On CBS.com: Paul McCartney on Late Show

IT Security

Host: Chad Perrin
Contact

Many businesses and home users have decided to skip MS Windows Vista and wait for Windows 7. Many were waiting for significant security improvements in Vista, but security professionals have found nothing more than minor, incremental improvements at best. Some fundamental changes need to be made to avoid the same mistakes with MS Windows 7.


There is a lot Microsoft can do to help make its Windows 7 operating system a commercial success. Jason Hiner offered his opinion on how it can do so in Sanity Check: Five things Microsoft has to do for Windows 7 to succeed, and I have my own opinions on the matter as well.

To go beyond immediate commercial success, and deliver on its promises of a genuine, effective focus on security, Microsoft must do more than just appeal to the masses. It must give its operating system design, development, and management policies a complete overhaul. Only time will tell whether MS Windows 7 will meet those requirements, or be found wanting. Five such changes are described here:

  1. Use standardized, peer reviewed tools and protocols for all security related functionality. Microsoft has one of the best known “not invented here” cultures in the software industry. While Microsoft does use a lot of code that wasn’t invented there, it never uses it unchanged and, when possible, buys out the creators before incorporating any of that outside software into what it sells. Even in the rare case that Microsoft uses something whose continued development it doesn’t really control, the company takes on code that cannot be taken back, continues development internally, and changes its functionality in some often startling ways that usually break interoperation with other branches of the same code base — as in the case of adopted code like the BSD Unix network stack and MIT Kerberos. This contributes to much of Microsoft’s security woes, as it then cannot really share advances with outside developers. It takes on a greater weight of code to maintain, and doesn’t add in the additional, free development efforts that could come with it. Because of this, the security characteristics of its remote login tools, encryption functionality, and network protocol implementations has been suspect at best, essentially from day one. Leveraging the tremendous breadth and depth of peer reviewed, best of breed, well tested tools that can be had — freely, in most cases — is key to producing an operating system people can trust.
  2. Implement true, comprehensive, architectural privilege separation. Microsoft’s operating systems have seen significant evolution over the years, from the early days of MS-DOS all the way to MS Windows Vista. Anyone can easily see that major changes have been wrought. One change that seems to happen over and over again is the addition of true privilege separation to the system architecture, protecting key parts of the system from unauthorized access by users who are supposed to be unprivileged. This “seems” to happen over and over again because it has not actually happened yet; some superficial changes are made that appear to address the problem of privilege separation, but by the time the next release of MS Windows hits the market the fact that privilege sepration was never really achieved in the interim has become common knowledge. For such a change to take place, Microsoft is going to have to let its attempts to maintain a stranglehold on how people use their computers slip a little bit, and stop looking for ways to allow Microsoft software to circumvent the security functionality of other Microsoft software.
  3. Start taking vulnerability patching seriously. Seven years is just too long for a severe vulnerability like the SMB flaw that was first discovered at least as long ago as March 2001. The fastest patch turnaround time for any Microsoft security fix was MS06-001, when Microsoft distributed a patch ahead of schedule only ten days after Microsoft officially learned of the vulnerability. The SQL Slammer worm, which brought much of the Internet to its knees in 2003, was patched by Microsoft long before it became a threat — but if the patches were applied out of the order in which Microsoft intended them to be applied, later patches would uninstall earlier patches, leaving your computer vulnerable (and Microsoft blamed the admins for not effectively patching their systems). Meanwhile, the standard for which Microsoft should be aiming is that of open source projects that routinely produce stable, effective security patches that don’t break things in under a week — sometimes in a matter of hours. Before MS Windows 7 security can really be taken seriously by most security professionals, this is a serious problem area that must be addressed. Microsoft recently released a patch for MS Windows 7 pre-beta before the pre-beta was released, which looks like a good sign, but it may also be a one-time aberration. Only time, and attention to Microsoft’s behavior in the near future, will tell.
  4. Don’t let backward compatibility trump default security. It’s understandable that Microsoft wants to support backward compatibility for its customer base, and I applaud the effort to ensure such compatibility in and of itself. That doesn’t mean that misfeatures that compromise security should be allowed to trump default security, however. If something that can compromise security absolutely must be included, it should be a configurable option, and not the default setting. It should also not, under any circumstances, require fundamental compromise of the system’s security on an architectural level. A related concern is that of the security of default settings in general — such as the unacceptably high number of unnecessary services running by default in a fresh install of MS Windows. I’d love to no longer have to write articles about things that should be turned off before you even think about connecting a network cable to your computer.
  5. Change the business model. Yes, really — this is, in fact, a security matter. Microsoft’s security model is in essence a financial manifestation of the old security through obscurity fallacy. Not only is that a broken model, but chasing after the mirage of that kind of secured revenue creates a conflict of interest between revenue stream “security” and actual system security, to the detriment of the company’s customer base. As the IT industry and software market continue to change in the next few years, the conflict of interest that represents will become even less defensible, because the “traditional” business model will become less and less viable. It’s time to make a change. Windows 7 may not be the place to jump headlong into a new business model, but Microsoft definitely needs to make some bold strides in that direction at least. Jason Hiner is on the right track with his admonishment that Microsoft should make MS Windows 7 it’s last shrink-wrapped OS. The alternative is to continue to damage Microsoft’s reputation amongst home computing consumers and business customers.

Of course, if the last decade has proven anything about software marketing and security, it is that good, secure software design, vulnerability management policy, and other security concerns for software vendors are often of little importance in determining market share. An image of acceptable security seems to be easier to manufacture than actual security is to achieve, and Microsoft has met with great success in manufacturing such an image.

There are those who look past the shiny marketing facade, however, and will not simply take Microsoft’s self-serving statements at face value. To satisfy their desire for security, Microsoft will have to do some things differently with Windows 7.

Chad PerrinChad Perrin is an IT consultant, developer, and freelance professional writer. He holds both Microsoft and CompTIA certifications and is a graduate of two IT industry trade schools. Read his full bio and profile.

Print/View all Posts Comments on this blog

5 things Microsoft should do to secure Windows 7 apotheon | 12/02/08
More around windows 11 will I upgrade SinisterSlay | 12/02/08
I'd like to see IE's tentacles pried out of the OS Palmetto | 12/07/08
Agreed.... jmgarvin | 12/07/08
Microsoft will change when users change. scarville@... | 12/09/08
There's another side to that. apotheon | 12/09/08
Users are changing. Tony Hopkinson | 12/09/08
RE: 5 things Microsoft should do to secure Windows 7 larry@... | 12/02/08
that was totally different Neon Samurai | 12/02/08
From what I've heard... Sterling "Chip" Camden | 12/04/08
That's basically why I decided to write this article. apotheon | 12/04/08
so it'll be completely out of character for MS then wink Neon Samurai | 12/04/08
link please apotheon | 12/02/08
The only point in putting UAC Tony Hopkinson | 12/02/08
A real virtual registry jmgarvin | 12/02/08
Vista and Office 2007 interflex@... | 12/03/08
It's already on the cards. V@... | 12/06/08
I'm hoping they will understand what they have jmgarvin | 12/06/08
I won't hold my breath either V@... | 12/06/08
Access? apotheon | 12/06/08
It's not crucial, yes I don't 'need' it. V@... | 12/07/08
Nuke or Access Tony Hopkinson | 12/07/08
RE: 5 things Microsoft should do to secure Windows 7 sar10538@... | 12/04/08
of course apotheon | 12/04/08
Which is why Tony Hopkinson | 12/04/08
I'm not so sure. apotheon | 12/04/08
True sar10538@... | 12/05/08
Side ways thinking from marketing Tony Hopkinson | 12/06/08
UAC is a joke sar10538@... | 12/05/08
It's worse than that -- he's dead, Jim. apotheon | 12/06/08
Well personally I read my UAC hits Tony Hopkinson | 12/06/08
UAC is a PITA in the enterprise though jmgarvin | 12/06/08
Well at work I'm only a user Tony Hopkinson | 12/07/08
So MS needs to make two truly different versions of 7 Palmetto | 12/07/08
Well I like the idea Tony Hopkinson | 12/08/08
What is with that for MS SQL!!?? jmgarvin | 12/08/08
The only explanation I can come up with for that Tony Hopkinson | 12/09/08
they did it again apotheon | 12/09/08
That one was probably before Tony Hopkinson | 12/09/08
RE: 5 things Microsoft should do to secure Windows 7 Techno Rat | 12/07/08
Admin access through an SU style facility Tony Hopkinson | 12/08/08
scarville@... | 12/09/08
Hi Tony Techno Rat | 12/10/08
RE: 5 things Microsoft should do to secure Windows 7 support@... | 12/09/08
Why? njic@... | 12/09/08
It's not Unix. apotheon | 12/09/08
Foundational architecture basically Tony Hopkinson | 12/10/08
the article you mentioned apotheon | 12/10/08
Whys Palmetto | 12/10/08
responses to responses apotheon | 12/10/08
Happy snipe santeewelding@... | 12/10/08
I'm with you 90% of the way. Palmetto | 12/11/08
Hmm, VMs . . . apotheon | 12/11/08
Why why? njic@... | 12/11/08
A Linux liveCD may actually be what your looking for Neon Samurai | 12/12/08
Online Updates jim@... | 12/18/08
Microsoft could protect Windows 7 with MetaFortress steve.goodison@... | 01/05/09

What do you think?

White Papers, Webcasts, and Downloads

Recent Entries

TR on Twitter

Archives

TechRepublic Blogs



IT Professional's Guide to Policies and Procedures, Third Ed
Whether you're creating policies for management, training, personnel, support, privacy, Internet/e-mail usage, security, or inventory, you'll meet the needs of your entire enterprise with this one download!
Buy Now
IT Help Desk Survival Guide, Third Edition
TechRepublic's IT Help Desk Survival Guide, Third Edition provides tools and recommendations to help you better manage help desk services, improve end-user support, troubleshoot frustrating hardware issues, identify quick fixes to vexing Windows problems, and help users make the most of Microsoft Office 2003.
Buy Now

Meet Doc

advertisement
Click Here