Home > Security News > Microsoft has high hopes for Vista security
Security News:
EMAIL THIS
QUESTION & ANSWER

Microsoft has high hopes for Vista security

By SearchSecurity.com Staff
05 Feb 2007 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Ben Fathi is the vice president of the Security Technology Unit at Microsoft and is responsible for the overall security of Microsoft's products as well as the development process known as the Secure Development Lifecycle. He took a few minutes recently to talk about the security features in Windows Vista and how Microsoft's security play will affect third-party vendors.

RSA Conference 2007

Can't make it to the show? SearchSecurity.com staff members are on the RSA floor, on hand to deliver the latest RSA Conference 2007 news and updates.
What are the early returns like from customers on the new security features in Vista?

Fathi: The feedback has been almost universally positive. We've had a huge number of beta customers, something over a million of them, running the earlier versions of Vista, so we've received a lot of security, performance and reliability feedback from them. There are a number of utilities in Vista that can send data back to us automatically whenever something hangs or crashes and we can collect and analyze that and look for spikes that indicate problems. Talking to customers, the security aspects of Vista get a lot of mentions. We've spent a lot of time improving the usability of the security controls like User Account Control to reduce the number of pop-ups customers get.

"Obviously zero vulnerabilities would be great...I'm hoping for a reduction of at least 50 percent over XP."
Ben Fathi,
vice president of the Security Technology Unit at Microsoft
If we have another conversation in six months, what kind of security performance would you like to see from Vista at that point?

Fathi: Obviously zero vulnerabilities would be great. I'd be dancing in the streets with that. But the number should be very small. I'm hoping for a reduction of at least 50 percent over XP. One thing that happens when a new OS comes out is that the research community shifts its attention to the new version. But because of the defense in depth approach that we've taken, it improves the end-user experience so that if there is a vulnerability, they're protected.

With big vendors such as Microsoft and Cisco building more security into their products, does that reduce the opportunity for independent security vendors over time?

Fathi: I hope and believe that there's plenty of opportunity for them to innovate and add protections both on top of and underneath the system. There are a lot of categories that we're not going to get into. But as we improve the security of the base product, some of the other vendors' products may not be as interesting as they once were.

<< Return to our special coverage of RSA Conference 2007



Tags: Windows Security: Alerts, Updates and Best PracticesSecurity Patch ManagementVendor Management: Negotiations, Budgeting, Mergers and AcquisitionsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Windows Security: Alerts, Updates and Best Practices
New attack code targets Microsoft ActiveX zero-day vulnerability
When BIOS updates become malware attacks
Microsoft patches WebDAV security vulnerability in bevy of updates
Microsoft plans 10 security updates, fixing IE, Word, Excel vulnerabilities
Hackers targeting unpatched Microsoft DirectShow flaw
Microsoft warns of IIS zero-day vulnerability
Microsoft updates Office to address serious PowerPoint vulnerabilities
Microsoft to patch critical PowerPoint zero-day flaw
How to perform Microsoft Baseline Security Analyzer (MBSA) scans
Microsoft patches serious Excel zero-day, Windows flaws

Security Patch Management
Adobe fixes critical Shockwave Flash Player flaw
Mozilla patches 11 Firefox security flaws, JavaScript errors
Microsoft patches WebDAV security vulnerability in bevy of updates
Adobe issues first quarterly patch release fixing 13 flaws
Microsoft plans 10 security updates, fixing IE, Word, Excel vulnerabilities
Adobe shifts to Microsoft patching process, incident response plan
Software delivery could fix software patching issues
Microsoft updates Office to address serious PowerPoint vulnerabilities
Microsoft to patch critical PowerPoint zero-day flaw
Firefox update addresses several security flaws

Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
Sophos CEO on Symantec, McAfee after Utimaco acquisition
EMC adds configuration management with Configuresoft acquisition
Know when you need IDS, IPS or both
Symantec acquires Mi5 Networks, bolsters Web security
RSA Conference 2009 shines spotlight on security vendor innovation
Oracle to buy Sun Microsystems for $7.4 billion
Entrust to be acquired by investment firm
Enrique Salem takes charge at Symantec
Countdown: Top 5 most important questions to ask endpoint security vendors
Flaw disclosure debate polarizes SOURCE Boston panel

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
BotHunter  (SearchSecurity.com)
principle of least privilege (POLP)  (SearchSecurity.com)
security identifier  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




More Tips to Secure Your Network
Focused on Channel Security?
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts