Microsoft "Sunday marks the tenth anniversary of Bill Gates's trustworthy computing memo, which made securing applications from the ground up a key priority at Microsoft for the first time. The directive followed a period during which Redmond took a sustained shelling over the instability and insecurity of its software, especially in Internet Explorer and Outlook, highlighted by the damage caused by high-profile malware outbreaks such as the rampaging Love Bug, Melissa and Nimda nasties."
Defaults favor Ease of Use over Security
MS announced Trusted Computing and put a ton of work into it. But until they change their perception of the trade-off between security and usability, Windows will continue to have security issues.

Examples -- Today you plug an unknown USB stick or DVD into your computer, and Windows eagerly runs whatever program happens to be on there via autorun. Another example of this, Outlook has message Preview on by default. These simple examples show how MS weighs security vs user-friendliness. Their defaults are wrong if security is the goal.

