Feeds

Share the Vista vision, Microsoft tells security rivals

Build it like you mean it

High performance access to file storage

Microsoft has called on security software firms to provide more than just "basic" products for Windows Vista.

Partners must deliver more than "baseline" protection and support for Windows Vista's new security architecture to address future threats to computers, it says.

Its cry comes in response to a barrage of complaints from security software vendors, such as Symantec and McAfee, which slam Microsoft for taking "unnecessary security risks" and for potentially damaging the industry by releasing Windows Vista.

In an open letter published in the Financial Times, McAfee chief executive George Samenuk said Microsoft has "shut off" independent access to the Windows Vista kernel.

His comments follow claims from Symantec that Microsoft had withheld information about APIs for the Windows Defender anti-spyware product. Last week, Symantec representatives, with one eye to European Commission anti-trust officials, briefed the press in Brussels over its concerns. This was good timing on Symantec's part as it coincided with the commission's decision to widen its investigation into Vista's encryption and handwriting technology.

In August, Symantec highlighted problems with PatchGuard, software from Microsoft designed to thwart hackers by preventing the execution of unassigned kernel-level code, and so helping to stop denial of service attacks.

By blocking kernel extensions PatchGuard also denies security firms anything other than temporary access to the kernel. "These new technologies, along with Microsoft's unwillingness to make compromises in this area have serious implications for the security industry as a whole," Oliver Friedrichs, director of emerging technologies in the Symantec security response team, blogged.

Microsoft first floated the idea of a hardened kernel when Windows Vista was still a glint in Bill Gates's jeans. Unpopular then, security vendors were being forced to work through Palladium, the Digital Rights Management (DRM) technology subsequently renamed Next Generation Secure Computing Base (NGSCB).

Picking up the Windows Vista baton, Samenuk wrote in his FT letter: "Microsoft is embracing the flawed logic that computers will be more secure if it stops cooperating with the independent security firms. For the first time, Microsoft shut off security providers' access to the core of its operating system.

"At the same time, Microsoft has firmly embedded its own Windows Security Center - a product that cannot be disabled even when the user purchases an alternative security solution. This approach results in confusion for customers and prevents genuine freedom of choice."

Microsoft says it has supplied adequate documentation and support to partners, which should continue to work with PatchGuard. "The security threat landscape has evolved and Microsoft has to continue to evolve Windows to provide a safer, more secure computing experience," the company said.

"The solutions these partners provided yesterday need to evolve to address the threats of today, tomorrow, and go beyond the baseline protection that Microsoft needs to provide to its customers through technologies like Kernel Patch Protection [PatchGuard]." ®

High performance access to file storage

More from The Register

next story
Android engineer: We DIDN'T copy Apple OR follow Samsung's orders
Veep testifies for Samsung during Apple patent trial
Windows 8.1, which you probably haven't upgraded to yet, ALREADY OBSOLETE
Pre-Update versions of new Windows version will no longer support patches
OpenSSL Heartbleed: Bloody nose for open-source bleeding hearts
Bloke behind the cockup says not enough people are helping crucial crypto project
Half of Twitter's 'active users' are SILENT STALKERS
Nearly 50% have NEVER tweeted a word
Windows XP still has 27 per cent market share on its deathbed
Windows 7 making some gains on XP Death Day
Internet-of-stuff startup dumps NoSQL for ... SQL?
NoSQL taste great at first but lacks proper nutrients, says startup cloud whiz
Microsoft lobs pre-release Windows Phone 8.1 at devs who dare
App makers can load it before anyone else, but if they do they're stuck with it
US taxman blows Win XP deadline, must now spend millions on custom support
Gov't IT likened to 'a Model T with a lot of things on top of it'
prev story

Whitepapers

Mainstay ROI - Does application security pay?
In this whitepaper learn how you and your enterprise might benefit from better software security.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.