Users ponder Microsoft security plans

News
Apr 19, 20045 mins

Microsoft should retrofit older software with new security enhancements it plans to release later this year and add more support and better reporting features to its forthcoming patch-management tools, according to users attending at a stop on the company’s current 20-city Security Summit road show.

DENVER – Microsoft should retrofit older software with new security enhancements it plans to release later this year and add more support and better reporting features to its forthcoming patch-management tools, according to users attending at a stop on the company’s current 20-city Security Summit road show.

End users say older versions of software they run, especially Windows 98 and 2000 and server software such as Exchange and SQL Server, would benefit from new security tools Microsoft is developing. Those tools include the Internet Connection Firewall (ICF) on the desktop and automated patch-management tools for servers and desktops, both of which are set for delivery no later than June 30 when Microsoft ships Windows XP Service Pack 2 and Windows Update Services (WUS), respectively. In addition, users say WUS, a free server-based application for downloading and deploying patches, also would benefit from more sophisticated reporting tools that detail patch installations.

Users’ have made these suggestions because ICF isn’t compatible with operating systems released before XP. WUS initially will only support Windows XP Professional, Win 2000, Windows Server 2003, Office XP, Office 2003, SQL Server 2000, MSDE 2000, and Exchange 2003. Microsoft will only say other software will be added over time.

Some users are caught in a deployment conundrum.

“We can’t implement what is available. Microsoft is addressing our security needs, but we’re not able to take advantage of it right now,” said Jeff Rachwitz, network engineer for Harrison School District 2 in Colorado Springs. “We can’t automatically deploy patches to our Windows 98 desktops with WUS.”

That means half of the districts 3,000 desktops, which are spread out over 21 schools, have to be patched individually, as new patches are released. The district can’t upgrade those desktops because its educational applications won’t run on XP.

The district has been able to upgrade the other half of its desktops to XP to take advantage of welcomed security features, including ICF and the predecessor to WUS, Software Update Services 1.0, but now those machines can’t run the educational applications.

The presentation in Denver drew 900 people, who attended daylong seminars after receiving a summary of current tools and a review of Microsoft’s security road map from Richard Kaplan, who last week was appointed corporate vice president for business development marketing and emergency response in Microsoft’s Security Business Unit.

Kaplan said Microsoft will evaluate adding security features in XP SP2 to older operating systems, but he said, “We have no commitments yet.”

Despite calls for some changes, most users say it’s about time Microsoft made the commitment to secure its software and applauded the company’s ongoing efforts, which began in earnest two years ago with its Trustworthy Computing initiative.

“Windows has always been designed to be easy to use; now they have to make up for lost time,” said Michael Henry, a developer with Manakoa Service Group in Boulder, Colo., which develops software for risk management and regulatory compliance. Henry said that ease of use fuels security problems with Microsoft software. “In time they will improve,” said Henry, adding that Manakoa will take advantage of the new security features in its future tools.

However, Microsoft did not hear encouragement from everyone.

“Things are sure to get worse before they get better because hackers have seen Microsoft’s weaknesses, and they continue to exploit them,” said Ray Haschenburger, president of Alternative Computers in Denver, an IT contractor to government organizations. “Users are getting close to the attitude of ‘fix it or get off the pot.'”

Security slate

Microsoft this year plans to introduce a number of security upgrades to its software, including enhancements to its desktop operating system and patch-management tools.
Tool Release Description
Windows XP Service Pack 2No later than June 30Includes personal firewall and other upgrades that lock down vulnerable operating systems services by default.
Internet Security and Acceleration Firewall 2004No later than June 30Firewall for perimeter security includes URL scann-ing, new configuration and access control tools.
Windows Server 2003 Service Pack 1Second half of this yearIncludes Security Configuration Wizard, roles-based administration tool to configure server and lock down ports and services.
Windows Update ServicesSecond half of this yearFree server-based application for downloading and deploying patches.

Haschenburger said he already sees Linux creeping into government organizations for security and reliability reasons. “Years ago complaints about daily patches for HP-UX hurt HP, and the same scenario is hurting Microsoft now,” he said. “They are running scared because this [Denver security summit] is packed with people looking for better security.”

Roberta Bragg, an independent computer security evangelist who spoke at the summit in Denver, said evaluating Microsoft’s job on security has to take into account all the products they have. “Microsoft is doing a tremendous job, but they have a long way to go,” she said.

Bragg said Microsoft can’t escape accountability for all its products, but that other vendors, IT administrators and end users must all play a part in securing a network environment.