Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Vista Beta 2: Microsoft bites the security bullet

Testing of Vista Beta 2 shows deployment pain will yield security gain.
By Tom Henderson and Laszlo Szenes , Network World , 06/02/2006
  • Share/Email
  • Comment
  • Print

In our testing of Microsoft's recently released Vista Beta 2 code, we found that in terms of its revamped client-side networking infrastructure and policy-based security controls, it's in lock step with Microsoft's Longhorn server code.

In terms of the interesting bits this next generation Windows client holds in its own right, we found fully functional system health monitoring capabilities and several neat security tricks, like random DLL loading as a means of thwarting potential memory exploits.


Longhorn beta test
Archive of Network World tests
Subscribe to the Network Product Test Results newsletter

In addition, Microsoft released the recommended hardware specifications to run Vista, which point towards 64-bit hardware (32-bit CPUs are allowed, though) with a minimum 1GB of memory for 64-bit CPUs (or 512MB for 32-bit processors). Microsoft recommends that all Vista machines be equipped with a 128MB graphics adapter. That's a pretty huge appetite for desktop hardware, indeed. As for processor speed, we'd recommend as fast as you can get your hands on.

The doctors are in

While the August 2004 release of Windows XP Service Pack 2 ushered in an era of hierarchical user roles for Microsoft's client software, Vista Beta 2 gets serious about using them. Users have diminished authority to do things that, in the past, were commonplace because Microsoft didn't enforce its suggested program behavior for access to the system registry.

The anarchy is now controlled via a system called User Account Controls. As an example, applications commonly read and wrote from the registry at will - with any privilege strength they desired. Ultimately, they can still access the registry, but Vista Beta 2 requires that both users and applications authenticate the action or cancel it each time it happens in important levels. That is, if either the firewall or Windows Defender (Microsoft's renamed anti-spyware and popup-blocking application) doesn't stop the action first. This lack of "at will" access also applies to viruses that might want to hit on the registry. Indeed, every virus and Trojan sample we threw at Vista Beta 2 (and we used seven sample varieties) was detected and thwarted.

Microsoft plans to offer custom application workarounds, called 'shims', that trap error messages spawned from popular misbehaving applications. Microsoft also 'sandboxes' applications, including IE7 to areas considered more 'safe' than the "Program Files" and Windows "system" areas. Constant authentication and re-authentication of errant program actions will cause repetitive user and administrative headaches until new versions of popular applications are produced, shims become available, or other 'safe' workarounds become commonplace.

  • Share/Email
  • Comment
  • Print
Partner Content
CA logo

CA Network & Voice Resource Center

Comprehensive Network & Voice Management Visit CA Network & Voice Management Resource Center and get insights into industry best practices, information that helps you to address your challenges.

CA Network & Voice Management Resource Center

whitepaper

Managing Voice Over IP for Successful Convergence

Voice over IP (VoIP) has much to offer in cost savings but some customers have concerns about VoIP call quality compared to the quality of traditional voice services. This white paper will help you learn how to take the right steps so that voice quality is assured.

Managing VoIP for Successful Convergence

whitepaper

The Changing Face of Network Management

Managing your network is serious business. This paper discusses the benefits of integrating configuration change-awareness into your network fault management solution

Download Whitepaper

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.