Skip Links

Network World

  • Social Web 
  • Email 
  • Close

One year later: Did Vista's focus on security pay off?

By Elizabeth Montalbano and Robert McMillan , IDG News Service , 11/21/2007

Microsoft's emphasis on improvements to security features in Windows Vista may have undermined business adoption of the OS, as many business and enterprise customers are still holding off on upgrading to the OS nearly a year after its release to them.

Microsoft spent a good deal of time and money to ensure Vista's security after Windows XP and applications running on it proved susceptible to devastating worms like Blaster, Slammer and MyDoom. Though Microsoft released Windows XP Service Pack 2 to remedy some vulnerabilities, the company decided that security would be a top priority for the next major Windows release, said George Stathakopoulos, general manager of Microsoft’s Response and Product Centers.

"The security part of Vista was talked about a lot because it was a primary concern all over the world," he said.

But in retrospect, those close to the company and even Microsoft have acknowledged recently that security has not proved to be important enough to encourage businesses to upgrade to Vista.

Robert Hansen, CEO of IT security consultancy SecTheory LLC in Austin, Texas, who has spoken at Microsoft's Blue Hat hacker conference and done contract work for the company, said Microsoft is aware that its laser focus on Vista security may have been a misstep, and that it is trying to remedy that.

He said that Microsoft staffers are pleased in general with Vista's security improvements, but they acknowledge that "the consumer reaction was ho-hum."

"Over the next year, although security is definitely top of mind, some people feel as if the security as a priority is going to shift downwards, as opposed to feature enhancements," Hansen said.

Hansen also said that Microsoft traded general OS usability to add some of Vista's security features, such as User Account Control (UAC), and is "feeling pressure from Apple" to provide a more intuitive and user-friendly OS.

UAC gives system administrators more control over what features business users can access. It has become a chief complaint with users because it interrupts a PC user's work with a pop-up window whenever they're about to do something the feature considers an administrative function. UAC can be bypassed by working in administrator mode instead of standard user mode, but this defeats the purpose of the added security the feature was supposed to bring to the OS.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comments (1)
Login
Forgot your account info?

RE: One year later: Did Vista's focus on security pay off?By Rick on November 26, 2007, 1:18 pmMostly wrong. People avoid Vista like the plague because it breaks things that work on XP. It was released with no drivers for most hardware and no one was going...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.

Whitepapers

Advancing the Economics of Networking

Aging network systems and old habits have dictated how businesses spend their IT budgets. As a...

Implementing HA at the Enterprise Data Center Edge to Connect to a Large Number of Branch Offices

This paper reviews the problem of creating a network where the dynamic availability of services is...

Enterprise Data Center Network Reference Architecture

Using a High Performance Network Backbone to Meet the Requirements of the Modern Enterprise Data...

Webcasts

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Stay out of the headlines: Detecting and preventing network intrusions

How do YOU stay out of the headlines? There is no denying that risk exists in our computer-driven...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

IP address management in 2008 - six things to know

Read this Network World Special Brief to learn how Enterprise IT managers must update their...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...