Windows 7 may be secure, but are Windows users safe?
Noe of Tuesday's security patches affected the new OS
IDG News Service - Windows 7 users got a nice surprise on Tuesday when Microsoft released its first set of security patches since unveiling the new operating system last month. Of the 15 bugs patched, none affected Windows 7.
When Microsoft launched Windows 7, it was billed as the company's most secure release ever -- the culmination of a nine-year "Trustworthy Computing" effort to shore up a product line that had been riddled with major security holes.
But does stress-tested software really matter to Microsoft's customers, seemingly besieged by more online attacks than ever before? Microsoft had years to improve Windows XP, but the Conficker worm, which began spreading last year, is now thought to have infected more than 7 million Windows machines. And for every Windows bug that gets squashed, hackers seem to find new problems in the software that runs on top of Microsoft's operating system -- Flash Player, QuickTime and Java.
"Windows 7 is definitely by far the most secure system they've shipped," said Dave Aitel, chief technology officer with Immunity, a security company that spends a lot of time finding the latest software bugs. "I guess the question that everybody is asking right now is, 'Is this enough?'"
The man behind Microsoft's Trustworthy Computing initiative, Chief Research and Strategy Officer Craig Mundie, says the industry still has work to do. “We’ve made huge progress with respect to security around the core OS technology in the Windows PC," he said in a recent interview. "But as we did that and the 'Net became more prevalent, the bad guys continued to evolve their attacks."
This is Microsoft's conundrum. Windows may be safer, but cyber-criminals still have plenty of other places to attack. And when you can hit hundreds of millions of users with a single attack, why change the game plan? So most of the worst attacks today still target PCs running Windows, whether the OS itself is secure or not.
Take spear-phishing. Attackers are getting so good at sending these highly customized e-mail messages, complete with malicious attachments, that the underlying security of Windows is almost irrelevant.
"The problem with the targeted attacks is that there's so much money that they can actually trump the security," said Alan Paller, director of research for the SANS Institute, a security training company. "The amount of money that governments and large industrial crime groups have to spend is enough to trump any of the defenses we have."
In a report released last month for a congressional advisory panel, Northrop Grumman analysts detailed exactly how this happens. Looking at known attacks, the report found that targets are carefully selected, and then sent very believable e-mails with maliciously encoded attachments that exploit bugs in a product such as Adobe Reader -- something that's outside of Microsoft's control. The victim opens the .pdf and suddenly attackers have a foothold on the network.
Windows 7
- At CES, Microsoft sets stage for lower Windows revenue
- Windows 7 to crack 40% share by year's end
- Microsoft TV ads to target old PCs with anti-'good enough' angle
- Windows 7 share tops XP for first time in U.S.
- Windows 7 breaks 20% share barrier
- Microsoft to wind down Windows 7 Family Pack sales by year's end
- Microsoft delivers Windows 7 SP1 blocking tools
- Enterprises: We'll run Windows XP even after retirement
- Microsoft may face resistance to Windows 8
- Windows 7 Family Pack discount deal returns



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- VMware View Optimization Guide for Windows 7
- This document provides guidelines for configuring a standard Windows 7 image to be used within a VMware View™ environment, providing administrators with the...
- Watson - A System Designed for Answers. The future of workload optimized systems design
- Watson is a workload optimized system designed for complex analytics, made possible by integrating massively parallel POWER7 processors and DeepQA technology. Read the...
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring... All Operating Systems White Papers
- Optimizing Networks for the Cloud
- Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
- Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
- Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
- Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
- Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
- Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
- Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
- Virtualize Business-Critical Applications with Confidence
- Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®... All Operating Systems Webcasts
