Microsoft backs down over Vista complaints

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

Security rivals' reaction to word that Microsoft will make changes in Windows Vista to allay competitive concerns: we'll believe it when we see it.

On Friday, Microsoft said it will give security software makers technology to access the kernel of 64-bit versions of Vista for security-monitoring purposes. Additionally, the company said it will make it possible for security companies to disable certain parts of the Windows Security Center in Vista when a third-party security console is installed.

Microsoft made both changes in response to antitrust concerns from the European Commission. Led by Symantec, the world's largest antivirus software maker, security companies had publicly criticised Microsoft over both Vista features and also talked to European competition officials about their gripes.

Security companies are taking note of the changes Microsoft said it would make to the operating system update, but will judge the outcome when they actually see them.

"We have not seen anything yet," said Cris Paden, a Symantec spokesman. "These are technical issues. Until we actually see the APIs, all we know is what they have said in the media. So far they have not done anything."

APIs, or application program interfaces, are the actual parts of Vista that on Friday Microsoft said it would make available, so security companies can access the Vista kernel and disable parts of Windows Security Center.

"If it is true, then it would be a step in the right direction for giving customers the choice to use whatever solutions they would like," Paden said.

The technology to suppress Windows Security Center alerts should be available next week, but APIs related to kernel protection still need to be developed and may not be ready before Microsoft ships Vista to PC makers and CD factories, said Adrien Robinson, a director in Microsoft's Security Technology Unit.

"We do not want vendors... accessing the kernel through unmodified approaches or modifying the kernel," Robinson said. "We will not allow them to go on the fly and modify the kernel, basically circumventing PatchGuard. We need to work with them on the right approaches to work with PatchGuard."

Points of contention
Kernel protection and Windows Security Center were two of the main points of contention between Microsoft and its security rivals. Symantec, McAfee and others had charged that Microsoft was hurting the competition and creating an unfair advantage for its own products through these features.

In 64-bit versions of Vista, the kernel protection, or PatchGuard, not only locked out hackers but also prevented some security software from running, security companies have said. They had asked for a way to access the kernel, which Microsoft insisted would hurt the security and stability of Windows. Microsoft now says it will provide that access, albeit in a controlled way.

"We have committed to create a new set of APIs that will enable third-party security products to access the Windows kernel in a secure manner," Microsoft said in a statement on Friday.

Windows Security Center, a key piece of Windows Vista real estate, tells people the status of security on their Vista PC, such as whether antivirus software or a firewall is installed and running. Security rivals have asked for a way to disable the Windows Security Center in favour of their own security dashboards.

Microsoft appears to be granting some, but not all, of that wish. "We are creating a new set of APIs to ensure that Windows Security Center will not send an alert to a computer user when an alternative competing security console is installed on the PC and is sending the same alert instead," Microsoft said in a statement.

Windows Security Center will continue to be running on the system so that a customer can have a cross-vendor, cross-technology view of the security on their Vista PC, Robinson said. In other words, third-party products won't be able to completely hide the Windows Security Center interface, which is what security companies had asked for.

Still sceptical
McAfee and Check Point Software Technologies, maker of ZoneAlarm security software, welcomed Microsoft's announcement, but, like Symantec, reserved judgment.

"We are encouraged by Microsoft's recognition that there is a problem. However, we do not have specific information on the nature of these changes, or their timing," said Siobhan MacDermott, a McAfee spokeswoman. "As more information becomes available, we will study it carefully before forming a view on whether Microsoft's plans provide a reasonable basis for addressing these issues."

Check Point's response also stressed that the clock is ticking on the release of Vista.

"We are encouraged to see Microsoft taking the security industry's concerns seriously," said Laura Yecies, general manager of Check Point's ZoneAlarm consumer division. "Once we have a chance to see what capabilities the new kernel-level APIs will extend to us, we'll have a better idea if they will be adequate. We hope to see those new APIs soon."

Timing is of the essence. Security providers, including Symantec and McAfee, want to have products available that work with Vista the moment it is released. Vista, the long-awaited successor to Windows XP, is slated to be available to large business users next month and the general public in January.

"If the APIs exist, then Microsoft should make them available to the security industry immediately," Symantec's Paden said. "We will have Vista-compatible solutions when the operating system is finally available for consumers. Last we heard, that was going to be January; therefore, we need these APIs yesterday."

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

8 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

16 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

18 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

18 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

20 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

22 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

23 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

24 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

24 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

1 day ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

1 day ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

1 day ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

1 day ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

1 day ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

2 days ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

2 days ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint