McAfee and Microsoft tangle over Vista security

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS

McAfee launched its first salvo in the increasingly bitter battle between Microsoft and the security industry on Monday, taking out a full-page advert in the Financial Times.

The advertisement, entitled "Microsoft increasing security risk with Vista", claimed that the company's aim was to see "a world in which one giant company not only controls the systems that drive most computers around the world but also the security that protects those computers... when it fails, it fails for 97 percent of the world's desktops".

In the advert, McAfee said that it had not been granted access to central portions of Vista, the next version of the Windows operating system, specifically to the kernel of the 64-bit version of Vista.

Mike Dalton, European president of McAfee, told ZDNet UK that this lack of access would "stop McAfee solutions working" on the 64-bit version of Vista, while leaving the door open for hackers to get past PatchGuard, the part of the operating system designed to prevent malicious attacks.

"If we can't see what's going on in the kernel, we can't see if there's an issue caused by malware," said Dalton. "The decision to build a wall around the kernel with the assumption it can't be breached is ridiculous. We know there are hacker documents out there on how to circumvent PatchGuard, and Microsoft has not had a good history of writing secure code."

In response, Microsoft claimed that PatchGuard, or Kernel Patch Protection, was "a critical step to making the kernel more secure".

"Kernel Patch Protection is not new to Vista; the technology has been shipping for more than three years and is currently available on XP 2003 and for Vista 64-bit shortly. McAfee's security solutions work on 64-bit systems. Customers can and will be protected by their solutions on 64-bit systems," a Microsoft spokesman said, adding that allowing third-party security vendors access to the kernel would cause "security, stability and integrity issues".

Dalton claimed Microsoft was trying to lock security vendors out of Vista so it could sell users its own security products such as OneCare.

"This is clearly an area where Microsoft is taking advantage of its position as vendor of 97 percent of the world's operating systems," said Dalton.

"Is Microsoft [locking vendors out] because the market will see other vendors are doing a better job at security? We may show them up as not having the greatest security product. I would say they're very worried [about that]," said Dalton. "You don't learn the technologies we've learnt overnight, and Microsoft's security attempts so far have been fraught with problems."

McAfee also claimed that Microsoft's refusal to allow its security console, Windows Security Center, to be turned off by vendors was a further attempt to sell more Microsoft products unfairly. "Windows Security Center is always on, always running in the background, saying 'Hey, come and look at Microsoft products'. I find it alarming," said Dalton.

Windows Security Center, introduced with Windows XP Service Pack 2, pops up on desktops to alert PC owners...

Talkback

Microsoft should not disclose any info to anybody about how to get into the kernel.
At the same time they sould stick to develop OS and leave everything else to others, but being the greedy corporation that they are, they want a finger in the pie which they helped to create with their sloppy code writing.
The security crowd should go about their business which is to find the holes in, and solutions for the OS and applications, after all that is what hackers do without going to Bill and ask him how to do it.
Security firms should not be too concerned about the OS steel wall around the kernel. As per MS's long track record, it won't be solid, but more like a sieve as they always have being doing.
MS and the security industry are both crying wolf.

via Facebook 4 October, 2006 13:23
Reply

"Microsoft has not had a good history of writing secure code." In the past, the only thing M$ was interested in was getting a new product on the shelves, ready or not. And 100% of the time it was shipped too early. Stability and security took a back seat to beating a deadline. VISTA is already late, so they have had plenty of time to make it stable and secure, but like Dalton, I have to assume it will not be secure given their previous record. By locking the kernel they are preventing third parties writing secure software. It will come back to bite them.

via Facebook 4 October, 2006 14:14
Reply

When others issue patches for M$ products before them it realy inspires confidence in M$.

Ok the others see their companies going down the tubes if wee Billy freezes them out. Would you be happy if your jacket was on an extremely loose nail ?

I have yet to be convinced that M$ are the knight in shining armour and with their security record so far will take a lot of convincing.

Conclusivly prove that security is completely buttoned down and is un-hackable then I might support M$ but until then I am looking for better security than what I have been receiving from them.

via Facebook 4 October, 2006 16:11
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

2 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

3 hours ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

4 hours ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

6 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

7 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

9 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

9 hours ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

9 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

10 hours ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

12 hours ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

18 hours ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

20 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

20 hours ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

21 hours ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

22 hours ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint
bdantas

Excellent article. One small correction, though--although a fresh installation of Linux Mint 12 will, indeed, provide the user with a version of...

23 hours ago by bdantas on A tale of two distros: Ubuntu and Linux Mint
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

23 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Alan Ralph

In related news, the ISPs club together to get the members of the Home Affairs Select Committee (ya goofed on that part, ZDNet UK) copies of "The...

23 hours ago by Alan Ralph via Facebook on MPs urge ISPs to take down terrorist material
Moley

For Gnome 2 die-hards, it is possible to add icons to the bottom panel (or top top panel, if you prefer) which provide the exact Gnome 2...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
ramwellian

Your comments would seem pretty naive and immature. Your 'solution' appears to be, "gee, let's all just give in to the hackers and give them...

1 day ago by ramwellian on Cloud computing security: no more oxymoron?