On TV.com: JESSICA ALBA photos
BNET Business Network:
BNET
TechRepublic
ZDNet

By Ina Fried
Posted on ZDNet News: Sep 9, 2004 11:00:00 AM

SAN FRANCISCO--Windows makes it easy to quickly download files to iPods and other portable storage devices--a little too easy in the minds of many IT managers.

In the next version of Windows, Microsoft will give big companies an easy way to block use of such devices, while making it easier for consumers to connect their home systems to them, a company representative told CNET News.com.

News.context

What's new:
Longhorn, the next version of Windows, will let big companies block access to iPods and other tiny storage devices in the name of tighter security.

Bottom line:
The new feature should make it harder for employees to grab sensitive corporate data from business PCs or to introduce malware onto local area networks.

More stories on Longhorn

Much has been made of the security risks posed by portable storage devices known as USB keys, or flash drives, music players like the iPod, and other small gadgets that can store vast amounts of data. Some fear that such tiny devices can be used to quickly copy sensitive data off business PC hard drives, or to introduce malicious software onto corporate networks.

"It's a real problem," said Padmanand Warrier, a developer in Microsoft's Windows unit. "That's the feedback we've gotten from IT folks."

To put the new features in place, Microsoft is hoping to move to a common model for how wired and wireless devices connect to a PC in 2006, around the time that it releases the next version of Windows, code-named Longhorn. For consumers, that means that wireless printers, networked music players and other wireless devices should be able to connect to a PC as easily as the USB drives today.

Microsoft did include a workaround in Windows XP Service Pack 2 that lets users change an internal Windows setting to prevent data from being written to USB devices. But the features planned for Longhorn will be more comprehensive.

Microsoft showed its future technology, known as "Plug and Play Extensions," at this week's Intel Developer Forum.


special coverage
Intel Developer Forum 2004
Dual-core chips are a highlight
of the three-day gathering. For
all stories from the event, plus
video, click here.


For businesses, it means regaining some control over portable devices. "It's not just USB keys," Warrier said, noting that devices can just as easily link to PCs through Bluetooth short-range wireless or another connection.

By including tools to prevent workers from connecting portable storage devices to corporate PCs, Microsoft is offering big companies another option in addition to the outright banning of such devices, as some government agencies and other high-security installations have done.

"USB keys have become ubiquitous," said, Alan Brill, a senior managing director at Kroll OnTrack, a technology services firm that does security consulting. "You can pop them into any computer after Windows 95 and all the software that's needed is already in there. It's a tool that can be both used and abused very easily."

Companies have been slow to react to the threat posed by digital storage devices in general, Brill said.

"It's one that companies have turned a blind eye to for a very long time," Brill said. "If you think back, it used to be that stealing significant secrets was difficult because it was hard to get away with that much paper."

Intel, for example, used to check the bags of employees, but eventually such searches became impractical. With roughly, 80,000 employees, the company found it didn't have the resources to prevent against someone putting files onto a flash drive or iPod, a representative said.

"You take a better approach--you make sure people understand the need to protect company information and you hold them accountable," the representative said.

Market research firm Gartner has advised big companies to disable certain "plug and play" functions in Windows as a security precaution.

IT managers do have access to tools that would allow them to block USB ports, but such tools are little-known, and little-used. "There are tools that are available to...manage USB ports, but 99.9 percent of all machines in corporations don't have anything like that," Brill said.

Longhorn in the headlights
Of course, Microsoft's changes aren't coming until Longhorn, which isn't scheduled to arrive until 2006, and it is likely to take more time before the new operating system is widely adopted by companies.

"(USB keys are) a tool that can be both used and abused very easily."
--Alan Brill of consulting firm Kroll OnTrack
The moves do shed more light on Microsoft's intentions for Longhorn. Much of the attention recently has been on Microsoft's decision to pull a key feature out of Longhorn--a new file system known as WinFS.

In addition to the new device architecture, Microsoft on Wednesday said it also still plans to include in Longhorn a controversial new security architecture called the Next Generation Secure Computing Base.

The company's most detailed outline of Longhorn came at a developer conference last fall, when they spoke of three main pillars--WinFS, a Web services architecture known as Indigo, and a presentation subsystem dubbed Avalon.

Microsoft is making changes to all three pillars. WinFS will be available as a beta when the Longhorn release comes out as a client. Avalon and Indigo will be part of Longhorn, but also made available separately for Windows XP and Windows Server 2003.

Microsoft has also promised improvements in manageability and ease of use, though the company has not gone into great detail on how those new features will work.

In an interview last moth, Windows chief Jim Allchin identified a few Longhorn features, including version 2.0 of the .Net framework, a new user interface, more resilience to malware and "a new photo experience."

  • Talkback
  • Most Recent of 61 Talkback(s)
That would hurt backups
And if they made a backup exemption, it would be easy to spoff as a backup device. (Read the rest)
Posted by: GreatInca Posted on: 10/14/04 You are currently: Logged In as: a Guest  | Login | Terms of Use
Pretty much sums up Longdrawn: RESTRICTIONS RESTRICTIONS!  Xunil_Sierutuf | 09/09/04
What are you talking about?  Patrick Jones | 09/09/04
Newsflash  Michael Kelly | 09/09/04
Your employer's Computer. Their Rules. Simple  balsover | 09/09/04
Way to generalize...  hayesk | 09/09/04
Hey rocket scientist  balsover | 09/09/04
Here we go again: Microsoft taking away more rights from the end user  Jeff Spicoli | 09/09/04
Did you actually read the artice?  Patrick Jones | 09/09/04
Did you even read MY post?!  Jeff Spicoli | 09/09/04
I read your post..  Patrick Jones | 09/09/04
Boredom  Jeff Spicoli | 09/09/04
Good Enough  Patrick Jones | 09/09/04
I got an answer for you  Squawkbox | 09/09/04
but there's a difference...  ryusen | 09/10/04
It depends how MS implement this...  Zogg | 09/09/04
Exactly  Michael Kelly | 09/09/04
well that and...  ryusen | 09/10/04
MacOS X and Linux can do this now  hayesk | 09/09/04
So can Windows OSes  Squawkbox | 09/09/04
Get Real  The King's Servant | 09/09/04
Yes, you can  Confused by religion | 09/09/04
It that is true  voska | 09/09/04
Please, educate us  Linux User 147560 | 09/09/04
Short of refusing to install the driver...  Michael Kelly | 09/09/04
not practical  balsover | 09/09/04
Selective access to devices  Seething Ganglia | 09/09/04
Not effective in real life  Chad_z | 09/09/04
The question is...  Michael Kelly | 09/09/04
because he's a boss  Amberhawk | 09/09/04
Then what does that say about your CEO?  Michael Kelly | 09/09/04
That he's the same as every other CEO  Jeff Spicoli | 09/09/04
Not mine  Michael Kelly | 09/09/04
Job satisfaction  Anton Philidor | 09/09/04
Just goes to show you  htotten | 09/09/04
If I want to restrict access to devices...  Michael Kelly | 09/09/04
Driver auto-installation  Seething Ganglia | 09/09/04
Every user is effectively root?  d_jedi | 09/09/04
WinXP Pro at my office (not by choice!)  Linux User 147560 | 09/09/04
That says more about Windows programmers than about Windows itself  Michael Kelly | 09/09/04
restricing access is simple  jmetz@... | 10/12/04
Right on, it's called a security policy  Sunny Jalolly | 09/09/04
It was inevitable...  elkabong453 | 09/09/04
Whats the Big Deal  mrlinux | 09/09/04
USB ports on consumer audio devices  Seething Ganglia | 09/09/04
I already have USB ports on entertainment devices  Sunny Jalolly | 09/09/04
because they do not care about paying customers  V Sanders | 09/09/04
Gadgets aren't the problem  alterego_z | 09/09/04
Like any other security...  Gasman_z | 09/09/04
What is all the hubbub about Bub?  Squawkbox | 09/09/04
Didn't I already asked yo to get real once?  The King's Servant | 09/09/04
My my what a long memory you have  Squawkbox | 09/09/04
Who controls it?  Yagotta B. Kidding | 09/09/04
Which apps require administrator to RUN?  d_jedi | 09/09/04
depends on your budget...  ryusen | 09/10/04
Users don't need Admin access  voska | 09/09/04
Just say NO to a wireless world....  tattoo5150 | 09/09/04
Two words, Compact Disc  Harry Butts | 09/09/04
Compact Disc`s ...  dr_who@... | 09/10/04
Good thing most External HDs arn't included  GreatInca | 09/10/04
Security  Dumber_z | 09/17/04
That would hurt backups  GreatInca | 10/14/04

What do you think?

advertisement
advertisement