Microsoft shares draft of Vista security hooks

By Joris Evers, CNET News.com
Thursday, December 21, 2006 10:59 AM

Microsoft has released a first draft of programming interfaces meant to help security firms create products that work with kernel protection features in Windows Vista.

The new application programming interfaces, or APIs, will let software makers extend the functionality of the Windows kernel in 64-bit versions of Vista, Microsoft said on its Web site Tuesday. Security companies, including market leaders Symantec and McAfee, had complained that Microsoft locked them out of the kernel, a core part of Windows.

Delivery of the APIs comes just over two months after Microsoft agreed to provide them. Microsoft long maintained that a complete lock on the kernel would provide the best operating-system security and stability, but made concessions in response to antitrust concerns raised by officials in Europe and Korea.

Security companies have unfettered access to the core of 32-bit versions of Windows. But they complained that the kernel shield, called PatchGuard and intended to stop hackers in 64-bit versions of Vista, blocks security products too. The 64-bit Windows is expected to eventually supplant 32-bit versions.

The APIs will offer security and nonsecurity software makers the ability to develop software that extends the functionality of the Windows kernel on 64-bit systems in a documented and supported manner, without disabling or weakening the protection offered by kernel patch protection, Microsoft said.

Symantec, the world's largest security software maker, acknowledged receipt of the Microsoft material, but a company representative couldn't provide any detailed comment on it yet. "We are currently evaluating the information and awaiting additional information from Microsoft," the representative said in an e-mailed statement.

McAfee is pleased with Microsoft's APIs, said George Heron, chief scientist at the Santa Clara, Calif., company, in an e-mailed statement. "Our preliminary review of the API specification document shows that Microsoft included some of the recommendations we had submitted, and it appears they did a good job on those," he said.

The final versions of the APIs won't be available for a while. Microsoft plans to release those with Windows Vista Service Pack 1, which analyst firm Gartner expects to come in early 2008. Until then, users of security technologies such as host intrusion-prevention systems should postpone buying 64-bit versions of Vista, Gartner has recommended.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Use shades of gray to enhance scale in Excel

Microsoft Office Suite

Excel's palette is generous, but don't throw buckets of pigment all over your spreadsheets just because you can.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web