ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Microsoft: More security challenges lie ahead

Joris Evers CNET News.com

Published: 07 Feb 2007 16:21 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Although Microsoft has made huge progress in security over the years, even more challenges lie ahead as additional devices go online, company executives said on Tuesday.

Only last week, Microsoft released Windows Vista and Office 2007, promoted as the most secure versions of the operating system and productivity products yet. And it has been nearly five years since company chairman Bill Gates sent out his "Trustworthy Computing" memo, which said the software maker was turning its focus to security. But that doesn't mean Microsoft products are now watertight, said Craig Mundie, chief research and strategy officer at the company.

"This won't make [the products] perfect," Mundie said in a joint keynote speech with Gates at the RSA Conference in San Francisco. "The challenges we face in building our products, and the challenges everybody faces in administering and using them, is that humans are humans and they make mistakes."

As more devices connect to the internet and as people demand access to data from anywhere, the security job will only get bigger and more complex. "This challenge is going to get a lot tougher," Mundie said.

Not all the pieces are in place yet for people to be able to freely and securely tap into online data while on the move, he said. But solutions to the challenges are beginning to emerge, both on the side of internet infrastructure — in servers, routers and switches, for instance — and in individual devices.

"We will build this model of seamless, easy access across all these devices. But we're not really there yet. We're on the path to this future world," Mundie told the audience at the security conference.

Microsoft is pitching IP version 6, the next generation of the Internet Protocol, and IPSec, a suite of protocols for securing IP communications, as part of the solution. Windows Vista has IPv6 built in, as does the upcoming Windows Server Longhorn release, which also supports IPSec.

IPv6 is designed to support a broader range of IP addresses, as the IP version 4 addresses currently in use are becoming scarce. The new protocol will not only let more devices connect, it will also allow the use of fine-tuned security controls, since each device will have its own address, Mundie said. He said that features in Windows XP and Vista will help people move to IPv6.

"There really isn't a challenge, in our view, in moving to the IPv6 infrastructure," Mundie said. "You don't have to contemplate some gargantuan infrastructure change."

Securing the actual data is another important piece in the puzzle, Gates added. He pitched BitLocker, a disk drive encryption feature in the higher-end version of Vista, as a way to lock down the data on a PC.

In addition, for businesses, rights management systems can help control the flow of confidential data, he said. For example, companies can use such rights settings to limit who can forward or open certain email messages, reducing the risk of data loss, Gates said.

Then came a familiar message from Microsoft: eliminate the weakest link in the computer security chain by getting rid of passwords. Gates told the RSA crowd that he now has the right weapons to supplant the password as a means of verifying who is who on computers and over the internet.

"Passwords are not only weak; passwords have the huge problem that if you get more and more of them, the worse it is," Gates said.

In Vista, Microsoft introduced Windows CardSpace for consumers to use instead of passwords. CardSpace is an application designed to represent an individual's wallet, holding different cards to use for identification in online transactions.

"That is one of the things that is in the Vista system," Mundie said. "I think people are going to have to acclimatise to it."

For authentication in businesses, the software maker is promoting products such as its Identity Lifecycle Manager 2007, set for release in May. "We think this is the milestone where enterprises should start the migration from passwords to smart cards," Gates said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Graduate Systems Engineer

Community Connect 3 (CC3) is a client server network developed for Primary schools, Secondary schools and further education. Job Title: Graduate ...

Terminal Services Specialist at Top Financial Comapny!(Wins/HP/AD)

As the main contact in the London office, you will be responsible for any queries arising locally from video conference issues to networking. Top ...

Helpdesk Support - Public Sector - IMMMEDIATE

You will be call logging, troubleshooting, re-setting passwords, adding/deleting users & escalating calls to 2nd/3rd Line. A Public Sector ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment