Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Microsoft Wakes Up to Security

    Written by

    Scot Petersen
    Published April 16, 2001
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      It took the globally debilitating “ILoveYou” virus and its link to vulnerabilities in the Outlook messaging software, but Microsoft Corp. says it has finally seen the error of its ways.

      As a direct result of the infamous virus that struck one year ago and wiped out Outlook users graphics and audio files, as well as bogging down e-mail servers, the Redmond, Wash., software giant has been quietly implementing a far-reaching strategy to build security into every piece of software it develops. To be sure, the shift is a dramatic one for Microsoft, which for years has focused its development efforts on ease of use.

      In addition to pumping out more secure software that requires far fewer security patches, company executives hope the moves, which include sweeping internal and external initiatives, will help Microsoft to shed its reputation for being aloof about security.

      “Weve made a clean break with our past policy on security,” said Scott Culp, security program manager at Microsoft, here last week at the RSA Security Conference. “We recognize now that every piece of software has vulnerabilities and bugs, and we have to deal with it.”

      The security edict came straight from the top of the company following last years Love Bug attacks, according to Microsoft officials. The initiatives, which were revealed here at the show, mark a 180-degree turnaround.

      One of the first manifestations that will make it into customers hands will be a feature in the Windows XP client and Whistler server called Software Restriction Policies. This “managed code” feature will enable administrators to set policies and choose which kinds of code are permitted to run and where and how programs can run on a users machine. For instance, all Visual Basic script files could be rendered useless, except for those that contain a digital signature embedded in the script code.

      Users are cautiously optimistic that such a method will end the trend of hackers targeting Windows with worm viruses such as the Love Bug.

      “That could really be a great feature, but the proof will be when the product is released and the rest of the world has been banging on it for a while,” said David Thompson, senior manager of the security practice at PricewaterhouseCoopers, of Boston. “This is about the third time theyve made this kind of pronouncement about security, but Im glad to see one of the major [operating system] vendors doing it. I dont see Sun [Microsystems Inc.] doing it.”

      Microsoft also has improved its process for responding to vulnerabilities and security incidents, officials said. As part of that process, Microsoft has developed a severity rating system for its patches so that customers will be able to decide whether they need to install the patch immediately or if they can wait for their next scheduled server maintenance. Officials said the company will enable “Hotfix” patches whenever possible that can be installed without requiring a reboot.

      While acknowledging that Microsoft seems to be making a concerted effort to bolster the security of its products, many customers say there is still a lot of work to be done.

      “They need to get serious about security,” said Howard Jones, CIO at Snapper Inc., in McDonough, Ga. “I personally think they still have to increase the security in all of their operating systems.”

      That is the stated goal of another Microsoft program, called the Secure Windows Initiative, which involves continuous educational programs for developers and a stepped-up internal and external testing process for new code. To that end, Microsoft, which is famously tightfisted about showing the Windows source code to anyone outside the company, has begun giving the code to groups of universities as well as outside security experts and urging them to search for vulnerabilities.

      Another significant chunk of Microsofts renewed security effort is its Security Services Partner Program, which has now grown to 50 companies with the addition last week of Computer Sciences Corp., of El Segundo, Calif.; Guardent Inc., of Waltham, Mass.; and Foundstone Inc., of Irvine, Calif.

      In addition, Foundstone and Guardent announced new managed security services built for Microsoft environments. Foundstones FoundScan Managed Security Services for Windows is a subscription service that offers vulnerability assessment and intrusion detection for about $7,000 per month. Guardents managed security service for Microsofts Internet Security & Acceleration Server will start in June for about $2,000 per month, depending on the level of service.

      The question that remains for IT managers is this: Will Microsofts new plans work?

      Some developers think Microsoft may even be going too far, pointing to a new security feature in Outlook 2002, due as part of the Office XP package next month, that will ban all e-mail attachments by default. Officials said the protection can be switched off.

      “Not everyone knows how to use all of the features of the software. Its going to make life challenging for a lot of people,” said Skip Winitsky, chief operating officer of Learning Worlds Inc., of New York.

      Scot Petersen
      Scot Petersen
      Scot Petersen is a technology analyst at Ziff Brothers Investments, a private investment firm. Prior to joining Ziff Brothers, Scot was the editorial director, Business Applications & Architecture, at TechTarget. Before that, he was the director, Editorial Operations, at Ziff Davis Enterprise, While at Ziff Davis Media, he was a writer and editor at eWEEK.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.