Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


November 2006

Fixing Microsoft's Leaky Pipes


RSS
Subscribe to Windows IT Pro | See More Windows OSs Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

You buy a house. After you move in, your walls and floors are suddenly soaking wet because all the pipes are leaking. You learn that your builder is infamous for constructing popular houses that have porous plumbing. Then you find some plumbing companies that specialize in fixing your builder's pipes. These plumbers have become hugely successful by understanding how to cut holes in your walls, access the pipes, fix them in whatever way they feel is appropriate, then charge you for getting rid of the leaks your builder was responsible for. The plumbers might have knocked holes in your walls, but at least you're no longer drowning.

Naturally, you join your neighbors in demanding that your builder stop constructing houses with dangerous plumbing. After years of complaints, the builder finally sees the light and revamps the whole plumbing system. The builder also realizes that when plumbers need to work on the pipes (as they inevitably must), whacking holes in random walls isn't the best approach and burglars could also use those holes to plunder the house. So the builder decides to create access panels through which plumbers can reach the pipes but that shut burglars out.

Everybody lives happily ever after, right? Not really. Plumbers are outraged: Not only has the builder eliminated a huge plumbing market by constructing houses with better pipes, but the builder is also preventing the plumbers from taking the quickest, easiest route to reaching the pipes. No more knocking holes in walls. How dare the builder improve its product in ways that prevent other businesses from profiting from the product's defects?

Builders? Plumbers? Microsoft?
I didn't set out to write this column about the construction industry. I was planning to write about the latest RCs of Microsoft Office 2007 System and Windows Vista. (In a nutshell: Office is great; Vista still has a way to go, especially on Tablet PCs.) But I was watching the morning news today, and my writing plan changed radically.

CNBC was interviewing security product vendors and Microsoft security Corporate Vice President Ben Fathi. The vendors were outraged that security precautions such as Kernel Patch Protection in Windows x64 technology will no longer allow anyone access to alter the Windows kernel at runtime. The vendors complained that this new security restriction is damaging to their business because they've previously had such access.

Ben responded with an unimpressive and unclear analogy about plugging your stereo headset directly into the guts of your CD player (Ben's analogy for the Windows kernel) instead of using the manufacturer's plugin outlets (Ben's analogy for Windows APIs). The CNBC anchors had no idea what Ben was talking about and snickered that this was another typical example of Microsoft squashing its competitors.

I'm the first to say that Microsoft has plenty of flaws that we should (and do) complain about—in fact, security is one of the biggest. But the CNBC reaction to this issue floored me because of the complete lack of understanding it displayed. After taking so much heat about its weak security, Microsoft is finally working to fix it. And people immediately complain that fixing security is wrong because it keeps out the good guys along with the bad guys. Catch-22 for Microsoft.

No Analogies
I asked Microsoft to clarify its position on this issue and got a long, boring marketing-speak message that makes my builder/plumber analogy look like great writing in comparison. I'll spare you the entire message, but here's the gist:

Current 32bit implementations of the Windows Kernel-contain undocumented and unsupported interfaces that modify key services of the kernel. This creates significant performance, reliability, and security risks. Not only can ISV's modify the 32bit kernel in place, causing operating system crashes and slowdowns, but attackers have equal access. Kernel Patch Protection, which is not new to Windows Vista and is available for x64bit systems only, removes the ability to modify or utilize undocumented or unsupported capabilities of the core of the operating system...Microsoft is providing documented, supported methods for industry partners and Microsoft product teams to implement new innovative functionality in defined and supported ways that will result in greater security and reliability for our mutual customers on x64bit systems. s

In Short: To Ensure Security, Kernel Access—Bad, APIs—Good
Let's continue to hold Microsoft's feet to the fire on security and other important issues. But let's also distinguish between attempts to squash the competition (which are a reality I've seen firsthand in different contexts) and attempts to do the right thing for customers.

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
VMware and the Future of Virtualization

What's next for virtualization and business IT? Windows IT Pro senior editor Jeff James speaks with VMware President and CEO Diane Greene on the future of virtualization technology. ...

WinInfo Short Takes: Week of September 8, 2008

An often irreverent look at some of the week's other news, including the long-awaited back to school season, Microsoft's first Seinfeld/Gates ad, some EU insights, another Netbook improvement, Opera silliness, and much, much more ...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...


Windows OSs Whitepapers Why SaaS is the Right Solution for Log Management

Are You Satisfied?

A Preliminary Look at Deployment Plans for Microsoft Windows Vista

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

IT Connections
Dive into the new Microsoft platforms and products you implement and support with the experts from Microsoft, TechNet Magazine, Windows ITPro and industry gurus. There are 70+ sessions and interactive panels with networking opportunities.

Attention User Group Leaders...
Announcing the eNews Generator—a FREE HTML e-newsletter builder for user group leaders. Build your HTML and text e-newsletters in minutes and add Windows IT Pro & SQL Server Mag articles alongside your own message!.

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Get SQL Server 2008 at WinConnections
Don’t miss Microsoft Exchange and Windows Connections conferences, the premier events for Microsoft IT Professionals in Las Vegas, November 10-13. Every attendee will receive a copy of SQL Server 2008 Standard Edition with one CAL.



Interested in Email Encryption?
Read about the advantages of identity-based encryption in this free report.

Order Your SQL Fundamentals CD Today!
Learn how to use SQL Server, understand Office integration techniques and dive into the essentials of SQL Express and Visual Basic with this free SQL Fundamentals CD.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing