By Jay Lyman TechNewsWorld Part of the ECT News Network
10/16/03 3:20 PM PT
Speaking at a conference in New Orleans, Louisiana, this week, Microsoft chief executive Steve Ballmer announced the company's next service pack for Windows XP will include more secured memory to ward off buffer overrun exploits, which have plagued Windows.
How Much is 'Free' Costing You? Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.
Microsoft (Nasdaq: MSFT) once again is discussing plans to overhaul its security just as the company has released five patches for seven newly discovered vulnerabilities in Windows desktop and server software.
Microsoft issued the patches for a range of Windows systems that could be compromised as a result of the vulnerabilities -- five of which were rated critical because they could provide attackers with direct access to computers via HTML e-mail or via malware, such as the Blaster worm that hit half a million machines last August.
As the volume of vulnerabilities and patches increases, the Redmond, Washington-based company repeatedly has said it is taking distinct steps to secure its flagship operating system: moving to a monthly patch schedule except for critical vulnerabilities; updating Windows XP to secure memory and force firewall use; and providing a site for users to find out more about protection.
But Microsoft's commitment to security is something an attack-rattled industry has heard before, Forrester analyst Jan Sundgren told TechNewsWorld. "These are not huge steps. It's not that dramatic, but it's still steady progress."
Locking Windows
Speaking at a conference in New Orleans, Louisiana, this week, Microsoft chief executive Steve Ballmer announced the company's next service pack for Windows XP will include more secured memory to ward off buffer overrun exploits, which have plagued Windows and other software.
With the XP update, due in the first half of next year, Microsoft also will turn on the operating system software's built-in firewall, which was not necessarily on by default before.
Microsoft spokesperson Sean Sundwall told TechNewsWorld that some of the measures -- such as a protection site where Microsoft recommends firewall, computer updates and up-to-date antivirus software -- are already under way.
Other measures, including the Windows XP service pack, will not be put in place until next year, Sundwall said.
Security Echo
Analysts agreed that Microsoft continues to improve its security practices, but the flow of vulnerabilities and patches seems to be increasing as much as Microsoft's security talk.
"They definitely need to improve security," Sundgren said. "Most importantly, they need to reduce the number of vulnerabilities that are emerging in their software. The problem is, there's so much legacy code, it takes time to find the vulnerabilities."
In response to criticisms that Microsoft's security speeches have been nearly as numerous as security holes in its products, Sundwall told TechNewsWorld, "Yes, we've said we are committed to security before, and we have been; as security takes different twists and turns, we adapt to that and make changes."
Long Haul
Analysts agreed that while Microsoft is making improvements to its software security, it will take time for the measures to slow down the bad guys.
Gartner (NYSE: IT) research vice president Richard Stiennon told TechNewsWorld that Microsoft has improved security by "finally" shipping products without open ports and services that unnecessarily expose users to attack.
Sundgren referred to the software maker's efforts with developers, which he said is one of the security measures that is well under way.
"I think they have trained their developers to be more security-minded, and that's an important part of their strategy," Sundgren said. "The impact is not going to be dramatic and instant, though. It will occur over time, and it will be harder [for attackers] to find those vulnerabilities."
Report on Controversial VeriSign Service Expected in Two Weeks October 16, 2003
In a survey conducted for VeriSign, 84 percent of Internet users said they would rather be redirected to SiteFinder than receive an error message. However, when pressed by committee members about the methodology and data behind the study, VeriSign executives claimed the information was proprietary.
Wintel Monoculture, Lamarckian Biology and Bill Joy October 16, 2003
It's possible to think of the present epidemic of Wintel security violations and its worldwide economic consequences as a relatively benign demonstration of what happens when a Lamarck biology is allowed to work itself out in the absence of intelligent direction and control.
Dell Introduces Wireless Axim X3 October 15, 2003
The Axim X3 is available in three configurations: the Axim X3i with integrated Wi-Fi 802.11b for $379, and two nonwireless Axim X3 configurations for $229 and $329.
Microsoft Debuts Visual Studio Tools for Office October 15, 2003
"The opportunity to use [Visual Studio Tools] in conjunction with Visual Basic .NET and Visual C# .NET to extend Microsoft Office 2003 is compelling," said Peter Gassner, senior vice president and general manager of the sforce products division at Salesforce.com.
The Possibilities Are Endless October 15, 2003
Oracle CEO Larry Ellison would be seen carrying a fruit basket into PeopleSoft headquarters and then would not emerge for hours. When he finally did, he would be carried out like a hero and would announce his decision to let PeopleSoft have the Oracle business line for free.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.