By Jay Lyman TechNewsWorld Part of the ECT News Network
08/09/04 12:47 PM PT
SP2 will not fully solve the security issues that have cost companies time and other resources, but it will make things more difficult on attackers, who have grown more cunning in their assaults on Windows. 'It doesn't mean you're not going to have a hack, but a hack delayed is often a hack thwarted,' said Yankee Group analyst Laura DiDio.
After extensive investment, testing and delay, Microsoft (Nasdaq: MSFT) has made its
Service Pack 2 (SP2) for Windows XP available and is urging corporate and
consumer users to update the operating system, which has been bombarded
by Explorer browser and other vulnerabilities.
An enormous batch of security upgrades and other fixes typical of a
full software update, SP2 has been widely anticipated as a
provider of better security -- as well as a potential breaker of other
applications.
Microsoft provided the patch to Windows XP users with an easier
automatic update. Industry force IBM (NYSE: IBM), however, said it would not install the update until it could test the final release of SP2 on its own.
"You always have to test," Yankee Group senior analyst Laura DiDio told TechNewsWorld. "All of the networks are so heterogeneous these days, you can't predict where and how these things will interact."
Security Shot
Nevertheless, analysts agreed that system administrators -- who have
battled an increasing number Windows vulnerabilities,
attacks and outbreaks -- are happy to have some reinforcement
from Redmond.
"The IT departments are battle-weary," DiDio said. "They are damn sick
and tired of getting alerts every day. Windows has come under constant,
deliberate assaults and attacks."
DiDio added that while SP2 will provide greater security for both
individuals and corporations, the security struggle will continue.
"This is a pretty big weapon in the ongoing war, and you can expect them
to spend billions more," DiDio said. "This is not the be all and end
all."
Rollout Roll of Dice
Meta Group vice president Steve Kleynhans said companies eager to shore
up security will likely update Windows XP systems fairly quickly.
The update, however, will not necessarily be easily absorbed, as evidenced by Microsoft's warnings that the update might cause problems with its own customer relations management software.
Still, the analyst indicated that companies will update with SP2 but perhaps
turn off the firewall, which is now a default feature from Microsoft
with the update. Kleynhans told TechNewsWorld, "In the
end, most companies will end up implementing SP2. They may not turn on
all of the capabilities, but ultimately, they'll [update]."
Testing or Turning Off
Gartner (NYSE: IT) research vice president Richard Stiennon said companies will test SP2 as if it were a new
version of an operating system.
Stiennon told TechNewsWorld that the impact of SP2, which reportedly has already
thwarted access to popular Web sitesm, might also force companies simply to turn off all
of the security features contained in the update.
Stiennon said it will take time to evaluate how much SP2 actually improves security. "It won't have an overall impact on reducing threat exposure for a long time," he said.
More Than Microsoft
DiDio said SP2 will not fully solve the security issues that have cost companies time and other resources, but it will make things more difficult on attackers, who have grown more cunning in their assaults on Windows.
"It doesn't mean you're not going to have a hack," DiDio said. "But a hack delayed is often a hack thwarted."
DiDio explained that it is up to Microsoft to fix security holes in its software and provide updates such as SP2, but it is up to consumers and companies to protect themselves with their own security steps.
Microsoft Windows XP Service Pack 2 Arrives August 06, 2004
"Service Pack 2 is a significant step in delivering on our goal to help customers make their PCs better isolated and more resilient in the face of increasingly sophisticated attacks," said Bill Gates, chairman and chief software architect at Microsoft.
Related Stories
Windows Users Eagerly Await XP Service Pack 2 August 06, 2004
The security-focused Windows XP Service Pack 2 (SP2) update for Microsoft's main operating system is now only days away, Microsoft's senior product manager Matt Pilla indicated this week.
A New Era of Internet Threats August 06, 2004
In the earlier age of virus attacks, computer users had to interact with the infection vehicle in order to activate the virus. While those old techniques relied on the ignorance of end-users, in today's world the end-user doesn't have to do anything wrong. The Scob attacks of this past June give a hint of what's to come.
Microsoft SP2 Possibly Toughest Rollout Yet August 05, 2004
Analysts agreed that the size and significance of SP2 render it as close to a new version of Windows as Microsoft could get while still calling it an update. "Enterprises are taking a wait and see approach," Meta Groups's Steve Stiennon told TechNewsWorld. "It's going to go through a lot of the testing that a new version of Windows does."
Microsoft Delays Windows Server, XP Upgrades July 28, 2004
Microprocessor maker AMD has made 64-bit chips a centerpiece of its strategy to compete with rival Intel in the desktop space and recently rolled out a line of mobile chips aimed at appealing to users who want to be at the cutting edge of the 64-bit revolutions.
The delays could also give open-source rivals of Microsoft a chance to plant a flag in the 64-bit server niche.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.