Error » Microsoft Error! » Microsoft Operating Systems Error » Microsoft windows vista error » Experts sceptical on Vista security

Microsoft windows vista error all errors related to microsoft windows vista

Post New Thread Reply
  Experts sceptical on Vista security
LinkBack Thread Tools Display Modes
Old 25-Feb-2007, 10:58 PM   #1 (permalink)
Administrator
 
Anilrgowda's Avatar

Posts: 18,762
Join Date: Jan 2006
Rep Power: 10 Anilrgowda is on a distinguished road

IM:
Default Experts sceptical on Vista security



Microsoft has been promoting Windows Vista's security for years, saying that it will prove to be its strongest, toughest operating system ever. But now that the long-awaited operating system is out, how will Vista really stack up? Ben Fathi, the former head of Microsoft's security group and now the chief of development in the Windows core operating system group, recently set the security bar.
"I made a statement six or nine months ago that I would like to see half as many vulnerabilities as XP [had] in the first year," Fathi said earlier this month at the RSA Conference 2007 in San Francisco. "Obviously, I'd like less than that; I'd be happy with zero. But I think it's reasonable to say, given the additional complexity and the additional size of Vista, that half as many would be a great goal."
In the first year after Windows XP debuted in October 2001, Microsoft posted 30 security bulletin pegged to the Home version of the then-new operating system. (Unlike today, Microsoft didn't spell out the number of vulnerabilities in each bulletin.)
For Microsoft to meet Fathi's goal, that means 15 or fewer security updates will tag Vista before the end of January 2008 - a year after the retail/consumer release. Is Fathi being overly optimistic, or is he being conservative in the hope that the first 12 months look even better than predicted? Computerworld asked a half-dozen security researchers and analysts for their take on Fathi's target. Not surprisingly, they don't all agree on whether the security objective is obtainable - or out of the question.
Minoo Hamilton, senior security researcher, nCircle Network Security.
"I agree when he says that it's a 'great goal,' where 'great' implies tremendous luck and fortune. Whether it's a reasonable goal, it will remain to be seen, but I don't think so. I think that would be quite spectacular, if it came to pass.
"I think he's overconfident, but also speaking hopefully. They've put a tremendous amount of effort into improving things in Vista. I just think a few factors make that harder to come to pass. First, there is so much new code and new opportunity for vulnerabilities. Secondly, the ease, speed and ability of people to find flaws have really improved.
"I think the age of mass-proliferating Internet worms in waning, because the remote surface space is finally starting to diminish. This may partly be due to host-based firewalls and better enforcement of IT policy, but also - in the case of Vista - more standard OSs are starting with a more conservative approach to exposure. How this shifts the offensive tactics of malware and virus writers, I can't be completely sure, since it's incredibly hard to predict. But I think this will force them into continuing the trend toward browser, e-mail and parsing exploits.
"In the case of Vista, owning a box will now require multiple hoops or combining exploits, like a browser vulnerability and a local vulnerability that gives privilege escalation, for example. In any case, I believe this raising the bar will coincide with the trend of increased sophistication of attackers and balance out.
"I am not expecting a huge decrease in Microsoft vulnerabilities. My best guess is more likely a 20 percent decrease, if that."
Michael Cherry, analyst, Directions on Microsoft.
"Making these kinds of predictions is like saying when you're going to ship. If you're right, no one pays attention. But if you're wrong, they'll rub your nose in it.
"Actually, I don't want to set my mindset to a certain number of vulnerabilities, or say a certain number is acceptable. I don't care if it's only one vulnerability, because if it's really, really bad, that's worse than 20 cosmetic bugs. Better, I think, would be to set a goal that says 80 percent of the vulnerabilities in the first year will be [rated] important or less.
"Fathi should have said, 'We are just not going to discuss counting' and leave it at that.
Graham Cluley, senior technology consultant, Sophos PLC.
"I have to say that I admire Microsoft's optimism.
"I would perhaps be more cautious than Fathi because in the last five years, the number of hackers and researchers who are examining Microsoft's code for vulnerabilities with ever greater intensity has increased. Furthermore, we have seen a number of legitimate security companies (including some who may have a vested interest in debunking Microsoft's status as a security player) put efforts into finding flaws in Microsoft's code.
"What isn't in doubt is that there will continue to be flaws found in Microsoft Vista.
Michael Silver, analyst, Gartner Inc.
"While the number of critical holes is important, for enterprises it would be nice if they had one or more months with no critical issues on Vista. That could actually have more of an impact in reducing the cost of testing and deploying fixes than reducing the overall number, because it would mean fewer test and deployment cycles.
"I think XP even had one or two months with fixes dropped [there were no XP bulletins released in January 2002], so reducing the number of months with fixes from like 13 to 10 would be great for organizations."
Oliver Friedrichs, director of security response, Symantec Corp.
"It's just too early to tell. Certainly, just as with XP SP2, some of the improvements in Vista will make an improvement in the number of security vulnerabilities and the [in]ability of attackers to exploit them. But the volume of new code in Vista makes it hard to predict what we'll see.
"I am sure, though, that hackers are already hammering away at the OS. I don't expect it to be bug free.
"What we need to remember, however, is that over the last decade, relatively few of the vulnerabilities released had been leveraged by attackers. The rest are largely irrelevant. So if those 15 are critical vulnerabilities, things may not be any different than with XP.
"But 15 doesn't sound unreasonable to me, given the amount of new code."
John Pescatore, analyst, Gartner.
"We saw definite improvement [in security] from Windows Server 2000 to Windows 2003 Server, not only many fewer vulnerabilities, but many fewer critical ones. Gartner believes we will see a similar improvement from Windows XP to Vista.
"Half as many critical vulnerabilities would be a conservative goal, [though] I would hope for much fewer than those, given all of Microsoft's investment in, and marketing of, its Security Development Life Cycle. I'd say a better success measure would be more like [a] 25 percent [reduction], not 50 percent.
"Vista does have more 'stuff' jammed in. Microsoft just had to announce a critical vulnerability in the malicious software detection engine, which is now built into Windows because of the [integrated] Defender anti-spyware. That works against security. Late in Vista's development, Microsoft ripped out a lot of other stuff (like new file systems and virtualisation and the like), which reduced the complexity a good deal (a good thing) but always raises the worry that the late modifications may have opened up security holes. Also, many of those functions will come back to Vista later on. ... Vista will change much more continuously than any previous Windows OS, and that has to be done very, very rigorously or there are more security worries.
"We have to look at Office as well. If you notice, many of the vulnerabilities being found are in how Word and Excel documents are handled. Also, Office Live, the Web 2.0 version of Office, how is [Microsoft] applying security to that rapidly changing capability?
"Fathi has a lot to worry about, not just Vista security."



Source:Techworld.com - Security Insight - Experts sceptical on Vista security
Anilrgowda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Forum Jump


All times are GMT -8. The time now is 08:47 AM.

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232