Security features in Windows Vista and IE7 – Microsoft's view

Stephen Lamb · Network Security · 2006

With the launch of Windows Vista a few months off, its security prowess is more than a matter of curiosity. Detractors such as Symantec are lining up. We look under the covers at the security features in the run-up to Microsoft's biggest operating system launch since XP hit the streets nearly five years ago. And while we're at it, IE7, also currently in beta, gets the treatment. As the article shows, one of the features Windows Vista introduces is a privilege brokering system named User Account Control which obviates the need to login interactively with what Microsoft sees as ‘excessive privilege’. The requirement for excessive privilege often stems from application developers who build code using privileged accounts and hence the software they produce often assumes a similar environment. Previous versions of Microsoft Windows have required privileged accounts to be used to change the system's TimeZone setting. This setting together with several others have been changed to enable control by regular users. With Windows Vista due to be released in early 2007, IT departments across the world are planning for the inevitable. Also currently in beta testing, Internet Explorer 7 is likely to be out by year-end. What can be expected security-wise? Microsoft presents its case.

Read the paper · More papers on PaperTik