Some of the companies that have built a business on the security problems in Microsoft’s operating systems now disingenuously are decrying Microsoft’s own efforts to address those security gaps.
But Microsoft being Microsoft, the company has yet to learn how to handle such loaded issues without stirring up a cloud of accusations about anticompetitive behavior.
It started when McAfee last week took out a full-page ad in the Financial Times taking Microsoft to task for the way it will approach security in the forthcoming Vista operating system, criticisms that were reiterated at a briefing hosted in New York by the company’s CEO, chief scientist and chief security architect.
McAfee has two central gripes: first, that Microsoft is locking up the kernel in the 64-bit version of the new operating system, excluding kernel access for third-party security tools and thus limiting what those tools can do; and second, that Microsoft is making it impossible to disable the Windows Security Center console, even if the customer has installed different security products.
In an open letter from Chairman and CEO George Samenuk titled “Microsoft increasing security risk with Vista,” McAfee argues, “Microsoft seems to envision a world in which one giant company not only controls the systems that drive most computers around the world but also the security that protects those computers from viruses and other online threats. Only one approach protecting us all: When it fails, it fails for 97% of the world’s desktops.”
The real issue is that companies like McAfee will lose business as Microsoft addresses security problems, because buyers always try to simplify their environments by reducing the number of vendors and tool sets they have to deal with.
Instead of being criticized, Microsoft should be lauded for finally addressing security issues head-on. That said, the company is going about it wrong, taking its usual heavy-handed, crush-all-competitors approach. Microsoft is simply being greedy by locking up the kernel and making it impossible to disable the console.
Experts say it shouldn’t be hard for Microsoft to offer security vendors some form of authenticated access to the kernel, and the console thing is pure hubris.
The fear of a monoculture that McAfee spells out is overstated, but customers still want choice, and Microsoft should be a good corporate citizen and reverse its stand.
Microsoft, by all means safeguard your goods in every way you can, but acknowledge that other companies have been solving your problems for years, and some of your own customers will continue to prefer their solutions. Play nice.




