Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Latest News

      Symantec: Vista Code Has Holes

      Written by

      Matt Hines
      Published July 24, 2006
      Share
      Facebook
      Twitter
      Linkedin

        eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

        A new report from Symantec security researchers contends that Microsofts much-awaited Vista operating system could harbor a range of vulnerabilities that will make it less secure than previous iterations of Windows.

        According to research published July 18 by Symantec, in Cupertino, Calif., a number of Vistas software components, specifically a handful of protocols related to its redesigned networking technologies, could become security loopholes if Microsoft does not fix the problems or ensure that the product is configured appropriately to hide the glitches when it is shipped.

        The Redmond, Wash., software maker is slated to deliver a final version of Vista in January 2007.

        Symantec researchers reported finding three different types of potential flaws in Vistas underlying software code, including the presence of stability issues that could cause the operating system to crash when presented with attacks that use malformed files to deliver their payloads.

        Other issues include undocumented IP protocols with no known purpose in the product and problems with some new protocols deep within the operating systems so-called network stack.

        The security company based its assessment on tests run on three different publicly available beta iterations of Vista and conceded that Microsoft has eliminated large numbers of potential vulnerabilities with each successive beta release.

        However, despite Microsofts aggressive efforts to rid its next-generation operating system of bugs, specifically with the employment of its SDL (Security Development Lifecycle) process, which re–quires that all Vistas code be scoured for potential problems before being added into the product, the task of completely rewriting the sprawling code base without introducing any loopholes may be too much to expect from any vendor, said Oliver Friedrichs, director of emerging technologies at Symantec Security Response, also in Cupertino.

        Enterprises should be most concerned that Microsoft configure Vista so as to best protect customers from any potentially risky protocols, Friedrichs said. He suggested that if Microsoft fails to address the problematic code appropriately, Vista could end up less secure than Windows XP, which has demanded a long list of security patches.

        Microsoft officials didnt immediately return calls seeking comment on the Symantec report, but Ben Fathi, corporate vice president for Microsofts Security Technology Unit, said in a June interview that the company is doing as good a job as it can in building Vista while always looking for new ways to eliminate problems introduced during the software development process.

        “Theres no question that Microsoft is making progress, but research shows that any time you attempt to rewrite a core component like the network stack, you face a number of challenges from a security standpoint,” said Friedrichs.

        Up to code?

        Symantec claims Vistas code will have holes, while Microsoft believes SDL will keep issues down.

        Symantecs Critiques

        * Virgin code base will have vulnerabilities

        * Undocumented protocols must be eliminated

        * Network stack additions such as IPv6 could allow attacks

        * Aggressive hacker community will find holes

        Microsofts Strategy

        * SDL clearinghouse scours for developer errors

        * Beta versions will be reworked

        * On-board anti-malware tools will fight threats

        * New security products augment finished Vista

        Matt Hines
        Matt Hines

        Get the Free Newsletter!

        Subscribe to Daily Tech Insider for top news, trends & analysis

        Get the Free Newsletter!

        Subscribe to Daily Tech Insider for top news, trends & analysis

        MOST POPULAR ARTICLES

        Artificial Intelligence

        9 Best AI 3D Generators You Need...

        Sam Rinko - June 25, 2024 0
        AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
        Read more
        Cloud

        RingCentral Expands Its Collaboration Platform

        Zeus Kerravala - November 22, 2023 0
        RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
        Read more
        Artificial Intelligence

        8 Best AI Data Analytics Software &...

        Aminu Abdullahi - January 18, 2024 0
        Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
        Read more
        Latest News

        Zeus Kerravala on Networking: Multicloud, 5G, and...

        James Maguire - December 16, 2022 0
        I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
        Read more
        Video

        Datadog President Amit Agarwal on Trends in...

        James Maguire - November 11, 2022 0
        I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
        Read more
        Logo

        eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

        Facebook
        Linkedin
        RSS
        Twitter
        Youtube

        Advertisers

        Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

        Advertise with Us

        Menu

        • About eWeek
        • Subscribe to our Newsletter
        • Latest News

        Our Brands

        • Privacy Policy
        • Terms
        • About
        • Contact
        • Advertise
        • Sitemap
        • California – Do Not Sell My Information

        Property of TechnologyAdvice.
        © 2024 TechnologyAdvice. All Rights Reserved

        Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

        ×