Friday | 16 May, 2008
ARN

News

Microsoft bets big on Vista security
Robert McMillan (IDG News Service) 27 August, 2006 09:40:57

Related Stories
  • +

    Microsoft bets big on Vista security 25 July, 2006 08:45:39

    Microsoft's Vista developers can't catch a break these days. After years of warnings from security researchers that old code in Windows was creating security risks, the software giant decided to rewrite key parts of the operating system.
  • +

    Has Microsoft kept its Vista security promise? 29 March, 2007 12:03:42

    Just three months into the official commercial release of the OS, questions are flying
    According to Microsoft, it's the most secure operating system the company has ever produced. Five years in the making, Windows Vista promises to lock down the desktop and usher in the era of "trustworthy computing," in which PCs are more reliable, user experience is improved, and rampant malware is a thing of the past.
  • +

    Knocking off the nasties 06 December, 2006 16:25:29

    With the security threat landscape mutating for financial gain, and Microsoft jumping into the SCM game, resellers have no shortage of opportunities.
  • +

    Consolidation craze 16 October, 2002 14:29:22

    Consolidation is having a dramatic impact on the storage market; hardware vendors are merging with each other as well as with application vendors, and integration specialists are following suit. The plummeting price of hardware is forcing vendors to offload manufacturing to third parties and get into the services game. Meanwhile, customers are doing a spring-clean through their IT departments to understand and maximise their assets and the result has server vendors concerned for their livelihood. Kevin Cosgriff reports.
  • +

    Ten dangerous claims about smartphone security 27 March, 2007 15:04:37

    Our columnist sees Barack Obama with that BlackBerry and shudders
    My heart sank when I first saw Al Gore pull out his BlackBerry. It was in the waning weeks of the 2000 US presidential campaign, and there he was on the TV, tapping away on his then-novel converged device. Though I had no evidence, I was positive that whatever he was reading had already been perused by some conservative skunk works, with his responses scrutinized not long after. Given recent revelations about the opposition's ethics and panting obsession with domestic spying, I still suspect that any eavesdropping technically possible at the time was probably being done.
Additional Resources
ARN Library

Newsletter Subscription

Sign up for our ARN newsletters!
The premier provider of daily news to the IT channel, covering business, technology, products, and services.
RSS Feeds

Microsoft's Vista developers can't catch a break these days. After years of warnings from security researchers that old code in Windows was creating security risks, the software giant decided to rewrite key parts of the operating system.

The result? Last month, Symantec published a report suggesting all of this new code will introduce new security problems.

"The network stack in Windows Vista was rewritten from the ground up. In deciding to rewrite the stack, Microsoft has removed a large body of tried and tested code and replaced it," Symantec wrote, noting that it found vulnerabilities in the Windows Vista networking software.

"Despite the claims of Microsoft developers, the Windows Vista network stack as it exist today is less stable than the earlier Windows XP stack," it said after examining a beta release of the software.

After years of being blamed for countless security problems, Microsoft may be in a no-win situation.

"You get beaten up if you modify the old code; you get beaten up if you write new code," Cybertrust senior information security analyst, Russ Cooper, said. "The historic complaint against Microsoft has been that its code is bloated with all this legacy stuff. Rewrite it and now, 'this is too new; this is untested'."

The fact that Symantec was able to discover flaws in a beta release should not raise eyebrows, Cooper said.

"There's a reason products are put in to beta, and it isn't because people just want to see the default colours change," he said.

More secure

If customers do not ultimately see Vista as a more secure product than its predecessor, however, it will be a disaster for Microsoft - on an epic scale. Over the past few years, the company has literally reinvented the way it produces software, instituting a new set of software development practices known as the Security Development Lifecycle.

It has retrained developers, built a suite of automated security testing tools, and, most remarkably, invited scores of independent researchers to have unprecedented access to early versions of Vista.

"Vista is really the first release of the operating system to go through our Security Development Lifecycle from beginning to end," corporate vice-president of Microsoft's security technology unit, Ben Fathi, said. "That's fundamentally a different way of looking at building security into the platform."

Microsoft has gone to great lengths to publicise its Security Development Lifecycle, which was used in the development of Windows XP Service Pack 2 and SQL Server 2005.

Company executives claim the strict development guidelines used for XP Service Pack 2 played a big role in eliminating the widespread worm virus outbreaks that seemed so common just three years ago.

The emphasis on security is perhaps best illustrated by an event that Microsoft executives have declined to discuss in detail: the recent slip in Vista's ship date.

Last March, Microsoft grabbed headlines by announcing Vista would not be available in time for the 2006 holiday shopping season, as expected. It never gave specific reasons for the miss, but it was a major setback for a product already five years in the works. Microsoft immediately reorganised the Platforms and Services Division responsible for the delay, putting a new executive, Steve Sinofsky, in charge of Windows development Privately, several sources familiar with Vista's development say security concerns caused the widely publicised slip in the product's ship date.

Market Place

ARN Member Login

 
Channel Watch
  • Brian's bloopers

    It takes a long time to produce an episode of Channel Watch. Maybe you'll understand why after watching this...

Play
ARN news
Play
Business Continuity & Disaster Recovery Zone

When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
ARN Vendor Directory
ARN Library

November Infringement Alert

Recently Microsoft® took legal action against individuals and resellers for distributing and selling unauthorised Microsoft software.

Sponsored Links