Allchin: Buy Vista for the security

By Joris Evers, CNET News.com
Wednesday, February 01, 2006 12:48 PM

Another security change at the operating system level involves Internet Explorer. In Vista, IE 7 will run in protected mode by default, Allchin said. This mode will prevent silent installs of malicious code by stopping the Web browser from writing data anywhere except in a temporary files folder without first seeking permission. "We sandboxed all of IE," he said.

On systems with 64-bit processors, Vista will require digital signatures to run kernel-mode software such as device drivers, Allchin said. This is an attempt to block unwanted software such as rootkits from nestling deep into the PC.

Microsoft also has updated the security software in Windows Vista to help fend off threats. The firewall has been updated and now looks at incoming as well as outgoing traffic--in XP SP 2 only incoming traffic was watched. Also, Microsoft has made its anti-spyware tool, Windows Defender, part of the operating system.

"The first step is protection from doing things inadvertently or warning you about the level of impact it could have," Allchin said. "Then, if you let something in, Defender is there to (warn you) and you can undo it. If the thing gets in and has really done some awful things, using the equivalent of System Restore in Windows XP you can back up time and undo it," he said. Microsoft doesn't yet have a new name for System Restore, he said.

Other security features in Vista include BitLocker Drive Encryption to protect data on computers when lost or stolen. The encryption feature is designed to work with a chip called the Trusted Platform Module, which offers protected storage of encryption keys, passwords and digital certificates. BitLocker is the one remnant of Microsoft's grand hardware-based security plan originally envisioned for Vista.

For businesses, Vista will offer tighter control over removable storage devices by letting administrators centrally block the installation of, for example, USB (universal serial bus) flash drives and external hard drives. This feature is designed to help prevent intellectual property or sensitive data from being compromised or stolen.

IDC analyst Al Gillen said that Microsoft has taken much-needed steps with the operating system, such as the USB-blocking abilities.

"Those kinds of things are incremental improvements that really were pretty important," Gillen said.

But, like any software, Vista isn't hack-proof. In fact, Microsoft has already had to issue a security update for the operating system. The patch fixed the same vulnerability related to the processing of Windows Meta File (WMF) images found in earlier versions of the operating system. "That torqued me," Allchin said.

Microsoft was in the process of checking the parsing of all kinds of files and hadn't made it down to WMF yet, according to Allchin. "We would have caught it. It was on the list; we didn't get to it" in time, he said.

"At no time am I saying this system is unbreakable," he added. "Security is going to be an issue for the industry in all pieces of software, not just the OS."


 Previous 1 2 

WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Release management: Unnecessary evil or Holy Grail?

Tech Management

Though organizations may dread these words, release management is an integral step throughout the software development process. Erica Henson explains more.


Read more »



Buying a projector? Try an LED TV instead

Blog thumbnail

If you're thinking of buying a new projector for your office meeting room, why not consider getting an LED TV instead. LED TVs are similar to LCD TVs except that..... by Lee Lup Yuen

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web