Ballmer Touts New Security Initiatives

By David Worthington | Published October 9, 2003, 11:08 PM

At Microsoft's Worldwide Partner Conference in New Orleans on Thursday, CEO Steve Ballmer lauded the company's efforts to protect its customers and lock down Windows. Through its "Protect Your PC" campaign, Microsoft will begin improving patch distribution, institute global education programs and develop new safety technologies.

Ballmer announced that Microsoft was endeavoring to improve the patch experience throughout its product lines. As previously reported by BetaNews, Windows Installer (MSI) 3.0 and Software Update Services 2.0 will work in tandem to reduce complexity, lower the need for system reboots by 30 percent, introduce rollback capabilities, and include new processes for patch distribution and manageability.

The release schedule for patches will be modified to deliver predictable monthly releases, while Microsoft is also extending legacy support for Windows NT Workstation 4 Service Pack 6a and Windows 2000 Service Pack 2 through June 2004.

Consumer education seminars will be hosted courtesy of Microsoft TechNet, paired with monthly webcasts and in-depth training courses. According to Redmond, these sessions will reveal new prescriptive guidance in the form of patterns and practices, deeper information on how to configure for security, and the company will begin sharing details on how it secures its own networking infrastructure.

New safety technologies are slated to ship with Windows XP Service Pack 2, planned for mid-2004, and Service Pack 1 for Windows Server 2003 shortly thereafter. These safety technologies are designed to be resilient against any future threats, protecting customers from malicious attacks even if patches have not been installed or released.

According to Microsoft, "these security advancements for Windows XP will focus on protections against the four types of attacks that constitute the largest percentage of threats: port-based attacks, e-mail attacks, malicious Web content and buffer overruns."

While Microsoft's Mike Nash, Corporate Vice President of the Security Business Unit, waxed poetic on how partners will fix this gap with the right medicine to cure what ails Windows, Microsoft is developing its own comprehensive backup, firewall and antivirus solution for Windows XP - currently code-named, PC Satisfaction. PC Satisfaction's firewall and antivirus technology are licensed from Redmond partners.

Microsoft already has a base to build upon. Windows XP includes Internet Connection Firewall, which is now "turned on" by default on all new Windows distributions. The software giant has also moved to gobble up the intellectual property and assets of a small Romanian antivirus vendor.

Windows Server 2003 safety technologies will enable remote-access-connection client inspection and intranet client inspection to help guard corporate networks against infections introduced by mobile systems.

"Our goal is to enable increased protection and resiliency of systems and networks," Ballmer said. "Our highest priority is developing these safety technologies for our customers. This is a key area of focus for us."

Future steps to secure the perimeter of the Windows platform include the Next-Generation Secure Computing code base, otherwise known as "Palladium." This controversial initiative is timed for release with the next major Windows upgrade, dubbed Longhorn. All in all, Microsoft's efforts to batten down the hatches and stifle hackers will take time.

Later this month, Microsoft's Professional Developers Conference (PDC) will focus a dedicated symposium solely on secure coding practices.

When asked by BetaNews why the company is hosting numerous PDC sessions on Longhorn, Yukon and Whidbey features and so few on securing the new products, a Microsoft spokesperson said, "Content on security processes and practices pervade many of the PDC sessions, and there is a full day dedicated to security in addition to the break-out sessions."

But just last week, a groundswell of criticism encircled Redmond, alleging that Microsoft is not doing enough to secure its products.

The first salvo was a class action lawsuit filed by the State of California in late September that all but mirrored a report authored by a group of security experts earlier that month. Both parties alleged that Microsoft's near monopoly power coupled by its penchant to be targeted by hackers, and vulnerable to malicious code, creates a cascading effect whereby massive network failures could potentially occur as a result.

Later on in the week, a highly publicized leak of Valve's Half-Life 2 source code was pinned on unresolved security lapses in Microsoft's Internet Explorer Web browser. In both circumstances, Microsoft refused to comment specifically; the software giant placed the blame on cyber criminals committing illegal acts.

Referring to the latest California class action lawsuit filed against the company, a Microsoft spokesperson told BetaNews, "This complaint misses the point. The problems caused by viruses and other security attacks are the result of criminal acts by the people who write viruses."

"While working hard to improve the security of our software, Microsoft also works closely with federal and state law enforcement to help bring the perpetrators of these attacks to justice," the spokesperson said. Microsoft would not comment on the Half-Life leak.

Comments

View comments by with a score of at least

"referring to the latest California class action lawsuit
filed against the company, a Microsoft spokesperson told
BetaNews, 'This complaint misses the point. The problems caused by viruses and other security attacks are the result of criminal acts by the people who write viruses'."

In Kalifornia, class-action lawyers are like the fourth
branch of government !

Criminals ~aren't~ the offenders. Victims are.

In the People's Socialistist Republic of Kalifornia,
culpability is directly corresponant to ability to pay.

The DataRat

Score: 0

|

This sounds good. I hope MS continues to really work hard on upping their security.

Score: 0

|

If you don't lock your door, and you are robbed who's fault is it? (The criminals)

NOW

If you don't lock your door AFTER being robbed, and you are robbed again who's to blame? (Both of you)

NOW

If they sell a door with locks, but you choose to buy a door that doesn't lock but looks much prettier who's to blame when someone opens that door unannounced? (Both of you)

NOW

If they sell a door that claims to lock lock, 90% of the world's home owners installs that door, but the lock fails who is to blame? (The door builder, and the crook)

NOW

If they sell a door that claims to lock but doesn't lock, and the door manufacturer replaces the lock which still doesn't lock who is to blame? (The door builder)

Say an auto manufacturer sells a car with tires that explode..

'nuff said

Score: 0

|

MS isn't doing a bad job in my opinion. However, I DO think that they made too many operating systems, and instead they should make a PERFECT one just for the heck of some people. for me I don't care, if virus and attacks come on my comp, I just reformat the whole thing, at least windows is much faster than linux (seriously)...

Score: 0

|

"MS isn't doing a bad job in my opinion. However,
I DO think that they made too many operating systems,
and instead they should make a PERFECT one"

Well, actually, exactly ~that~ is the plan !

Hence Microsoft folded both Win9.x/ME and WinNT/2000
into WinXP.

Of course, there's ~always~ got to be SOME differentiation.
Therefore there's WinXP Home and WinXP Professional.

We don't want Microsoft to unify their OS into a
one-size-fits-all product !

As for the "perfect" OS part:

There will NEVER be a perfect OS. Ever.

You're not perfect, DataRat is not perfect, and neither
is Microsoft.

The very most we can expect from ~anybody~ is that they're
good. And, right now, Microsoft has the best OS available
for desktop computing.

The DataRat

Score: 0

|

"at least windows is much faster than linux (seriously)..."

Umm, can you qualify that statement for me? What do you define as "faster" and at what tasks?

Score: 0

|

Will Firefox beat IE9 to Direct2D rendering?

Just days after Microsoft executives gave conference attendees a peek at a new rendering technology, a Mozilla contributor revealed he's working on the same thing.

AOL's decision to rebrand as Aol. takes a bad brand and makes it worse

The idea behind the social Web is to crowd source before bringing out something new. But not at AOL, which new logo debuted with a cry of "fail!" across the blogosphere and Twittersphere today.

Microsoft's Bob Muglia and Ray Ozzie on Silverlight vs. standards

Bob Muglia: "We're trying to provide people with an environment that has capabilities that you just simply can't do today in the standards-based world."

Uh-oh, netbooks -- not Windows 7 -- will lift 2009 PC sales

Santa may bring a lump of coal to the Windows PC industry this holiday season. Netbook sales will sap PC margins, while weak Windows 7 PC sales could further drive down average selling prices.

Kindle 2 update adds battery life, native PDF reader

Amazon has pushed out an update to the Kindle 2 e-reader that lengthens battery life and adds a native PDF viewer.

Safari on iPhone gets competition from a $1 browser app

Apple likes to say it gives iPhone users a full browsing experience, but a new competitor tries to incorporate more desktop browser features.

Action Replay maker sues Microsoft for Xbox 360 'predatory technological barriers'

Third-party video game accessory maker Datel has filed an antitrust lawsuit against Microsoft over the Xbox 360's recent Dashboard update.

Where there's smoke: Apple warranty stance raises troubling questions

Carmi Levy | Wide Angle Zoom: Smoking can be dangerous not only for your lungs, it appears, but for your Apple hardware warranty.

Microsoft's .NET Micro Framework is now free and open source

The latest version of Microsoft's .NET Micro framework is now in the hands of the FOSS community.

Google's value proposition for Chrome OS: Should we feel insulted?

For a search engine that has direct access to all the world's online history, it appears to have taught Google nothing about selling a machine.

E-book readers will be in short supply this holiday season

E-readers are hot this year, and a lot of compelling new products have been released, but are there enough electrophoretic displays to go around?