May 08, 2003

WinHEC: Microsoft expects slow adoption for NGSCB

Critics fear security technology will limit user freedom

NEW ORLEANS -- Even though major hardware makers will support Next-Generation Secure Computing Base (NGSCB) from the start, Microsoft expects user adoption of its nascent security technology to be slow in the first year after launch, a company executive said Thursday.

"A small single digit percentage of PCs shipped in the year after (NGSCB) becomes available will support it, ramping up to double digits the year after that," said Peter Biddle, product unit manager at Microsoft's security business unit. "I am not sure if it will ever be in 100 percent of the systems," he said in an interview at Microsoft's Windows Engineering Hardware Conference (WinHEC) in New Orleans.

Corporate users will likely be first to buy the technology, according to a Microsoft spokesman. Early applications will include secure messaging and other applications especially interesting for corporate PC users, he said.

NGSCB is a combination of new hardware and software that Microsoft says will boost PC security but that critics fear could be a scourge for user freedom. Microsoft demonstrated NGSCB for the first time at WinHEC on Tuesday. The company plans to incorporate the technology in Longhorn, the successor to Windows XP planned for launch in 2005.

Computer processor maker Advanced Micro Devices (AMD) and graphics chip company Nvidia, two of Microsoft's hardware partners, said Thursday that they plan to have hardware that supports NGSCB ready when Longhorn is introduced. Intel also is expected to have processors ready by that time.

AMD thinks NGSCB might be in most PCs by 2008, said AMD Platform Security Architect Geoffrey Strongin.

"My crystal ball is pretty fuzzy. I don't think ubiquity by 2008 is unreasonable," he said.

NGSCB, formerly known by its Palladium code name, includes a new software component for Windows called a "nexus," and a chip that can perform cryptographic operations called the security support component (SSC). NGSCB also requires changes to a PC's processor and chipset and the graphics card. The combination of hardware and software creates a second operating environment within a PC that is meant to protect the system from malicious code by providing secure connections between applications, peripheral hardware, memory and storage.

Microsoft's Biddle expects PC makers to offer systems with and without support for NGSCB, giving PC buyers the choice whether they want it or not.

"I expect there to be boxes in the store that support (NGSCB) by having the hardware and boxes that do not," Biddle said. Microsoft is not putting any pressure on PC makers to incorporate NGSCB, he added.

PCs with NGSCB support will cost more than systems without the technology, Biddle said.

"It will be a value-added feature that people will be willing to pay more for," Biddle said of NGSCB. Microsoft has said it wants to keep the cost of NGSCB for the PC buyer under $50. Biddle would not give a dollar amount, saying only that $50 "sounds high."

Tonya Dezso, a spokeswoman for AMD, said the $50 "sounds reasonable" but added that the higher price would "not come from the processor or other hardware."

"We are aiming to keep the cost as low as possible," she said. "Users typically don't want to pay more for anything."

Although Microsoft says NGSCB will be a boon for its customers, critics have argued that it will curtail users' ability to control their own PCs and could erode fair-use rights for digital music and movie files. NGSCB could be a Trojan horse for copyright enforcement through its DRM (digital rights management) capabilities, critics say.

"Our concerns are whether it can be used to limit the user's control over his PC and prevent interoperability," said Wendy Seltzer, a staff attorney with civil liberties organization the Electronic Frontier Foundation (EFF).

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2010 Infoworld, Inc.