Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Microsoft doctors AutoRun in Windows 7 to stymie Conficker

April 29, 2009 12:00 PM ET

The more advanced Security Research & Defense blog, however, noted an exception. "Some smart USB flash drives can pose as a CD/DVD drive instead of standard [drives]," the blog warned. "In this specific scenario, the operating system will treat the USB drive as if it is a CD/DVD because the type of the device is determined at the hardware level."

In other words, malware could still spread via such devices, which are identified as "U3 smart drives." For example, many of SanDisk Corp.'s drives are U3-capable.

Microsoft said it would backport the AutoRun/AutoPlay changes to Windows XP and Windows Vista, but the company did not give any indication when it would do so. "We will be bringing this change to Vista and XP in the future," was all Cohen said. When asked for something more specific, a company spokesman said, "We don't have any more details to share about the timing for this change to be implemented on Windows XP and Vista."

It shouldn't be a surprise that Microsoft is being coy about a timetable for XP and Vista, said John Pescatore, a Gartner Inc. analyst who covers security. "In the last three to four months before an OS shift, most of the development and security testing resources are in the new release," said Pescatore. "That sucks out the energy of what's going to be fixed in the older releases."

And Microsoft may want to gauge the change's effectiveness in Windows 7 -- and its reception by users -- before it backports the modification to XP or Vista. "They may want to make sure it's working," said Pescatore, "and do a true backport, rather than having to write totally separate code [for XP and Vista]."

He noted that Windows XP and Vista users can already disable AutoRun and AutoPlay manually by editing the registry, or in an enterprise, through group policies. To disable AutoRun, however, users must first apply a patch Microsoft issued earlier this year to fix a bug that kept the feature from really being switched off.

The AutoRun and AutoPlay changes will debut in the Windows 7 Release Candidate (RC), which will be available Thursday to MSDN and TechNet subscribers and on May 5 to the general public.

Read more about security in Computerworld's Security Knowledge Center.



Jump to comments

Microsoft

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs