On BNET: 10 ways to manage your geeks
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Apr 27, 2006 5:35:00 PM

The firewall in Windows Vista will have half its protection turned off by default, because that is what enterprise customers have requested, Microsoft has said.

When Windows Vista is released early next year, it will have an updated firewall that looks at incoming as well as outgoing traffic, the company has said--an advance on the firewall in Windows XP service pack 2, which only watches incoming data.

But the default on the firewall in Vista will be set to block incoming traffic only, Microsoft said. The protection will be curbed in order to make life easier for the company's enterprise customers, it said.

A closer look
Piecing together Windows Vista
Aiming to recreate the excitement of Windows 95, Microsoft is trying to turn Vista into its next big win.

"Because the nature of an outbound firewall is to restrict the traffic sent to specific ports, the outgoing access in the Windows Vista firewall is open by default," a representative for the software maker told ZDNet Australia. "The reason for this is Microsoft has received strong feedback from its customers, especially from large organizations and government departments, saying that they would like to manage this feature from an administrator level."

Configuring the Vista firewall to stop outgoing connections made by rogue applications and malicious software will require a varying degree of technical knowledge, depending on each user's security requirements, Microsoft said.

"Users need to understand how their applications undertake communication and connections, and the associated threats and risks. This security requirement will vary amongst users, and Microsoft is providing the capability to allow users to determine how they wish to leverage this security capability," the Microsoft representative said.

Firewall specialist Zone Labs said that people will require a "fairly high level of sophistication" in order to properly configure the Vista firewall. For consumers, the company said the task will be nothing less than "challenging."

"Outbound protection requires a fairly high level of sophistication to engage, and reports indicate that Microsoft expects that functionality to be used by IT professionals in a business-networking environment," Laura Yecies, general manager at Zone Labs, said.

Security specialist Michael Warrilow, director of Sydney-based analyst firm Hydrasight, believes that Microsoft has found it too difficult to create an all-encompassing firewall. However, he said that by not putting the capabilities of the firewall into full play, the company is not ignoring its nontechnical customer base.

"In effect, Microsoft is putting outbound (protection) in the 'too hard' basket for the time being," Warrilow said. "The firewall is to protect against inbound attacks--instead of protecting the rest of the world from you."

Vista's firewall is just one layer of security in the new operating system, according to Microsoft. "New features such as User Account Control, Windows Defender, and Internet Explorer Protected Mode, along with improvements to Windows Firewall and Windows Update, work together to help shield Windows Vista PCs from malware," or malicious software, the company's representative said.

Munir Kotadia of ZDNet Australia reported from Sydney.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 20 Talkback(s)
Here you go
http://privacy.microsoft.com/en-us/default.aspx

read through all sections of this and if you can find where Microso... (Read the rest)
Posted by: xuniL_z Posted on: 04/29/06 You are currently: a Guest | | Terms of Use
They don't want MS protection? Or they've got something reliable instead?  HypnoToad72 | 04/27/06
Didn't you know...  ju1ce | 04/27/06
Only if your Firewall Admin is a lazy bum  nucrash | 04/27/06
Hey nu...  ju1ce | 04/27/06
Re: Only if your Firewall Admin is a lazy bum  none none | 04/27/06
Simplicity over Security ... again ...  ac2_z | 04/27/06
I agree..  ju1ce | 04/27/06
So turn it on yourself  georgeou | 04/27/06
Not so simple and not all about security  ibabadur1 | 04/27/06
thats like saying  not of this world | 04/27/06
It also makes it easier  bjbrock | 04/27/06
phone home?  xuniL_z | 04/27/06
Re: phone home?  none none | 04/27/06
Here you go  xuniL_z | 04/29/06
copy edit this story!  ChazzMatt | 04/27/06
What?  ThomasAnderson | 04/27/06
No, that's what he meant and it works both ways  georgeou | 04/27/06
Very sensible. Security can never get int he way of usability  mrjonno | 04/28/06
I agree...  jinko | 04/28/06
Shouldn't they leave it on for lazy non enterprise users  Boot_Agnostic | 04/28/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

Introducing SmartPlanet

  • Find thought-provoking progressive ideas on topics that intersect with technology, business and life. Visit Today
  • Technology, perspective, and insights shaping the world
  • Learn innovative and practical skills for your business and your life. SmartPlanet offers 360 degree coverage that you need to feel connected to the information that matters to the world at large. Go to SmartPlanet
advertisement
Click Here