Has Microsoft kept its Vista security promise?

Just three months into the official commercial release of the OS, questions are flying

The road to security

"We remain confident that Windows Vista is the most secure version of Windows to date," says Russ Humphries, senior program manager for Windows Vista security, "however, it is important to note that no operating system is ever going to be 100 percent secure -- there are no silver bullets."

The bottom line: Windows Vista is not immune to attack, nor would it be fair to expect it to be. Technological advances within the OS bestow real security benefits, but Microsoft acknowledges that Vista users will benefit from aftermarket security and anti-malware products, as they have for previous versions of Windows.

As is often the case with Microsoft operating systems, perhaps Vista's biggest weakness lies in the desire for backward compatibility. Most of the vulnerabilities discovered in Vista so far exploit legacy applications that don't take advantage of the new Windows security model. Even UAC itself is a capitulation to outdated practices.

The sooner enterprises embrace the latest Windows technologies, the sooner they will begin to benefit from Microsoft's engineering efforts in the area of security. Wherever possible, custom applications should be migrated to managed code and the .Net framework, and care should be taken to observe the new core Windows security APIs and practices. Even more hardware-based security mechanisms will become available as the industry transitions to 64-bit computing platforms.

In the meantime, the watchword is caution. Microsoft has issued specific security guidance for IT administrators who are evaluating Vista for enterprise networks with Active Directory.

The exact configurations recommended depend on the level of security required within a given organization, but the overall message is straightforward: Effective security under Windows Vista will still require a combination of IT oversight, adherence to security policies, and third-party anti-malware and security management tools -- in other words, business as usual. Vista does represent a significant security improvement over Windows XP, but after all, it's still Windows.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

More about MicrosoftPromiseSymantecWebroot

Show Comments
[]