On mySimon: Chinese Laundry Top Over-the-Knee Boots
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Feb 1, 2006 1:35:00 AM

The firewall component in Microsoft's Windows OneCare security bundle has holes, experts have warned.

The security software, available in a public beta version, by default allows applications that use the Java Virtual Machine or have a digital signature to connect to the Internet.

Like any blanket security-bypass rule, these default settings are a bad idea, said Mark Curphey, vice president at vulnerability management specialist Foundstone, a part of McAfee.

"Any firewall, any security device should have a default deny," Curphey said in an interview Tuesday. "Any door should always be closed."

Curphey discovered the issue when running software on his wife's computer, on which he had installed OneCare. He informed Foundstone security consultant Roger Grimes, who subsequently blogged about it on the InfoWorld Web site. Grimes also blasted the default bypass settings.

"It just invites malicious hackers and other malware goons to exploit it," Grimes wrote.

OneCare team on Tuesday responded to the Foundstone experts in its own blog, and a Microsoft representative confirmed the blog's content. Yes, the OneCare firewall does allow any signed application and the Java Virtual Machine to pass through without alerting the user, but this should not be a security risk, according to the posting. The team invites readers to discuss the topic.

"It is highly unusual for malware to be signed," according to the Microsoft blog posting. Furthermore, if an application is signed, it can be traced to its author, it said.

Blocking Java would result in many applications being disabled, Microsoft, the posting added. And asking users to allow applications to pass through each time they are invoked would be too confusing. If a malicious program that uses the Java Virtual Machine does land on a user's PC, the antivirus component of OneCare should catch it, the OneCare team wrote.

According to Grimes's blog, however, that adware and spyware makers often sign their applications. Such a signature is meant to make their software look more reliable. "They already routinely use signed controls to install themselves onto users PCs, and certainly they will continue to use them to bypass this (OneCare) service," Grimes wrote.

Spyware expert Ben Edelman agreed. "Most malware is signed," he said. "Getting these signatures is remarkably easy. And the resulting user experience is far better: reassuring-looking dialog boxes that make users think software is safe."

A public test version of OneCare has been available since November. OneCare is meant for consumers and will combine anti-spyware software with antivirus software, firewall software and several tune-up tools for Windows PCs. The final package is expected sometime this year and will be offered as a subscription service.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 13 Talkback(s)
Doors in Windows Onecare
So why is this on ZDNet? I thought News was something defined as new or unknown information. This story just confirms the obvious - Another miKro$loth product with security holes. Jee, go figure, its default settings contradict the purpose of the bloatware being marketed.... (Read the rest)
Posted by: zclayton2 Posted on: 02/08/06 You are currently: a Guest | | Terms of Use
Microsoft's OneCare firewall draws fire  Loverock Davidson | 02/01/06
But the GUI is beautiful  nucrash | 02/01/06
So as a beta, it's draws reviews and suggestions  Boot_Agnostic | 02/01/06
Wipe sites off the map that are malware holes  Leria | 02/01/06
Web domain registration  Boot_Agnostic | 02/02/06
OneCareLive  bellacoup | 02/01/06
Re: OneCareLive  ecvogel76 | 02/01/06
Microsoft has no intention of making  bjbrock | 02/01/06
Who cares?  IT Scion | 02/01/06
I agree  Leria | 02/01/06
I AGREE?  coinsrgood | 02/02/06
I Disagree !!!  TSEG72351@... | 02/05/06
Doors in Windows Onecare  zclayton2 | 02/08/06

What do you think?

advertisement
Click Here
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here