McAfee SecurityCenter Looks to Windows Update

By David Worthington | Published July 19, 2004, 8:30 AM

When Microsoft outlined the security initiatives found in the upcoming Windows XP Service Pack 2, some security vendors grumbled behind the scenes, but McAfee remained unfazed. In fact, the duo may now have settled into a cozier partnership than ever before.

Not only should the upcoming edition of McAfee's SecurityCenter console be compliant with Windows Security Center, it will actively monitor the status of Windows Update automatic updates.

Although Microsoft has farmed out other hosted services to third parties, it has maintained tight control over Windows Update - a core feature of the Windows operating system. Despite its best efforts to fine tune Windows Update to be its primary vehicle to effectively distribute updates to customers, Microsoft's quandary has been that it cannot ensure the compliance of end users.

Un-patched systems are left vulnerable to worms and other exploits that tarnish the reputation of Microsoft and place the security and privacy of Windows users at risk. The infamous Blaster Worm (W32.Blaster.A and its variants) exploited a flaw in Microsoft's Remote Procedure Call (RPC) function that was addressed by a security update released July of 2003.

By mid-August, hundreds of thousands of users who failed to upgrade were struck by Blaster, and Microsoft braced for the worst.

To fend off future incidents like Blaster, Microsoft designed Windows XP Service Pack 2 with an emphasis on security. Upon the initial reboot after installation has completed, users will be presented with a dialog encouraging them to enable automatic updating.

To add another layer of certainty that users will comply, Windows Security Center will continue to monitor the status of this feature and will notify users when updating has been disabled. However, users can still chose not to heed Microsoft's warnings, which is where vendors can assist Microsoft its campaign.

At first glance, users will also notice that McAfee's software sports a console interface similar in appearance to Windows Security Center. McAfee's intention with SecurityCenter is to provide users with quick access to security applications with one major change: SecurityCenter will now monitor the status of Windows Update and inform users when updates are available.

While there is no specific API to monitor the status of automatic updates, Microsoft has published a knowledge base article with a set of instructions on how to set the feature through the registry.

When asked for his perspective on McAfee's decision to make Windows Update a high value item in SecurityCenter, Matt Rosoff, an analyst with Directions on Microsoft, told BetaNews, "I only see positives in this announcement: it will help end-users keep up to date with the latest security patches, which can be a daunting task."

"This seems like a pretty simple function that other antivirus vendors could build in to their products as well," said Rosoff.

Comments

View comments by with a score of at least

First there were its ever-worsening products, then came its crappy handling of the products. I can't believe they are that dumb. I used to like McAffe, but now, they have a stuffed up UI and now this: WindowsUpdate, a site for Windows updates (which is excellent, by the way) is used by other companies.

McAffe should totally revamp its products and maybe I will once again buy their products.

And I don't need to mention Norton.

Score: 0

|

McAffe and Norton both are crappy. Personally i believe they both just rely on there name and the terror they try to inflict on normal pc users. A good AV program is F-secure or sophos. There are better yes but for the money they both do a better job than others.

Score: 0

|

Windows XP Service Pack 2 Security Center already monitors Windows Update. It's another misleading business tactic by McAfee. I also don't think McAfee or Norton have proven that they can be depended on to protect their customers.

Score: 0

|

McAfee monitors on top of that. The article also mentions that the service pack monitors as well. So a system with SecurityCenter will be monitored by both.

Score: 0

|

EC's Kroes to US senators: Mind your own business on Oracle + Sun

If the AP is accurate, the EU's antitrust chief just told the United States Senate that any merger that takes place in the world is more her affair than theirs.

What does AT&T's 'Mark the Spot' app say about service quality?

That's a question for Betanews readers to answer in comments to this post.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Google rolls out real-time search, Near Me Now, extended personalization

Over time, searches from PCs and mobile phones will grow even "more personalized." But what about user privacy and search results that give you "the truth"?

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.

Google Goggles: Hands on with the Shazam of the Real World

Google today unveiled Goggles, its visual search lab for Android devices that identifies objects by sight.

Microsoft: Windows 7 Family Pack wasn't 'pulled,' it just sold out

If you hurry, you may still be able to find the last Family Pack upgrade editions hanging around retail store shelves, but probably not so much online.

Clever iPhone game returns after being bumped over a name dispute

The game's simple concept and multitude of platforms and puzzles manage to pull off a retro, 8-bit style that's reminiscent of an old Atari game given a modern makeover.

Intel's marriage of CPU and GPU not ready for prime time

Although there will be an Intel component this month that can compute and plot in parallel, Betanews was told today, it won't be based on Project "Larrabee."

An alternative to Research in Motion's enterprise e-mail? There's an app for that

Good Technology today released an iPhone app compatible with its enterprise e-mail solution.