ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Emerging tech Toolkit

CeBIT

Microsoft partner: Vista less secure than XP

Tom Espiner ZDNet.co.uk

Published: 16 Mar 2007 16:09 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security company Kaspersky claims that Vista's User Account Control (UAC), the system of user privileges that can be used to restrict users' administrative rights, will be so annoying that users will disable it.

Natalya Kaspersky, the company's chief executive, said that without UAC, Vista will be less secure than Windows XP SP2. "Windows Vista with UAC disabled will be less secure than XP SP2," said Kaspersky, speaking to ZDNet UK at the CeBIT 2007 show in Hanover. "There's a question mark if Vista security has improved, or has really dropped down."

Kaspersky provides one of the scanning engines in ForeFront, Microsoft's business security product.

Arno Edelmann, business security product manager for Microsoft, said that Kaspersky's claims were surprising. "We have a thriving community of partners, and Kasperky is one of our best partners," Edelmann told ZDNet UK. "I find their statements a little strange because they have one of the best insights into Microsoft security products."

After being roundly criticised over its security strategy in the past, Microsoft has done a lot of work to improve its approach and has been touting Vista as its most secure operating system. But Kaspersky confirmed that her analysts had found five ways to bypass Vista's UAC, and that malware writers will find more security holes.

Kaspersky also added her voice to Symantec and McAfee complaints that PatchGuard, designed to protect the Vista kernel, is hindering security companies' work.

"PatchGuard doesn't allow legitimate security vendors to do what we used to do," said Kaspersky.

Symantec has claimed that PatchGuard is hurting security vendors more than it was hurting malware writers. Bruce McCorkendale, a chief engineer at Symantec, said: "There are types of security policies and next-generation security products that can only work through some of the mechanisms that PatchGuard prohibits."

Eugene Kaspersky, the company founder, said on Thursday that while vendors had to interact with Vista legitimately, hackers were under no such constraints.

"Cybercriminals seem not to care about Vista licensing," said Eugene Kaspersky. "They don't need to follow regulations or be certified by Microsoft — antivirus vendors do."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
16 out of 18 people found this useful


Full Talkback thread

1 comment

  1. User access refusal cabala

More in this Special Report

CeBIT Blog

The need for video content

Thanks to one of ZDNet UK's readers, filthylooker, for his/her reply to my last blog post. For those who missed it, I expressed surprise at the response by BlackBerry manufacturer... More

1 comment

Nervous RIM

My interview yesterday with the European head of RIM sent the BlackBerry maker into a nervous spin. Armed with my video producer, we arrived smack on time at RIM HQ here at CeBIT... More

1 comment

Front-line tech reporting

So, I'm talking to a helpful and informative German gentleman from navigation specialists Telmap about the company's BlackBerry-based solution, and he's giving me the low-down on the... More

Post a comment

Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Architecture Manager (Technical Architect) North West

Assist in determining exactly when the required capacity should be available - Manage the work schedule of the team to deliver the conflicting ...

Director Level 100k +

This opportunity to lead the largest Pharmacovigilance Division within the company involves: Manage staff in accordance with organisations policies ...

Contract Specialist - Newcastle-00051050

Will be required to work in a client facing environment, with senior management levels Responsible for educating the project team on contract terms ...

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments

Featured Talkback

While full medical records may be of (dubious) value at rear/base medical facilities, these could be provided much simpler by either physical disk or electronic transfer to an "in theatre" database for individuals posted in. That £80m (and it's associated running costs) could have been far better employed in resuscitating a disbanded infantry battalion or providing a big boost in equipment quality and quantity.

By: 1000215420

Read full story:
Photos: MoD unveils £80m IT health programme