Slashdot Mirror


Security Companies Tussle With MS Security Center

hey0you0guy writes, "The large security firms such as Symantec and McAfee want Microsoft to allow them to replace Microsoft's Windows Security Center. Microsoft is refusing these requests. 'By imposing the Windows Security Center on all Windows users, Microsoft is defining a template through which everybody looks at security,' Bruce McCorkendale, a chief engineer at Symantec, said in an interview. 'How do we trust that Microsoft knows what all the important things about security are to warn users about?' Given Microsoft's past, with vast piles of security flaws and patches, they should at least cooperate with these companies. A dispute still exists over PatchGuard, a security feature that Microsoft says is designed to guard core parts of the 64-bit version of Vista, but which critics say locks out helpful software from security rivals."

18 of 225 comments (clear)

  1. Bad track records all around by Nimey · · Score: 5, Insightful

    It's not as though Symantec and McAfee have spotless records on security and especially not fucking up your Windows installation. The more stuff that's in a sandbox the better.

    --
    Hail Eris, full of mischief...

    E pluribus sanguinem
    1. Re:Bad track records all around by betterunixthanunix · · Score: 5, Insightful
      And Windows should have been designed with security in mind since '95, when they integrated networking and web browsing. Symantec's MASSIVE business is the result of poor design on Microsoft's part, which is a shaky basis for a business. The fact that Microsoft is at least trying with security is making Symantec nervous...

      Of course, they said that about other things too...

      --
      Palm trees and 8
  2. Dancing with the devil by truthsearch · · Score: 4, Insightful

    By imposing the Windows Security Center on all Windows users, Microsoft is defining a template through which everybody looks at security

    By imposing the Windows UI on all Windows users, Microsoft is defining a template through which everybody looks at UI.

    By imposing the Win32 API on all Windows developers, Microsoft is defining a template through which everybody looks at development.

    If you sell software to help manage Windows, Microsoft will define your business plan. Those are the consequences of dancing with the devil. Not that they should be happy with it, but you can't expect any less from Microsoft.

  3. Re:Arrrrr! by dave562 · · Score: 4, Informative
    What's the harm in running both at the same time?

    Have you ever run two anti-virus programs on a computer at the same time? More often than not your file system performance completely tanks because every time a file is accessed you have two programs trying to scan it and verify it's integrity. You will also frequently run into problems where one AV program will label the other AV program as a virus.

  4. Re:They'll be forced to play due to antitrust laws by Frumious+Wombat · · Score: 4, Insightful

    It will be an interesting suit with the argument, "They fixed their operating system, so we're not needed any more, but they won't let us in". So, they took the part of the OS most succeptible to being tainted, and shut it off so it can't be. At least they're even handed; "Friend or Foe, Out You Go."

    --
    the more accurate the calculations became, the more the concepts tended to vanish into thin air. R. S. Mulliken
  5. Re:They'll be forced to play due to antitrust laws by Gr8Apes · · Score: 4, Insightful

    If they'd actually fixed it. But they haven't. (See IE7 zero day exploits)

    And they're bundling security products with their OS. They're not providing a secure OS. There's a major difference between the two. The first is illegal when you're a defacto monopoly. The second would be welcomed by everyone.

    --
    The cesspool just got a check and balance.
  6. Why you shouldn't give a shit. by argent · · Score: 5, Insightful

    Microsoft's whole approach to security is backwards. And so is the approach of Symantec and Macafee and the rest... not to mention the EC and everyone who thinks antitrust is even applicable to this whole commotion.

    They think they can add security on, like a product. You can't. You have to design it in. If you had a building with no locks on the doors you wouldn't keep casual visitors out by adding guards before you'd even tried adding locks, even if carrying cards or keys was "inconvenient". So why does Microsoft think they can add security to Internet Explorer that way?

    The whole basis of Microsoft's approach to the Internet is fundamentally wrong. They can't fix it by adding products. They can only fix it by ripping out most of the desktop-browser integration they fought the DoJ to a standstill over in the Clinton and first Bush administrations, and making the browser responsible for never allowing an untrusted object out of the sandbox, no matter what. Even if sandboxes are "slow" and installing plugins are "inconvenient".

    Same with Windows networking, CIFS, CIFS-authentication for HTTP, and everything else they've done to lower the barriers between local and remote resources. Those barriers, those locked doors, are there for a reason.

    1. Re:Why you shouldn't give a shit. by SnprBoB86 · · Score: 4, Insightful

      "...and making the browser responsible for never allowing an untrusted object out of the sandbox, no matter what."

      What a novel idea. Microsoft should implement this!

      Oh, wait...

      http://www.microsoft.com/technet/itsolutions/msit/ security/IE_protected_note.mspx

      --
      http://brandonbloom.name
  7. Re:Vista is Dead by ppz003 · · Score: 5, Insightful
    Vista is dead before it even arrives. What would I possibly want it for that I don't already have?

    Tell this to everyone who will buy a new PC as their old one becomes so infested with malware that it slows to a crawl. I bet MS will make sure any new computer will come with Vista once (maybe never, I hope) it comes out.
  8. I cry not for McAffee and Symantec. by mumblestheclown · · Score: 4, Funny

    So, McAffee/Symantec..

    Has actual PC security actually interested you in the past, say, decade? I was of the impression that you just paid some second rate programmer in bangalore a load of bananas to churn out any old crap that had the following requirements:

    1. we must be able to sell it in regular, deluxe, gold, platinum, internet, special edition, international, lite, and fat free versions. after all, this allows the user to pay for the exact level of security they need. consumer choice, right! some people only want to pay a little and thus be protected only against some vague subset of last year's threats, while others want to pay more and thus be protected a bit more against some vague subset of last year's threats.

    2. as in #1, the software must be sold in yearly versions. this allows users to respond to the cutting edge threats of 2003 by buying the 2005 version, still on sale in CompUSA (probably).

    3. we must really focus our efforts on getting this shiat pre-loaded on as many chain store PCs as posslbe. WARNING YOUR COMPUTER IS AT RISK! DO YOU WANT TO PAY $99.99 PER YEAR NOW TO UPGRADE? Your choices are [ Yes ] and [ Ask me again in 5 minutes with a big ass system modal dialog box ]

    4. The software must be impossible to uninstall, for Sound Business Reasons (tm). Well, we should include an uninstall routine, but ensure that it does not work if the software is modified in any way.

  9. It's worse than that by Anonymous Coward · · Score: 5, Insightful
    It's in Symantec's interest that Windows *remain* insecure forever so they can keep selling workarounds to the broken OS.


    I wouldn't trust either side in this argument -- Micrsoft has long proven itself incapable of understanding comptuer security (at least compared to any other OS competitors), and the anti-virus guys have a business model that relies on Fear of Viruses.


    Neither is in a position to earn any trust from anyone.

  10. Silly question by Guppy06 · · Score: 5, Insightful

    If third-party software could automatically disable Microsoft's Security Center, couldn't malicious software do the same?

    From a busines perspective, this may be the same as bundling IE, but from a security perspective this is the exact opposite: removing security holes rather than adding them (in the name of "functionality").

    Yes, Microsoft is likely being monopolistic, but I think I'd rather worry about all the Windows zombies populating the web rather than the profit margin of particular security software companies, especially when said companies rely on the inherent insecurity of Windows installations for their income.

  11. Re:Arrrrr! by Shadyman · · Score: 4, Funny

    You will also frequently run into problems where one AV program will label the other AV program as a virus.

    That's not a bug, it's a feature. It's called 'competition' :p

  12. Some things only the OS should access by Anonymous Coward · · Score: 4, Insightful

    If you open up part of the system so that rival security firms can access them, then potentially anyone could access them. Security mandates that there are some things that only the OS can access. So much as I despise M$, I have to agree with them here.

  13. First they came. by OpenSourced · · Score: 4, Insightful

    First they came for the office software companies. But I said nothing because I wasn't an office software company.
    Then they came for the internet browsing companies. But I said nothing because I wasn't an internet browsing company.
    Then they came for the media playing companies. But I said nothing because I wasn't a media playing company.
    Then they came for the security software companies. But I said nothing because I wasn't a security software company.
    Then they came for me, and there was no one left to speak out for me.

    I suppose some day the sofware companies that do bussiness with Microsoft and so help it consolidate its grip on the desktops of this world will take note and start thinking about alternative platforms.

    --
    Rome taught me patience and assiduous application to detail. Virtues which temper the boldness of great, general views.
  14. Rather Microsoft than McAfee... by Curmudgeonlyoldbloke · · Score: 4, Insightful

    (no, really)

    As a former McAfee home user, I was rather surprised to see MS' "security center" replaced with McAfee's when I made the mistake of updating their AV software just over a year ago. What McAfee put in place instead was little more than an annoying attempt to sell me McAfee products that I didn't need (such as a software firewall; in addition to a hardware router controlling access in I also had a software firewall from another vendor in place to stop unwanted access out).

    I rejected McAfee for home use because of this, and tried to make it is clear as I could to the company why (although I doubt that that got past the poor bloody infantry on the helpdesk). Like many people here I'm sure, I get landed with fixing people's Windows PCs. Recommendations count, and McAfee's home software certainly haven't had any from me over the last year.

  15. Simple solution by ditoa · · Score: 5, Informative

    Don't replace, disable! Simply disable the Security Centre service, install your own and you're done. Infact this is exactly what we have done at work, the idea of a security centre is great however we wanted to add our own applications to the security centre. Sadly there is no way to do this with the default security centre in Windows XP SP2. So rather than try and extend it we simply disabled it and replaced it. Doing the job of the security centre is pretty simple as it is documented what applications have to do to be "seen" by the security centre so we just did the opposite to monitor them (Symantec is very difficult about this because it has anti-monitoring tech built in). I don't see why this is a big problem for Symantec. AFAIK there is no reason they cannot disable the security centre service when they install their application.

  16. What Do These Companies Expect? by segedunum · · Score: 4, Insightful
    They've been milking money from Windows lack of security and viruses for years, so it's been good business for them. They have flat out and point-blank refused, along with many other companies, to take a lead in developing another desktop system, and developing for it, so that they won't continue to be at a disadvantage. They want to support only Windows, and develop software only for Windows. Companies like Adobe, with it's suite of software like Photoshop and ex-Macromedia stuff that makes a tidy profit, are going to be next in the Redmond cross-hairs over the next few years.

    I mean, I know Microsoft has a monopoly through Windows, but do these companies really not expect Microsoft to use that against them? These software vendors, between them, do have the power to move people away from Windows and on to a system where they all have a much more level playing field.

    Bruce McCorkendale, a chief engineer at Symantec, said in an interview. 'How do we trust that Microsoft knows what all the important things about security are to warn users about?'
    Errrrr. I have news for you Mr. Chief Engineer *snigger*. Windows is a closed source operating system designed to make money for Microsoft. They control the software you run your software on, so they have the high ground. Be grateful that you have had a company and a nice salary off the back of that for all these years. Windows is not designed to keep you in business.

    A dispute still exists over PatchGuard, a security feature that Microsoft says is designed to guard core parts of the 64-bit version of Vista, but which critics say locks out helpful software from security rivals....."PatchGuard is hurting security vendors more than it is hurting malware writers," said Bruce McCorkendale, a chief engineer at Symantec, in an interview on Wednesday.
    Errrr. I have news for you imbeciles. Wait until that is protected by a Trusted Computing system in the hardware and it is difficult, bordering on impossible, to bypass and you are legally prevented from doing so even if you could. See. The whole Trusted Computing thing is most certainly not just about DRM in films and music, and it looks like a fairly big deal for Microsoft.

    I mean, I think Windows is a monopoly and Microsoft should be subject to restrictions like all monopolies have been. However, there's a part of me that is glad that idiotic companies like Symantec, other security companies and companies like Adobe will probably go out of business. Many of them go into denial and like to pretend that they don't compete with Microsoft in order to support only Windows (making more money for Microsoft), but it is obvious that they do. When the brown stuff hits the fan they then whinge about it, rather than having put some thought and effort into ensuring their own survival. Digging your own grave must be a fun business endeavour.

    You know, Microsoft will argue that all these companies had it within their power, collectively, to go off and bolster the popularity of the Mac, or make Linux a first-rate desktop OS that they could sell their wares on if they weren't happy. And you know what, however much I don't want to really say it? They'll be right.