May 15, 2006

Analysts, users disagree on Vista pros, cons

Enterprise reality could dampen Vista's shock

As Microsoft slouches toward its first full operating system release in five years, code-named “Vista,” Microsoft-watchers are beginning to debate the impact of the system’s security enhancements, which could be more pain than gain.

New firewall and anti-spyware features, tighter user role management, and drive encryption technology called “BitLocker” may change the landscape of the lucrative desktop security market forever. But for enterprise IT staff, the stronger security protections could cause headaches in the short run, said Andrew Jaquith, a program manager at Yankee Group Research. Still, a CIO at one organization that tested the new operating system says that Vista security is right on track.

Jaquith based his assessment on a Yankee Group test of a December 2005 CTP (Community Technical Preview) release of Windows Vista. He recorded his findings in a May 8 report called “Microsoft’s Vista Won’t Stop the Windows Security Aftermarket.” The report found that Microsoft “did a lot of things right” with Vista security that would make it difficult for malicious software to propagate using the operating system, Jaquith told InfoWorld.

The Yankee Group, however, took a dimmer view of Microsoft’s implementation of limited-access user accounts, which scale back the actions ordinary users can take on the operating system. Jaquith said Microsoft’s enforcement of the limited permissions in the version that Yankee tested was “invasive,” and would irritate ordinary users with frequent warning messages around simple tasks such as deleting desktop shortcuts.

“You can’t fault Microsoft for wanting to give users choice, but those choices are presented too often,” Jaquith said.

Instead of making users security-conscious, the constant pop-up warnings about actions that could “harm your computer” will have the opposite effect: They will desensitize Windows users to real threats, Jaquith said.

The Yankee Group’s report was not greeted very warmly in Redmond, where Microsoft engineers have had to winnow features from Vista for almost two years to meet a 2006 release date.

Yankee was testing old code, not the latest “Beta 2” release of Windows Vista, which cut out some notifications after testers complained, said Austin Wilson of Microsoft’s Windows Client Group.

The final version of Windows will “polish” the user experience even more, eliminating security warnings for trivial actions, Wilson said.

IT staff for Fulton County, Georgia, a Windows Vista test site, also downplayed the user role changes in Vista. Least privileged user accounts aren’t a significant change from the way the county already manages user access, according to Robert Taylor, Fulton County’s CIO and director of IT.

“Our current policy limits access to the desktop for only domain users, (ensuring) that users do not have the capability to install unauthorized or any software without domain administrator privilege,” Taylor wrote in an e-mail message.

Coupled with Microsoft’s Group Policy features, Vista with User Account Control will actually give Fulton County users more control of their desktop than they have with XP, allowing them to install local printers and Internet plug-ins in limited-access user profiles, Taylor wrote.

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.