Microsoft
Experts have raised doubts about the integrity of Microsoft's OneCare security suite

Microsoft's OneCare offers malware loophole

Researchers question suite's security

Written by Tom Sanders in California

The firewall in Microsoft's forthcoming OneCare security suite fails to stop two potentially harmful data streams, security expert Roger Grimes has alleged.

Grimes claims that the firewall will allow any Java application or Java script to contact the internet, and is also set up to trust any application that uses a digital certificate.

While Microsoft has its reasons for assuming that traffic from these sources can be trusted, the facility goes against best practice by allowing it through by default, argued Grimes, who referred to it as a "misconfiguration error".

"In any managed firewall service you would rather not have any blanket statements. You want to deny traffic by default, not by exception," he told vnunet.com. "My hope is that Microsoft will reconsider the policy." 

Microsoft's OneCare suite, announced in May last year, bundles antivirus, anti-spyware, back-up software and a two-way firewall that filters incoming and outgoing traffic. The firewall currently built into Windows XP SP2 only filters incoming traffic.

The suite is currently in beta and is scheduled for release as a subscription service.

But Grimes argued that Microsoft is undermining the suite's security by letting through code signed by a digital certificate. A digitally signed application should not be trusted just because it offers a certificate, as it creates a loophole for spyware and other malware.

Most consumers are aware of digital certificates from e-commerce and online banking websites. The certificate verifies the identity of the site's publisher and aims to boost confidence in the site's trustworthiness.

But while there are rigid qualification requirements for so-called high insurance certificates used by e-commerce websites, basic certificates are easy to obtain and in some cases require the applicant to produce very few if any credentials.

"A lot of spyware uses signed code these days," Grimes contended. "It used to be that you could trust signed code, but spyware vendors are beginning to sign their code to make it look more official to end users."

Yoav Schwartz, lead programme manager for OneCare, denied that this is the case. "It is highly unusual for malware to be signed," he wrote in response to Grimes's claims. 

Schwartz added that the suite's antivirus and anti-spyware technology adds a defence layer designed to stop malware from infecting computer systems in the first place.

Tags:

reader comments

related articles

Internet fraud

Fraud puts online banking at risk of collapse

Consumer confidence 'fragile', reports FSA 23 Jan 2006

 

AMD forum users exposed to WMF worm

Failure to patch put users at risk 31 Jan 2006

More WMF woes for Microsoft

Redmond dismisses new flaws as just 'performance issues' 11 Jan 2006

IBM boosts Sametime with AIM/Yahoo support

Latest version of Lotus Sametime gets interoperability enhancements 25 Jan 2006

Credit card providers choke on safer payments

Complexity stands in the way of broad adoption, Gartner warns 19 Jan 2006

related whitepapers

today's top stories

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

Learning from the credit crunch to avoid a broadband crunch

While it might be the most pressing issue de jour , the financial system isn’t the only area where government needs to... 10 Oct 2008

How careerism can warp IT procurement

Many working in IT put their career interests before those of their employer when weighing up purchasing options 10 Oct 2008

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Computing podcast - IT implications of the banking crisis, and the FSA clamps down on IT security

We discuss the effect of shotgun mergers and acquisitions on financial services IT staff, and examine the industry regulator's plan to fine directors for information security breaches 09 Oct 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job


IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Are you worried about your job prospects in IT over the next 12 months?

Are you worried about your job prospects in IT over the next 12 months?

Will the economic crisis affect your job prospects?

Previous poll results

Latest audio and video articles

Remote workerVideo

WiMax: Threat or opportunity?

We examine the merits of WiMax and its benefits relative to other wireless technologies in our latest video 13 Oct 2008

programming codeVideo

The definitive guide to software development

Five key trends and five best practice tips to help you improve your programming capabilities 09 Oct 2008

Latest in-depth articles

Financial Services Authority buildingAnalysis

FSA threatens executives with fines

Senior management to be held accountable for security lapses at banks 09 Oct 2008

Comment

Broadband must be a spending priority

For the economic health of the nation, the government would do better to bankroll an optical fibre rollout rather than prop up profligate banks 09 Oct 2008

Advertisement

Primary Navigation