On GameSpot: Take on our editors every Tuesday night!
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: Jan 30, 2007 12:00:00 PM

Experts: Don't buy Vista for the security Windows Vista is a leap forward in terms of security, but few people who know the operating system say the advances are enough to justify an upgrade.

Microsoft officially launched Vista for consumers Tuesday. The software giant promotes the new operating system as the most secure version of Windows yet. It's a drum Microsoft has been beating for some time.

"Safety and security is the overriding feature that most people will want to have Windows Vista for," Jim Allchin, Microsoft's outgoing Windows chief, told CNET News.com a year ago. "Even if they are not into home entertainment or in any of the specialty areas, they are just going to feel safer and more secure by using it."

Now that Vista is finally here, pundits praise the security work Microsoft has done. However, most say that is no reason to dump a functioning PC running Windows XP with Service Pack 2 and shell out $200 to upgrade to Vista.

"As long as XP users keep their updates current, there's generally no compelling reason to buy into the hype and purchase Vista right away," said David Milman, chief executive of Rescuecom, a computer repair and support company. "We suggest people wait until buying a new machine to get Vista, for economic and practical reasons."

As in the past, Microsoft faces itself as its toughest competitor. SP2 for Windows XP, which was released in August 2004, marked a significant and much-needed boost in PC security. Since then, Microsoft has released Internet Explorer 7 and the Windows Defender antispyware tool for XP. As a result, the older Windows version is simply good enough for many users.

"Upgrading to Vista is pretty expensive, not only the new software but often new hardware as well," said Gartner analyst John Pescatore. "If you put IE 7 on a Windows XP SP2 PC, along with the usual third-party firewall, antiviral and antispyware tools, you can have a perfectly secure PC if you keep up with the patches."

News.com Poll

Vista: Now or never
How soon do you plan to move to Microsoft's latest OS?

I'm standing in line right now to buy it.
Whenever I buy my next PC.
Windows XP is going to last me a good, long time.
I'm sticking with the Mac--or moving there soon.



View results

Vista is the first client version of Windows built with security in mind, according to Microsoft. That means it should have fewer coding errors that might be exploited in attacks. Vista also includes several techniques and features designed to make it harder to attack computers running Vista and easier to thwart attacks if they do happen.

"Vista is light-years ahead of XP from a built-in security perspective," said Pete Lindstrom, a Burton Group analyst. "But the market will decide whether it is important. Note that there haven't really been significant problems with the operating system lately, and our memories are short."

If most consumers think like Brian Lambert, a student at Southern Illinois University, it doesn't bode well for Microsoft. "The added security alone is not worth the money when comparing Vista with Windows XP SP2," said Lambert, a member of CNET News.com's Vista Views panel.

But Chris Swenson, an NPD Group analyst, thinks that many consumers will prefer Vista's built-in security features over adding defenses to their XP machine.

"A lot of customers will prefer to either buy a new machine with Vista or upgrade a recently acquired XP machine with Vista in order to get at this added layer of protection," Swenson said.

If you are in the market for a new Windows PC because your old computer is outdated or otherwise failing on you, Vista is your best bet, all experts agree. That's even if you're considering buying a Mac, said David Litchfield, a noted security bug hunter.

"If you're looking to buy a new computer, the security features built into Vista tip the balance in its favor over other options such as Mac OS X," Litchfield said. "We've moved beyond the days of lots of bugs and worms. Recent history shows that Microsoft can get it right, as they did with XP SP2. With Vista, they will again demonstrate that."

Litchfield and other security researchers are impressed with the work Microsoft has done on Vista, in particular because the operating system has gone through the company's Security Development Lifecycle, a process designed to prevent flaws and vet code before it ships. Also, Microsoft challenged hackers to break Vista before its release.

Key Vista security features

User Account Control: Runs a Vista PC with fewer user privileges, which dictate how software can interact with the PC. UAC asks for permission to lift security barriers whenever software requires it.

Protected Mode for IE 7: Prevents silent installation of malicious software by Web sites by stopping the Web browser from writing data anywhere except in a temporary folder without first seeking permission. IE 7 is also available for Windows XP, but the protected mode is not.

Address Space Layout Randomization: Loads key system files in different memory locations each time the PC starts, making it harder for malicious code to run.

Windows Defender: Detects and removes spyware. Also available for Windows XP.

Windows Firewall: Blocks attacks from the Net and includes limited outbound protection. Also in XP, but improved in Vista.

BitLocker: Encryption for hard drives. Only in Vista Enterprise and Vista Ultimate.

"To be clear, XP SP2 was a massive leap for Windows security. But XP SP2 was not the systemic, top-to-bottom, scrub-everything experience that Vista is," said Dan Kaminsky, an independent security researcher. "XP SP2 secured the surface. Vista security goes much deeper. It's a far bigger leap."

Kaminsky was among about two dozen hackers asked by Microsoft to try to hack Vista. The exercise took about eight months, and Microsoft paid attention to the feedback, he said. "They did what we asked," Kaminsky said. "The security community spent years bashing Microsoft, and (Microsoft) deserved to get bashed. But they listened."

Robert McLaws, a blogger who writes about Microsoft, is particularly gung-ho about Vista. He recommends that everyone buy a copy as soon as possible. "Security is the No. 1 feature in Vista, and everyone with a computer in the house should go out and buy it," he said.

All the praise aside, Vista isn't flawless. In fact, Microsoft has issued security patches for the operating system even before its final release.

"To think there won't be vulnerabilities and there won't be exploits is inappropriate," said Michael Cherry, an analyst with Directions on Microsoft. "At best, we should see the number of them decline and the time in between them increase."

No software is without flaws, and Microsoft will be the last to deny that.

"While we greatly improved the security of Windows Vista and we believe it is the best system available, I have always been clear that the system is neither fool-proof nor unbreakable; no software I have seen from anyone is," Allchin wrote on a Microsoft corporate blog last week.

Some critics, however, say Microsoft has reserved too many of the security features for the high-end editions of Vista. The operating system comes in five different versions (with a sixth, "Starter" edition designed for developing countries), but only Windows Vista Ultimate--the most expensive one--includes the maximum level of protection.

Even more, Vista comes to market in an era in which criminals are taking to the Net and looking for profits by breaking into the PCs of unsuspecting Web surfers. Vista is their next target.

"I don't want people to expect that their computer is never going to be compromised because of Vista; that's simply not the case," McLaws said. "The nature of maliciousness on the Internet is changing rapidly. It used to be that nerdy kids were trying to outdo other nerdy kids. Now it is criminals."

  • Talkback
  • Most Recent of 69 Talkback(s)
Lose what security features??
To say that Vista Ultimate is 'the only' package containing all the security features indicates that the author presumes that the features left out differ in any significant way from comparisons betwe... (Read the rest)
Posted by: gpederson01@... Posted on: 02/03/07 You are currently: Logged In | Log out
Vista Watch : Users give up to many rights for Windows Vista Beyond the Vista, a Leopard is stalking .   | 01/30/07
Don't like it... csa0307   | 01/30/07
It's our profession. Its appropriate to ***** mighetto   | 01/30/07
What profession do you mean exactly? xuniL_z   | 01/30/07
Mighetto's Job M.R. Kennedy   | 01/31/07
Unlike Winblows itanalyst   | 01/30/07
Windows Vista Program Deletions M.R. Kennedy   | 01/31/07
Some of want to know voska   | 01/30/07
yep that's the response to any criticism of MS... mdsmedia   | 01/30/07
Naw, your the zealot, go for it. No_Ax_to_Grind   | 01/30/07
And Once Again, You're Full Of CRAP itanalyst   | 01/30/07
choice balsover   | 01/30/07
Re: choice none none   | 01/30/07
Buy Mac, Buy a Linux PC from HP balsover   | 01/30/07
I'll prove you wrong voska   | 01/30/07
Choices M.R. Kennedy   | 01/31/07
Why comment? brendthess   | 01/31/07
Irrelevancies M.R. Kennedy   | 01/31/07
What Is Seriously Irrelevant Here Ole Man   | 02/01/07
"*discuss* the good or bad points" Ole Man   | 02/01/07
Usual Suspect M.R. Kennedy   | 02/02/07
Stop provoking the Windows nerds! B.O.F.H.   | 01/30/07
This is a feature I would welcome, not hate stevey_d   | 01/30/07
While I agree with what you say voska   | 01/30/07
"on any machine you log in to"? Ole Man   | 02/01/07
they are just going to feel safer...... wjw@...   | 01/30/07
The debate isn't whether it's better Chad_z   | 01/30/07
What does the Upgrade sticker say? Oknarf   | 01/30/07
OMG!!! EXPERTS!!! xuniL_z   | 01/30/07
Is security an issue for most users? No_Ax_to_Grind   | 01/30/07
The average user doesn't care Shelendrea   | 01/30/07
Hey, Be Easy On The Old Man itanalyst   | 01/30/07
That's not something that Vista can help with. Resuna   | 02/01/07
That would be why it is an issue to them voska   | 01/30/07
Do dweebs that live in a basement know what most usres care about? B.O.F.H.   | 01/30/07
Joe Average brendthess   | 01/31/07
Who died before naming *you* the God of IT? M.R. Kennedy   | 01/31/07
We're security guards and physicians as well as janitors... Resuna   | 02/01/07
Janitor with delusions of adequacy M.R. Kennedy   | 02/01/07
Which is why Microsoft's screwups hurt people who don't even use Windows. Resuna   | 02/01/07
Experts: Don't buy Vista for the security Loverock Davidson   | 01/30/07
Na, I have never had a problem with XP balsover   | 01/30/07
Vista Security ... mrlinux   | 01/30/07
Great advice xuniL_z   | 01/30/07
I Can Picture Lovedorks Post Six Months From Now itanalyst   | 01/30/07
I don't think you get it Shelendrea   | 01/30/07
The security update was over a year ago,for Beta 1 and old preview versions PB_z   | 01/30/07
Jim Allchin, Coached to Lie: Lets never Forget mighetto   | 01/30/07
*putting on my flak jacket* Shelendrea   | 01/30/07
Mixed feelings on this one 3D0G   | 01/30/07
In 5 seconds after reading Vista security, ... Vily Clay   | 01/30/07
Too much work... josh@...   | 01/30/07
Stuipid Question halvorwh@...   | 01/30/07
Answer with a question Shelendrea   | 01/30/07
Not-quite Stupid Answer M.R. Kennedy   | 01/31/07
Security blocks users for their own works PhilippeV   | 01/30/07
Heck, I wouldnt buy vista for anything. kraterz   | 01/30/07
Expert advice, don't buy Vista if you don't want to Boot_Agnostic   | 01/31/07
P.S. Boot_Agnostic   | 01/31/07
LOL Badgered   | 01/31/07
Come on now Boot_Agnostic   | 01/31/07
Mac is safer and easier than Vista, even for pc newbies jonathan swift   | 01/31/07
Is this right? angela_6uk   | 01/31/07
Safe Computing M.R. Kennedy   | 02/01/07
Vista has NOT done anything for the main security problem in Windows. Resuna   | 02/01/07
Everything Vista brags about, I got 2 years ago with Mac OS Tiger. usc1801   | 02/01/07
Experts: Don't buy Vista for the Security rondev   | 02/01/07
Comments Ole Man   | 02/01/07
Lose what security features?? gpederson01@...   | 02/03/07

What do you think?

advertisement

Whitepapers & Webcasts