Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

Analysts, users disagree on Vista pros, cons

Enterprise reality could dampen Vista's shock

By Paul  F. Roberts
May 15, 2006
 

As Microsoft slouches toward its first full operating system release in five years, code-named “Vista,” Microsoft-watchers are beginning to debate the impact of the system’s security enhancements, which could be more pain than gain.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Return to Vista report

TALKBACK

Share your views on Microsoft's Vista


New firewall and anti-spyware features, tighter user role management, and drive encryption technology called “BitLocker” may change the landscape of the lucrative desktop security market forever. But for enterprise IT staff, the stronger security protections could cause headaches in the short run, said Andrew Jaquith, a program manager at Yankee Group Research. Still, a CIO at one organization that tested the new operating system says that Vista security is right on track.

Jaquith based his assessment on a Yankee Group test of a December 2005 CTP (Community Technical Preview) release of Windows Vista. He recorded his findings in a May 8 report called “Microsoft’s Vista Won’t Stop the Windows Security Aftermarket.” The report found that Microsoft “did a lot of things right” with Vista security that would make it difficult for malicious software to propagate using the operating system, Jaquith told InfoWorld.

The Yankee Group, however, took a dimmer view of Microsoft’s implementation of limited-access user accounts, which scale back the actions ordinary users can take on the operating system. Jaquith said Microsoft’s enforcement of the limited permissions in the version that Yankee tested was “invasive,” and would irritate ordinary users with frequent warning messages around simple tasks such as deleting desktop shortcuts.

“You can’t fault Microsoft for wanting to give users choice, but those choices are presented too often,” Jaquith said.

Instead of making users security-conscious, the constant pop-up warnings about actions that could “harm your computer” will have the opposite effect: They will desensitize Windows users to real threats, Jaquith said.

The Yankee Group’s report was not greeted very warmly in Redmond, where Microsoft engineers have had to winnow features from Vista for almost two years to meet a 2006 release date.

Yankee was testing old code, not the latest “Beta 2” release of Windows Vista, which cut out some notifications after testers complained, said Austin Wilson of Microsoft’s Windows Client Group.

The final version of Windows will “polish” the user experience even more, eliminating security warnings for trivial actions, Wilson said.

IT staff for Fulton County, Georgia, a Windows Vista test site, also downplayed the user role changes in Vista. Least privileged user accounts aren’t a significant change from the way the county already manages user access, according to Robert Taylor, Fulton County’s CIO and director of IT.

“Our current policy limits access to the desktop for only domain users, (ensuring) that users do not have the capability to install unauthorized or any software without domain administrator privilege,” Taylor wrote in an e-mail message.

Coupled with Microsoft’s Group Policy features, Vista with User Account Control will actually give Fulton County users more control of their desktop than they have with XP, allowing them to install local printers and Internet plug-ins in limited-access user profiles, Taylor wrote.





 


 
Paul F. Roberts is a senior editor at InfoWorld.
 

TOP NEWS:


»  Parts of San Francisco network still locked out
Administrators are still locked out of the city's VoIP system and LANs within the Sheriff's Department and the Recreation & Park Department

»  Intel says Moblin update coming soon
Open-source effort set for mobile Linux should have an alpha-level release in a few weeks

»  Are virtual firewalls a solution for VM security?
Virtual firewalls can be a useful security tool, but their efficacy depends heavily on how you have set up your networks

»  Ubuntu to unveil new version of Launchpad next week
Ubuntu's beta community still has a long way to go to achieve the popularity of competitors such as SourceForge.net

»  Oracle unveils access management suite
Oracle's suite includes a new server that provides controls to fine-tune user privileges

»  5 ways the iPhone 3G still lags in enterprise
Despite Apple's improvements, its iPhone 2.0 software remain less competent and less tested than its BlackBerry and Windows Mobile counterparts




Keeping the E-Mail Flowing
Traditional exchange and recovery solutions are not only complicated, but very expensive. Learn from the experts how to implement Continuous Application Protection (CAP) and save yourself the complications and cost of traditional exchange and recovery solutions. Sponsored by AppAssure

»  Click here to view this Webcast
  Zombie PCs Are Attacking Your LAN
A recent study showed that malware-infected zombie PCs are now a bigger threat to ISPs and Web infrastructure than DoS attacks. As this brand new IT Strategy Guide explains, an increased use of peer-to-peer techniques by the attackers has made it harder to fight back. Download now, compliments of Verio:

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist