Two and a half years after launching its Trustworthy Computing initiative, Microsoft Corp. is finding its products the target of escalating attacks, to the extent that some security experts are even warning that the company's Internet Explorer (IE) browser is simply not safe to use.
While the company has been trying to take these slings and arrows in its stride, claiming they are an unfortunate side effect of being a market leader and that it's doing all it can to defend itself, users seem to be looking for reassurance that Trustworthy Computing will pay off -- and soon.
"They've launched this Trustworthy Computing campaign and they are still issuing all these patches. They shouldn't make things so complex. When is it going to get better?" asked software developer Michael Kranawetter. He was interviewed on the floor of last week's Tech Ed conference in Amsterdam where some 6,000 software developers and IT professionals gathered to hear the latest in Microsoft development news.
To be fair, Microsoft has been working hard to streamline its patching process, by releasing combined fixes when possible and delivering them on a monthly release schedule, for instance. It is also providing a free patching service and a centralized place for users to find fixes.
Besides improved patching, it is also moving to bolster the security of its desktop software, by turning off potential ports of attack and adding security features such as a firewall enabled by default, to help users protect their PCs.
Many new security improvements are due to be delivered with the much anticipated Windows XP Service Pack 2 (SP2), an update to the Windows XP operating system (OS), which is so jam-packed with fixes and features that installing it is said to be like a installing a whole new OS.
Microsoft executives have promised to deliver SP2 by "the end of summer" although Microsoft Senior Director of Trustworthy Computing for Europe, the Middle East and Africa (EMEA) Detlef Eckert said at Tech Ed last week that "summer ends in September this year."
"We have now realized -- to some extent, painfully -- that the security atmosphere has changed which is why we are putting so much effort into Service Pack 2," Eckert said. "Most of these new features would have blocked against recent attacks."
The company learned a great deal from threats like the Sasser Internet worm, he added, which wreaked havoc earlier this year by exploiting a disclosed hole in a component in Windows.
"We know we need to move ahead of the attack cycle and mitigate against specific attacks against applications," he said.
But while the company has been working to address users' security woes, it continues to come under attack from virus writers who clearly have a few tricks up their sleeves.
One of the latest attacks used Web sites running Internet Information Server (IIS) to launch malicious computer code, and prompted the company to release updates to its Windows 2000, XP and Windows Server 2003 software last week to help users fend off the attacks.
The Redmond, Washington, company also said last week that it is planning to release a number of updates in coming weeks to shore up the security of IE.
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »