Tim Anderson

Vista flaws are greatly exaggerated

Despite some unfavourable reports, Windows Vista may turn out to be more secure than XP with SP2

Written by Tim Anderson

In an analysis of a network of Trojan-infested PCs used for sending spam, security researcher Joe Stewart at SecureWorks in Atlanta found last month that 99.95 percent of the "bot-net" machines were running Windows, nearly half of which were Windows XP with Service Pack 2. This service pack was released in 2004 to address security issues but appears to have failed. All eyes are now on Windows Vista, which introduces another round of security-focused features. Will it prove more effective than XP with SP2?

Antivirus vendor Sophos appeared to answer that with a press release declaring that "Sophos experts note that on the launch date of Microsoft's Windows Vista operating system, three of the top 10 [malware threats] are capable of bypassing the operating system's security defences and infecting users' PCs."

Depressing stuff, but I was intrigued. How were these viruses bypassing Vista's UAC (User Account Control), which means that users run by default with limited permissions rather than as local administrators? I asked Vanja Svajcer, the Sophos researcher who carried out the tests, how the machines had been infected. "That wasn't actually part of the test," he told me.

The focus was on how the malware behaved after it had been run on the user's PC. What Svajcer discovered was that there are common viruses which once installed will perform and replicate without requiring administrative privileges. It's a fair point, though I'm not sure that it counts as "bypassing the operating system's security defences".

I was surprised to discover that Svajcer is impressed by Vista's security measures. I asked him whether Vista is as secure as Mac OS X or Linux. "It's certainly as good," he said. "It's not that Windows is less secure, but being the most widespread operating system makes it such a target for malware."

SecureWorks researcher Joe Stewart is also upbeat about Vista. "Vista brings a new level of defence to the game," he wrote in his blog. "It is going to limit spammers mostly to social-engineering attacks ('double-click this executable attachment, please')."

If that is what the experts say, then Vista may really be more secure than its predecessors, though malware writers will adapt.

The other disturbing factor is that the centrepiece of Vista's security, UAC, can easily be disabled. Turning it off removes annoying dialogs and improves application compatibility. That said, most of those dialogs will disappear once application developers learn to write software that performs correctly when run by standard users.

Give Vista a chance and do not disable UAC.

Tags:

reader comments

related articles

Picture of Vista logo

Vista vulnerable to malware

Sophos finds three of top 10 malware threats can bypass Vista security 01 Dec 2006

 

Microsoft releases Vista patches

Beta operating system to get regular updates 18 Aug 2006

Microsoft plans Vista's replacement

Better use of multicore processors for the post-Vista operating system 29 Jun 2006

Vista security finds defenders

There are divided views on Microsoft's Vista disclosure 23 Oct 2006

Microsoft launches Windows Vista public beta

Latest version of Windows available to download 08 Jun 2006

Teenager admits to million-PC botnet scam

18 year-old unlikely to get jail senence 01 Apr 2008

Spammers warn of local nuclear meltdowns

New malware scam claims incidents in UK, Australia and Canada 12 Sep 2008

Kiwi hacker walks free from court

Small fine owing, police job pending 16 Jul 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation