aug Aug Aug Aug Aug Aug Aug Aug Aug Aug
Sep Sep Sep Sep Sep Sep Sep Sep Sep  
Oct Oct Oct Oct Oct Oct Oct Oct Oct  
Nov Nov Nov Nov Nov Nov Nov Nov Nov  
Dec Dec Dec Dec Dec Dec Dec Dec Dec  
Close