by Tom Henderson and Laszlo Szenes

Vista Beta 2: Microsoft bites the security bullet

Reviews
Jun 2, 20066 mins

Testing of Vista Beta 2 shows deployment pain will yield security gain.

In our testing of Microsoft‘s recently released Vista Beta 2 code, we found that in terms of its revamped client-side networking infrastructure and policy-based security controls, it’s in lock step with Microsoft’s Longhorn server code.

In terms of the interesting bits this next generation Windows client holds in its own right, we found fully functional system health monitoring capabilities and several neat security tricks, like random DLL loading as a means of thwarting potential memory exploits.


Longhorn beta test

Archive of Network World tests

Subscribe to the Network Product Test Results newsletter


In addition, Microsoft released the recommended hardware specifications to run Vista, which point towards 64-bit hardware (32-bit CPUs are allowed, though) with a minimum 1GB of memory for 64-bit CPUs (or 512MB for 32-bit processors). Microsoft recommends that all Vista machines be equipped with a 128MB graphics adapter. That’s a pretty huge appetite for desktop hardware, indeed. As for processor speed, we’d recommend as fast as you can get your hands on.

The doctors are in

While the August 2004 release of Windows XP Service Pack 2 ushered in an era of hierarchical user roles for Microsoft’s client software, Vista Beta 2 gets serious about using them. Users have diminished authority to do things that, in the past, were commonplace because Microsoft didn’t enforce its suggested program behavior for access to the system registry.

The anarchy is now controlled via a system called User Account Controls. As an example, applications commonly read and wrote from the registry at will – with any privilege strength they desired. Ultimately, they can still access the registry, but Vista Beta 2 requires that both users and applications authenticate the action or cancel it each time it happens in important levels. That is, if either the firewall or Windows Defender (Microsoft’s renamed anti-spyware and popup-blocking application) doesn’t stop the action first. This lack of “at will” access also applies to viruses that might want to hit on the registry. Indeed, every virus and Trojan sample we threw at Vista Beta 2 (and we used seven sample varieties) was detected and thwarted.

Microsoft plans to offer custom application workarounds, called ‘shims’, that trap error messages spawned from popular misbehaving applications. Microsoft also ‘sandboxes’ applications, including IE7 to areas considered more ‘safe’ than the “Program Files” and Windows “system” areas. Constant authentication and re-authentication of errant program actions will cause repetitive user and administrative headaches until new versions of popular applications are produced, shims become available, or other ‘safe’ workarounds become commonplace.

Security with a catch

Several other security features will also be difficult to administer initially, but will likely payoff handsomely. For example, Microsoft now uses a method in Vista Beta 2 that randomizes system DLL memory addresses. Certain kinds of malware were previously able to predict where system DLLs were loaded based on profiling and to locate where the system kernel lived in the memory map. This situation allowed DLLs to be tampered with if the malware inserted code at specific memory locations to either infect or use system processes nefariously. Vista Beta 2 DLL memory displacement points are now much more difficult to predict.

Vista Beta 2 code, like Longhorn Beta 2 code, can prevent individual or classes of devices like USB flash drives, network cards, and other common detachable (and potentially hazardous or policy-violating) peripherals from being used. Currently, if the device-installation denial policy is invoked when Vista Beta 2 is first installed, it will prevent subsequent driver installation by device ID or class. However, if somehow a driver is already installed on the machine, the use of the device isn’t blocked. Therefore, using the current policy, it must be enforced from inception/upgrade. Additionally, the administrative password must be given to change the policy. Once changed, however, it’s seemingly changed forever until the device driver is forceably removed.

The state of these and other policies are the crux of what Microsoft calls “System Health”, which is the mechanism that provides data to Longhorn Server under the Network Access Protection (NAP) System scheme. With information about the client’s health and adherence to configuration policy, the client and server pieces work together to permit, deny, or quarantine network access by Vista Beta 2 (or updated Windows XP) clients that aren’t up to company standards.

However, we found that all of the fabulous client-side User Access Controls can still be thwarted with an old trick. While the initial administrative password is set, another user called “administrator” lives inside the client machine. This password-less ‘god-mode’ account is completely unprotected, and was not only able to undo critical protection settings, but could also become infected with the viruses and Trojans we’d tested earlier. If available to end-users (or malware), access to this account means all the protection bets are off. This account, and its password – just like user ‘root’ in Unix – must be carefully guarded from access.

Real estate

Still painful is the fact that the new clutter-removing eye candy user interface additions to the “classic Windows look” aren’t well annotated or documented. Users have a choice, but we found ourselves fiddling to make things work in any useful way. Microsoft still casts windows, but doesn’t spread out fields to fill the windows with row data, listings, or fields correctly. It becomes more visually compelling to use the Aqua interface, which allows 3D views of windows, and allows for window ‘protection’ – the ability to force a dialog box to the foreground so that a user must address questions posited by the dialog. Users are prevented from ‘ignoring’ problems by bringing other windows to the foreground and working within them. Procrastinators will wail.

The user experience of Vista isn’t difficult overall. Some ordinary things are hidden, and instead of ‘parachute menus of choices’, ribbon menus are now used that perform the same choice of offering tasks but with an added visual dimension. Help desk support for basic operating system fundamentals changes should be minimal – it’s the application and security messages from errant/undisciplined programs that will cause problems.

The net-sum

Vista Beta 2 is indeed Windows. It looks, feels and operates with Windows-familiar functionality. It also has impressive graphics – if hardware is available to support the eye candy.

Underneath, it’s been gutted in numerous and important ways that will force many third-party security vendors and applications vendors into product overhauls or providing ‘shim’ supports. If there was ever a time for Microsoft to bite the security bullet hard, this is it, and with the stunning exception we found (above), Microsoft is on the right track. The continued delays in getting this new version of Windows out the door will be worth Microsoft’s embarrassingly long effort.

NW Lab Alliance

Henderson and Szenes are also members of the Network World Lab Alliance, a cooperative of the premier reviewers in the network industry, each bringing to bear years of practical experience on every review. For more Lab Alliance information, including what it takes to become a member, go to www.networkworld.com/alliance.