Windows defense handcuffs good guys

By Joris Evers, CNET News.com
Friday, August 11, 2006 09:50 AM

With PatchGuard, Microsoft is effectively taking control of security for the Windows core, Gorelik said. Previously, third parties could also provide defenses for that part of the operating system, he said. Now, if PatchGuard breaks, it will be up to Microsoft to fix the flaw and make Windows PCs secure.

"They would have to patch the kernel if someone bypasses PatchGuard," Gorelik said, noting that the kernel is the toughest thing to fix in the operating system.

Security vendors are calling on Microsoft to allow exceptions in the kernel shield for trusted third parties.

"There is definitely a legitimate need to lock down the kernel," McCorkendale said. "I don't suggest they eliminate PatchGuard. What I am asking for is an exception. There are less restrictive means available, and we have proposed many solutions to Microsoft. But it has fallen on deaf ears."

"Microsoft is disallowing this whole class of security products that they don't have."
--Bruce McCorkendale, chief engineer, Symantec

Microsoft opposes the idea of making exceptions, as it would increase the number of entry points that miscreants could take advantage of, Toulouse said.

"When you get into the concept of exceptions, you get on a slippery slope," he said. "What made a lot of sense to us is simply to restrict the kernel without exception, creating a level playing field that all of the vendors, including Microsoft, can then operate by." Toulouse's argument is that Microsoft's security software is also unable to touch the kernel.

Dropped ball
With the advent of threats such as rootkits, which that nestle deep inside the operating system, Microsoft should protect the Windows core, analysts said. However, the company has dropped the ball on letting other software makers in on what the new kernel protections mean for them, said John Pescatore, an analyst at Gartner.

"This is a complex issue, but Microsoft has definitely been deficient in including the impacted software makers early on," Pescatore said. "That definitely does work to their advantage from a competitive viewpoint. However, the rootkit issue has to be fixed, and kernel protection has to be stronger for all operating systems."

Indeed, Symantec is playing the anticompetitive card for the first time. The Cupertino, Calif.-based company had said it would beat Microsoft by using its security wits as long as the competition is fair. Now the fairness seems to be gone, McCorkendale said.

"It seems a bit disingenuous of Microsoft. They are getting into the security market and are disallowing this whole class of security products that they don't have," McCorkendale said. "It does not feel like a level playing field at that point."

McCorkendale stopped short of saying that Symantec would sue Microsoft or complain to antitrust authorities. However, Yankee Group analyst Jaquith believes that step is getting closer, especially if Microsoft were to give its own security products a way to bypass PatchGuard.

"Microsoft's anti-kernel hacking feature could conceivably create a formidable barrier to entry to their competitors in the security market," Jaquith said. He expects Microsoft to deliver host intrusion prevention capabilities in its Forefront products next year.

"I think you'll see the larger security companies run to the Department of Justice and the European Union faster than you can say 'Penfield Jackson'," Jaquith said, referring to Thomas Penfield Jackson, the judge who oversaw the landmark U.S. antitrust case against Microsoft.


 Previous 1 2 

WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web