Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register
Page 2 of 2  «  Previous Page

Microsoft weighs strong app IDs for Windows future

 

Microsoft's interest in application secure IDs is part of a larger effort to give administrators a finer degree of control over applications, said Mark Russinovich, a Windows security expert at Winternals Software, which makes system recovery and data protection software for Windows.

Free IT resource

Virtualization Insights from Top Experts - Learn how virtualization gets real!

Sponsored by Dell

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

More from Tech Ed

Traditionally, Windows applications have been granted access to one of three broad "service" accounts that came with rights to a wide range of system resources, regardless of the purpose of the applications. Malicious code authors have made use of those broad privileges for years, using attacks like buffer overflows to take control of applications and their elevated privilege on Windows systems to run amok, he said.

"It's a way to specify for a particular service what it needs access to and refine the scope of the privileges," Russinovich said.

But engineers at Microsoft will have to navigate a minefield of potential problems to make the strong, application secure IDs a reality. Challenges range from managing cryptographic signatures across enterprise applications to suspicion among ISVs that the Redmond company will use the secure IDs and lock out Windows competitors, experts say.

"There's no doubt that auditing secure environments will be more complex," said Dennis Moreau, CTO at Configuresoft.

As with the UAC technology, application secure IDs will require adjustment from software vendors.

"All applications are built with the assumption that they have access by default. This will get in the way of that and change the underlying authentication model," he said.

But complaints from customers, which also marked Microsoft's introduction of UAC, is not necessarily a bad thing, said John Pescatore, a vice president at Gartner.

"With XP SP2 you got one level of squawking and another level of squawking with Vista -- customers saying 'All our boxes and applications don't work!' But you have to raise the bar more," he said.

Cryptographic application IDs built into Windows should improve security. However, there's no guarantee that malicious code authors will not warm to the new architecture as well, Moreau said.

"Suppose exploit vendors apply for blocks of root keys from Verisign. Now [certificate authorities] have to issue growing revocation lists to deal with them. And that's the exact problem with PKI in enterprise environments," he said.

Fathi acknowledged the challenges facing the new application secure ID plans, and said Microsoft is just beginning to get "its hands around" the problem.

However, the advantages in such an architecture are considerable, he said.

Microsoft is looking into ways to tie reputation-based services to strong application IDs to ease security concerns in managed environments, with one Windows user being able to automatically "trust" a particular application within formal or informal networks, he said.

Applications, verified with strong application IDs, could one day have reputations akin to the URL reputation services that companies such as Microsoft and AOL offer to their customers to prevent phishing and spyware, he said.

Application reputations could be a big benefit for enterprises, which would have more assurance that the application they deploy meets standards, such as Common Criteria certification, said Pescatore.

However, the new architecture could awaken old debates about anti-trust and Microsoft's control of the desktop, he acknowledged.

"Microsoft sells a lot of software products. Will [IBM] Lotus get certified by Microsoft? Is that the way the world wants to go?" he said.


»  Previous Page | 1 | 2 



 


 
Paul F. Roberts is a senior editor at InfoWorld.
 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




REMOTE ACCESS: MAINTAIN SECURITY AND DECREASE THE BURDEN ON IT
Join this interactive webcast to discover how IT Managers can control access rights, end-user security settings and end-point authorization. Sponsor: Citrix(R) GoToMyPC(R) Corporate

»  Click here to view this Webcast
  WAN Emulation Sponsored Solutions Guide
WAN emulation technology enables IT organizations to predict reliably how applications will perform in a networked environment, before application rollout, mitigating development risk and costs.This Sponsores Solutions Guide has everything you need to now about WAN emulation and WAN and how to best implement it in your organization. Sponsored by Shunra

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist