On GameSpot: Wii Fit tells 10-year-old she's fat
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Mar 11, 2004 12:00:00 PM

COMMENTARY--In three months, Microsoft users will finally reap benefits from the company's new focus on security. The release of the second major update to Windows XP answers many long-standing design criticisms of its operating system.

But this was not a pain-free learning exercise. Indeed, Microsoft paid a steep price in the coin of user dissatisfaction--and in some cases, lasting mistrust.

In September 2001, the Nimda worm spread throughout networks worldwide, leading corporate customers--including many financial firms--to chastise Microsoft for failing to plug vulnerabilities in its code.

Two years later, the MSBlast worm and a variant of the program infected Windows computers and corporate networks, once again bringing consumer and corporate wrath on the Redmond, Wash.-based company.

Microsoft's service pack represents a solid step toward helping the overwhelming majority of customers who are not security-conscious enough to secure themselves.
But the attacks also compelled Microsoft to rethink how to provide improved security.

Nimda resulted in the Trustworthy Computing Initiative, a companywide program designed to prod Microsoft's development teams toward producing more secure code.

In the aftermath of MSBlast, Microsoft has refocused on security for its next update to the Windows XP operating system, Windows XP Service Pack 2. The changes feature an improved firewall, the ability to turn off pop-up ads and ActiveX controls in Internet Explorer and a control panel that will display the current state of a PC's security.

"One of the things that we really learned after August and Blaster is that...it is not enough to have the technology there; it has to be accessible as well," said Neil Charney, director of product management for Microsoft's Windows Client Group.

The aim is to bring ease-of-use concepts to security. The Windows Security Center will have a simple set of status displays, showing whether the PC is protected by a firewall and has the most recent patches. It will also make sure that the antivirus software is turned on and updated. Users also will be urged to turn on the basic security protections.

The company still hasn't put an indicator on the desktop for the most basic security function: backing up data.


Get Up to Speed on...
Enterprise security
Get the latest headlines and
company-specific news in our
expanded GUTS section.


Yet the service pack represents a solid step toward helping the overwhelming majority of customers who are not security-conscious enough to secure themselves.

Microsoft's focus on ease of security also offers an instructive example for the Linux world.

Historically, Linux has enjoyed an advantage in design and user education. Linux inherited its strength in design from Unix. In contrast, Microsoft has had to make sure that its products remained backward-compatible with its original Windows infrastructure, which treated security as an afterthought. Moreover, Windows users tend to be far less tech-savvy than those who use Linux.

However, from its Protect Your PC campaign to the coming service pack, Microsoft appears to have "got religion" about the subject. If Linux is to appeal to the general public, security must get easier.

Linux does have a wide variety of tools to secure a computer running the open-source operating system, but administering a system using the tools is relatively difficult. One tool, Nmap, checks for open data channels, known as ports, that could be vulnerable to an attacker; the tool, however, does not analyze which ports might be threats.

Another tool, Tripwire, creates a digital fingerprint of each important file on a computer and tracks changes to those files. While the software provides good security, it is so hard to configure and use that most users don't try to run the security check. (A company, also called Tripwire, makes a full-featured commercial version that is much easier to use.)

And a good backup utility that doesn't require magnetic tape is still hard to find.

As Linux slogs toward becoming a viable desktop alternative to Windows, proponents know that the battle may hinge on the ability of developers to integrate such security into major distributions. What's more, they must find ways to represent the results in an accessible way for average users. Speaking about the Linux user interface in general, Linux luminary Eric Raymond said as much in a blog that posted recently.

"None of this is rocket science," he wrote, referring to a problem he was having installing printer software using the application's user interface. "The problem isn't that the right things are technically difficult to do...The problem is that the (software) designers' attitude was wrong. They never stepped outside their assumptions."

Some projects are doing it right. A good example of a tool that has focused on ease-of-use is Nessus, which scans a network for signs of vulnerabilities and not only tells the user what it has found--but also explains why the issue poses a security problem.

Still, any Linux version that claims to be for the desktop might want to borrow a page from Microsoft's textbook and give users a central place to see the status of their data and computer system.

In the high-society circuit, they say you can never be too rich or too thin. So it goes that when developing operating systems, you can't ever make a product too accessible or too conscious about security.

biography
Robert Lemos is a senior staff writer at CNET News.com.

  • Talkback
  • Most Recent of 55 Talkback(s)
What Linux can learn from Windows
if you ever make it on top, don't srw your customers, always anouther distro waiting to take your place... (Read the rest)
Posted by: JWatson77 Posted on: 03/16/04 You are currently: Logged In as: a Guest  | Login | Terms of Use
What Linux can learn from Windows - marketing  FilledOut | 03/11/04
OEM courting...  ryusen | 03/11/04
preinstalls  richhayes | 03/11/04
Marketing  FilledOut | 03/12/04
Marketing  richhayes | 03/12/04
Make or Break  bit_rot | 03/12/04
Re: Make or Break  Mack DaNife | 03/12/04
I Agree  richhayes | 03/12/04
People have to want it  Bill Weisgerber | 03/15/04
Just wait for Longhorn  voska | 03/12/04
OEMs  Ardian Daka | 03/12/04
Nope..  d_jedi | 03/14/04
Is this XP only?  dnmott@... | 03/11/04
What Linux can learn from Windows  Loverock Davidson | 03/11/04
You sound like  Len Rooney | 03/11/04
re: You sound like  Iain_Peters | 03/12/04
re: You sound like  cbradshaw@... | 03/15/04
Here we go again  NemesisNL | 03/12/04
An MS shill doesn't need Linux experience.  John E Wahd | 03/12/04
ease  richhayes | 03/12/04
Unfortunately true  RedHat9User | 03/12/04
actually very easy  Grimm Reaper | 03/12/04
Easy  richhayes | 03/13/04
Installing Linux  d_jedi | 03/14/04
Put a rubber band around your head and snap out of it!  Grimm Reaper | 03/12/04
Yeah!  Update victim | 03/12/04
Let's just hope  middle of nowhere | 03/11/04
Lets look at what MS has on offer in the SP  Richard Flude | 03/12/04
re: What Linux...  Iain_Peters | 03/12/04
FYI: XP firewall is made by McAfee (NT)  Ardian Daka | 03/12/04
You have no clue...  omdguy | 03/12/04
You get a clue  Ardian Daka | 03/12/04
combining ease of use and power takes a unique talent  jimk_z | 03/12/04
Enjoy your nice looking windows while..  NemesisNL | 03/12/04
How Linux would prevent that kind of scenario?  jfrankcarr | 03/12/04
Try this, just for fun  voska | 03/12/04
who is this Linux??  jellyclock | 03/12/04
Linux is  voska | 03/12/04
Linux can learn a lot from Windows  Zuel | 03/12/04
Windows is the same  voska | 03/12/04
I think he means...  Patrick Jones | 03/12/04
User education  Ardian Daka | 03/12/04
I think people like that could use Linux  voska | 03/12/04
Very true (NT)  Ardian Daka | 03/12/04
maybe  richhayes | 03/12/04
That's my point  voska | 03/12/04
Its conditioning  nite_w0lf | 03/12/04
True  richhayes | 03/13/04
True  seosamh_z | 03/14/04
The author raises a good point  jfrankcarr | 03/12/04
Contradiction in terms  voska | 03/12/04
Not Necessarily  Mack DaNife | 03/15/04
backward-compatible  Update victim | 03/12/04
Message has been deleted.  spinit | 03/15/04
What Linux can learn from Windows  JWatson77 | 03/16/04

What do you think?

advertisement
advertisement

IP Networking

  • Anywhere, anytime productivity isn’t just for cyber-geeks and overachievers. It’s the state of business today, made possible through integrated wired and wireless networks, secure remote access, and advanced mobile applications and devices. Your users have what they need; do you?
  • From our sponsors
  • IT Solutions
  • AT&T IP Networking for your IT needs With AT&T IP Networking, you get flexible solutions designed specifically for your company’s IT needs Learn more
advertisement
Click Here