Home > Security News > Microsoft has high hopes for Vista security
Security News:
EMAIL THIS
QUESTION & ANSWER

Microsoft has high hopes for Vista security

By SearchSecurity.com Staff
05 Feb 2007 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

Ben Fathi is the vice president of the Security Technology Unit at Microsoft and is responsible for the overall security of Microsoft's products as well as the development process known as the Secure Development Lifecycle. He took a few minutes recently to talk about the security features in Windows Vista and how Microsoft's security play will affect third-party vendors.

RSA Conference 2007

Can't make it to the show? SearchSecurity.com staff members are on the RSA floor, on hand to deliver the latest RSA Conference 2007 news and updates.
What are the early returns like from customers on the new security features in Vista?

Fathi: The feedback has been almost universally positive. We've had a huge number of beta customers, something over a million of them, running the earlier versions of Vista, so we've received a lot of security, performance and reliability feedback from them. There are a number of utilities in Vista that can send data back to us automatically whenever something hangs or crashes and we can collect and analyze that and look for spikes that indicate problems. Talking to customers, the security aspects of Vista get a lot of mentions. We've spent a lot of time improving the usability of the security controls like User Account Control to reduce the number of pop-ups customers get.

"Obviously zero vulnerabilities would be great...I'm hoping for a reduction of at least 50 percent over XP."
Ben Fathi,
vice president of the Security Technology Unit at Microsoft
If we have another conversation in six months, what kind of security performance would you like to see from Vista at that point?

Fathi: Obviously zero vulnerabilities would be great. I'd be dancing in the streets with that. But the number should be very small. I'm hoping for a reduction of at least 50 percent over XP. One thing that happens when a new OS comes out is that the research community shifts its attention to the new version. But because of the defense in depth approach that we've taken, it improves the end-user experience so that if there is a vulnerability, they're protected.

With big vendors such as Microsoft and Cisco building more security into their products, does that reduce the opportunity for independent security vendors over time?

Fathi: I hope and believe that there's plenty of opportunity for them to innovate and add protections both on top of and underneath the system. There are a lot of categories that we're not going to get into. But as we improve the security of the base product, some of the other vendors' products may not be as interesting as they once were.

<< Return to our special coverage of RSA Conference 2007



Tags: Windows Security: Alerts, Updates and Best PracticesSecurity Patch ManagementVendor Management: Negotiations, Budgeting, Mergers and AcquisitionsVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Windows Security: Alerts, Updates and Best Practices
Microsoft to address flaws in Windows, Office for Mac
Microsoft fixes security update that breaks Internet Explorer
What is the best database patch management process?
Microsoft addresses critical SMBv2 flaw, fixes record number of flaws
Microsoft to address SMB zero-day, IIS FTP Service vulnerabilities
Microsoft releases temporary fix for SMB2 zero-day vulnerability
Microsoft issues SMB vulnerability advisory, patch pending
Attackers target Microsoft IIS; new SMB flaw discovered
Microsoft repairs Windows media, TCP/IP vulnerabilities
Microsoft five critical updates won't include IIS

Security Patch Management
Squad: Tokenization, Phishing and the Feds
Should management processes change based on a patch release schedule?
Should Windows Mobile updates come from Microsoft?
Adobe updates ColdFusion, JRun, Flex
Trusteer CEO criticizes Adobe, touts better patch deployments
Patch management study shows IT taking significant risks
Vulnerability mitigation study shows need for faster patching
Microsoft to issue security report card, new tool at Black Hat
How to manage patches for Adobe
When is it suitable to remove Java updates?

Vendor Management: Negotiations, Budgeting, Mergers and Acquisitions
M86 buys Web security gateway vendor Finjan
McAfee survey finds faults in midmarket enterprise security
Cisco acquires SaaS security vendor ScanSafe
Email archiving vendor sues Gartner over Magic Quadrant
Analyst calls Barracuda-Purewire deal proof of cloud dominance
Barracuda acquires Purewire expanding Web security reach
McAfee, Verizon Business partner to develop cloud security services
Security vendors can learn from ConSentry Networks demise
Security on a budget: How to make the most of authentication tools
2009 Information Security magazine Readers' Choice Awards

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
BotHunter  (SearchSecurity.com)
principle of least privilege (POLP)  (SearchSecurity.com)
security identifier  (SearchSecurity.com)
trusted computing  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary




More Tips to Secure Your Network
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts