Feeds

NT scales C2 security heights – but what about Win2k?

Long term, the NCSC criteria are challenges the company can't rise to

  • alert
  • submit to reddit

Maximizing your infrastructure through virtualization

Microsoft announced this week that it has received Orange Book C2 certification for NT 4.0, and FIPS 140-1 validation of the cryptographic services in Windows 95, Windows 98, NT 4 and Windows 2000. Microsoft says that "customers now have formal, third-party verification of the security" of these operating systems. Microsoft also said that "C2 is generally acknowledged to be the highest rating a general-purpose operating system can achieve", something that it has said before, but in different context, as we shall see. First let's recap on these coloured books. The US Department of Defense, through the US National Computer Security Center (NCSC, part of the National Security Agency), has a series of "rainbow" books, known as the DoD Trusted Computer System Evaluation Criteria. The Orange Book defines the criteria, but the Red Book is an interpretation of the Orange Book. The Red Book came about because the Orange Book was inadequate with regard to networking. There is also a Blue Book for advanced systems. The criteria are hopelessly out-of-date in many respects, because it takes so long for security organisations to develop standards. The only C2 security that Microsoft had previously received was Orange Book for Windows NT 3.5 (not 3.51) - but it was required that networking was disabled, that the floppy disk drive was disabled, and that the standard file system permissions were changed to be very restrictive, along with many permissions in the registry. Some cynics compared the process with castration. At the time, Enzo Schiano, a Windows NT Server product manager also noted that C2 presumes that the PC is kept locked away from unauthorised users since it was only necessary to remove the hard disc to get access to all the data. Microsoft had received E3/FC2 for NT3.51 and NT 4.0, but this level is regarded as too low for serious security consideration. If C2 Orange Book is about as reassuring as food labelled "100 per cent organic", then the E and F levels are perhaps the equivalent of dog food. In May, when Microsoft was not allowed to bid for the US Army Battle Command System which required secure messaging, Microsoft was cross because the UK Information Technology Security Evaluation Criteria (ITSEC) certification board had given Windows NT 4.0 (with Service Pack 3) an E3/FC-2 rating, which Microsoft then called "the highest security evaluation possible for a general purpose operating system". Sounds familiar, does it not? But that's what Microsoft now says about its Orange Book C2 certification. There were many critics of NT security. Terry Edwards, director of technical integration for the US Army's Force XXI initiative at Fort Hood, Texas, considered that "NT cannot support our security requirements". Mary Ellen O'Brien, director of DoD sales, Microsoft Federal, confirmed that MS is working with a third party, which she refused to name, to develop a Unix client for Exchange. Microsoft was concerned that Notes, running on Solaris, may increasingly replace Exchange in the military. It has also upset Microsoft mightily that Novell had received the superior Red Book C2 security on both the server and the client for NetWare 4.11, which meant that NT Server had no level of certified security. A Novell product manager sniffily described NT security as "an entire disease: they throw a password around the network, so it is available for capture, so it's not surprising that professional hackers are finding holes". In October at Gartner's Orlando meeting, Ann Reid of the US Department of Agriculture asked Steve Ballmer what Microsoft was doing about security problems and the federal information security requirements. Ballmer had to admit that Windows 2000 was unlikely to meet the requirements, which was interpreted at the time as no C2 in prospect. There is a footnote, and a serious one. Ed Curry, a former independent contractor for Microsoft and a security specialist, claimed that in 1998 Microsoft had been selling NT 3.51 and 4.0 to the US government and representing them as secure versions when they were not, and had false information on its Web site. Curry, who has since died, wrote to the US Secretary of Defense at the time claiming that "Microsoft has knowingly and wilfully concealed information regarding security flaws in computer hardware... I have raised the issue internally with Microsoft, and in return have been the subject of both bribes and threats". ®

The Power of One Infographic

More from The Register

next story
BBC goes offline in MASSIVE COCKUP: Stephen Fry partly muzzled
Auntie tight-lipped as major outage rolls on
You! Pirate! Stop pirating, or we shall admonish you politely. Repeatedly, if necessary
And we shall go about telling people you smell. No, not really
Airbus promises Wi-Fi – yay – and 3D movies (meh) in new A330
If the person in front reclines their seat, this could get interesting
UK Parliament rubber-stamps EMERGENCY data grab 'n' keep bill
Just 49 MPs oppose Drip's rushed timetable
There's NOTHING on TV in Europe – American video DOMINATES
Even France's mega subsidies don't stop US content onslaught
Samsung threatens to cut ties with supplier over child labour allegations
Vows to uphold 'zero tolerance' policy on underage workers
Dude, you're getting a Dell – with BITCOIN: IT giant slurps cryptocash
1. Buy PC with Bitcoin. 2. Mine more coins. 3. Goto step 1
ITC: Seagate and LSI can infringe Realtek patents because Realtek isn't in the US
Land of the (get off scot) free, when it's a foreign owner
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.