Error » Microsoft Error! » Microsoft Operating Systems Error » Microsoft windows vista error » Microsoft's new identity: secure OS vendor?

Microsoft windows vista error all errors related to microsoft windows vista

Post New Thread Reply
  Microsoft's new identity: secure OS vendor?
LinkBack Thread Tools Display Modes
Old 08-Dec-2006, 10:36 AM   #1 (permalink)
Administrator
 
Anilrgowda's Avatar

Posts: 18,715
Join Date: Jan 2006
Rep Power: 10 Anilrgowda is on a distinguished road

IM:
Default Microsoft's new identity: secure OS vendor?

Microsoft Windows Vista has been released! Well, released to enterprise customers, at least. Consumer and foreign language versions will be released in January.
In preparing my most recent book, Windows Vista Security: Securing Vista Against Malicious Attacks (Wiley), co-authored with Dr. Jesper Johansson, I’ve counted more than 180 new security improvements and features in Vista. I’ve been developing a PowerPoint presentation on it, and it’s already exceeded 220 slides (and I’m only a third of the way done).
Here are the most significant new features:
** The real Administrator account is disabled by default
** User Account Control prompts users in the Administrators group for an additional confirmation before every administrative task
** Even the Administrator cannot directly overwrite files in the \Windows and \System32 folders. They have to take ownership first, and add the correct permissions
** Internet Explorer 7 runs in Protected Mode by default, which will stop many “drive-by” download attacks
** Address Space Layout Randomization will randomly place critical Windows functions and applications in 1 of 256 places in memory, making many types of buffer overflows significantly harder to pull off
** BitLocker allows one or more drive volumes to be encrypted, and protected with an encryption key that can be stored locally, on a cryptographic chip on the motherboard, or on a USB key
** LM password hashes are disabled by default (finally!) as are LM and NTLMv1 authentication protocols
** Windows Firewall is enabled by default, protects better at boot-up, is integrated with IPSec, and has outbound blocking
** Firewall rules can be applied to specific users, computers, or groups
** Windows Defender is installed by default
** Password-protected screensaver is installed and made active by default
** Over 800 new group policy settings
** You can set multiple user or group-specific Local Security policies
** Session isolation (i.e. Windows kernel services and user-mode programs run in different Windows sessions) will prevent most “shatter”-style attacks
** Services now have SIDs, which simplifies setting security permissions. All default services have been given least-privilege permissions, and are limited by firewall security domain protection
** Portable media devices (such as USB flash memory, CD-ROMs, etc.) can be controlled with read, write, and execute permissions, both per user and per computer
** Integrity levels have been assigned to all files and objects. A security principal must meet or exceed the target resource’s integrity level in order to modify it; regardless of the NTFS permissions
** There are dozens of new log files, all collected in the expanded Event Viewer. Event triggers can be created on any event, and events can be collected to centralized computers
** Transactional NTFS ensures that NTFS changes will be written completely before being made permanent
** Previous Versions client is installed by default, allowing users to self-recover accidentally deleted or modified files
** System Restore now backs up user’s My Documents folder
** Creator Owners now no longer automatically get Full Control permissions, if you don’t want them to
** Commonly manipulated folder and registry keys are virtualized so that malicious modifications don’t result in system-wide infections
** EFS supports smart cards, can encrypt the page file, and has proactive key archival
** Remote Desktop Protocol (RDP) supports strong authentication with digital certificates
** Internet Explorer 7 has an anti-phishing filter and is more resistant to malicious attacks, spyware, and add-on abuse
** Internet Information Service 7 supports more granular loading of code. IIS is no longer a single monolithic executable
** Two more network domain profiles to plan firewall and IPSec rules around
** IPv6 and IPv4 are turned on by default
** Improved wireless security. Now, GPOs and logon scripts can be accomplished through wireless logons
** Improved SMB (file and printer sharing) protocol. Anonymous null session connections are no longer the great threat they once were
If you want more information on any of these features, just e-mail me at roger_grimes@infoworld.com.
Will Vista be hacked? Sure, anything super-popular gets hacked. IE 7 is the most likely target, of course, followed by Windows Mail (the Outlook Express replacement), because these applications have the highest visibility and hacker interest.
Which new services are likely to be hacked? I’d put my money on the RSS feeds, XML, and the new P2P and collaboration applications. Aside from the more than 70 new services, Vista has a lot of new file formats for hackers to explore, as well.
I will go out on a limb and say that I believe Windows Vista, and the forthcoming Longhorn server, will be tough to hack. Outside of client-side attacks and Internet Explorer, the fully-patched Windows XP Pro SP2 is already pretty hard to hack externally. Vista will never be as secure as OpenBSD, but I believe it will be secure enough to ensure that Microsoft becomes known as a vendor of choice for a secure operating system. And that’s a far cry from where it was five years ago.
If you don’t believe me, talk to the many professional hackers that Microsoft has invited to test and strengthen Vista. Hundreds of internal and external hackers gave it their best whacks. A few succeeded in finding new exploits (or in re-finding old exploits). But ask any of them what they think of Microsoft’s new OS, and all will tell you it’s a lot harder to hack than its predecessor.
Anilrgowda is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Secure Computing Introduces Secure Web Reporter for Complete, Real-Time Viewing of We newsprovider Security News 0 05-Aug-2008 02:12 AM
Secure Computing’s Secure Web Protects Joy Global From Web 2.0 Threats newsprovider Security News 0 17-Jun-2008 08:15 AM
1st European Summit on Identity - Identity Matters - resolves unanimously to take the webitpr Security News 0 21-Nov-2007 09:29 AM
Steganos Secure VPN PREMIUM enables companies to build secure LANs for mobile workers webitpr Security News 0 15-Mar-2007 04:10 AM
Microsoft's own antivirus fails to secure Vista Anilrgowda Microsoft windows vista error 0 06-Feb-2007 11:01 PM


All times are GMT -8. The time now is 01:21 PM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228