Extreme Monoculture

Looks like the Air Force has no qualms about the monoculture issue brought forth by Dr. Dan Geer (who got fired from @Stake (now Symantec) over its writing). They have announced a plan to standardize on Microsoft products to the specific configuration level, with hopes to save upwards of $100 million.

Monoculture is an interesting issue – on the one hand, it certainly could increase the impact/spread of a propagating worm or the number of available targets in a dedicated attack. Ultimately, though, this is a risk borne by the entire Internet community. On the other hand, security may be enhanced through increased manageability of the environment, thus reducing complexity.

For more on my perspective of the monoculture argument: http://infosecuritymag.techtarget.com/ss/0,295796,sid6_iss205_art449,00.html