Welcome | Sign In
ECommerceTimes.com
Security

Microsoft Issues Patches, Plans Security Overhaul - Again

Print Version
E-Mail Article
Reprints
Microsoft Issues Patches, Plans Security Overhaul - Again

Speaking at a conference in New Orleans, Louisiana, this week, Microsoft chief executive Steve Ballmer announced the company's next service pack for Windows XP will include more secured memory to ward off buffer overrun exploits, which have plagued Windows.


Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!

Microsoft (Nasdaq: MSFT) once again is discussing plans to overhaul its security just as the company has released five patches for seven newly discovered vulnerabilities in Windows desktop and server software.

Microsoft issued the patches for a range of Windows systems that could be compromised as a result of the vulnerabilities -- five of which were rated critical because they could provide attackers with direct access to computers via HTML e-mail or via malware, such as the Blaster worm that hit half a million machines last August.

As the volume of vulnerabilities and patches increases, the Redmond, Washington-based company repeatedly has said it is taking distinct steps to secure its flagship operating system: moving to a monthly patch schedule except for critical vulnerabilities; updating Windows XP to secure memory and force firewall use; and providing a site for users to find out more about protection.

But Microsoft's commitment to security is something an attack-rattled industry has heard before, Forrester analyst Jan Sundgren told TechNewsWorld. "These are not huge steps. It's not that dramatic, but it's still steady progress."

Locking Windows

Speaking at a conference in New Orleans, Louisiana, this week, Microsoft chief executive Steve Ballmer announced the company's next service pack for Windows XP will include more secured memory to ward off buffer overrun exploits, which have plagued Windows and other software.

With the XP update, due in the first half of next year, Microsoft also will turn on the operating system software's built-in firewall, which was not necessarily on by default before.

Microsoft spokesperson Sean Sundwall told TechNewsWorld that some of the measures -- such as a protection site where Microsoft recommends firewall, computer updates and up-to-date antivirus software -- are already under way.

Other measures, including the Windows XP service pack, will not be put in place until next year, Sundwall said.

Security Echo

Analysts agreed that Microsoft continues to improve its security practices, but the flow of vulnerabilities and patches seems to be increasing as much as Microsoft's security talk.

"They definitely need to improve security," Sundgren said. "Most importantly, they need to reduce the number of vulnerabilities that are emerging in their software. The problem is, there's so much legacy code, it takes time to find the vulnerabilities."

In response to criticisms that Microsoft's security speeches have been nearly as numerous as security holes in its products, Sundwall told TechNewsWorld, "Yes, we've said we are committed to security before, and we have been; as security takes different twists and turns, we adapt to that and make changes."

Long Haul

Analysts agreed that while Microsoft is making improvements to its software security, it will take time for the measures to slow down the bad guys.

Gartner (NYSE: IT) research vice president Richard Stiennon told TechNewsWorld that Microsoft has improved security by "finally" shipping products without open ports and services that unnecessarily expose users to attack.

Sundgren referred to the software maker's efforts with developers, which he said is one of the security measures that is well under way.

"I think they have trained their developers to be more security-minded, and that's an important part of their strategy," Sundgren said. "The impact is not going to be dramatic and instant, though. It will occur over time, and it will be harder [for attackers] to find those vulnerabilities."


Print Version E-Mail Article Reprints More by Jay Lyman


More by Jay Lyman

Open Source Developer Dumps Novell Over Microsoft Deal
December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux
December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0
December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network