Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

Has Microsoft kept its Vista security promise?

The blogosphere is all over Vista security. Here's our crack at sorting the real flaws from the anti-Microsoft hysteria


Unfortunately, UAC is not perfect. On her blog, Joanna Rutkowska details several flaws in Vista's UAC implementation that are potentially exploitable. For example, software installers are always allowed to run with full administrative privilege, just like in old-fashioned Windows. In addition, Symantec security analyst Ollie Whitehouse points out that Vista ships with executables that can be used to compromise UAC.

Download PDF

“I still think that Microsoft did a good job with Vista,” Rutkowska says, yet the significance of these discoveries is clear: Don’t expect UAC to eliminate problems associated with the administrator account overnight.

Programmatic exploits aren’t the only way around UAC’s protections, either. User behavior is equally critical. UAC confirmation dialogs can be intrusive and somewhat cryptic. Users might be tempted to simply disable UAC out of frustration, or they might become so numb to the UAC warning messages that they click “OK” without thinking. What’s more, they can easily be tricked into doing the wrong thing using social engineering or deception.


Click for larger view.
“Windows Vista provides many features to protect your system, but they require proper use,” reads Microsoft’s Windows Vista Security Best Practice Guidance for Consumers on the subject of UAC. “Your system security is only as strong as your actions, so think before you click.” In other words, relying on UAC puts the responsibility for system security in the hands of the individual user — hardly an ideal scenario.

In fact, Microsoft discourages customers from thinking of UAC as an explicit security boundary — and therefore, as Rutkowska notes, it does not consider flaws in the UAC implementation to be security flaws. Don’t ignore this point. It speaks volumes to how IT should view UAC within the enterprise environment.

Tweaking out
Microsoft has added numerous other features to Windows Vista besides UAC, many of which are intended to increase the overall security of the OS. But upon closer examination these add-ons are only marginal improvements over previous versions of Windows.

Windows Firewall has been enabled by default on all new Windows installs since the introduction of Windows XP Service Pack 2. With Vista, Windows Firewall gains the capability of blocking outgoing connections as well as incoming ones — a marked improvement, when you consider the growing threats of spyware, phishing, and DDoS attacks. Unfortunately, the filtering of outgoing packets is not enabled by default. In other words, Vista’s firewall won’t provide significantly more protection than the one included in XP SP2 without manual configuration.

Neil McAllister is a senior editor at InfoWorld.
Continued
« PREVIOUS PAGE | 1 | 2 | 3 | 4 | NEXT PAGE » 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





MIGRATING TO VISTA
Join Windows Vista Expert, Richard Whitehead as he presents the benefits and challenges of migrating to Windows Vista. Sponsored by Novell

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 10/07/2008

AMD to split into two companies, SAP suffers from stock market turmoil...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist