Rivals mock Microsoft's free security software

Although one of the top consumer security vendors welcomed Microsoft's Security Essentials to the market, another dismissed the new free software as a "poor product" that will "never be up to snuff." Earlier today, Microsoft launched Security Essentials , its free antivirus and antispyware software suite, which has been in development for almost a year. "I think it's a good thing that they're in the market," said Carol Carpenter, the general manager of Trend Micro's consumer division. "We look forward to the competition ... and I think Microsoft's targeting of developing countries and the unprotected is a good approach." Microsoft has pitched Security Essentials, which replaced the now-defunct for-a-fee Windows OneCare, as basic software suitable for users who can't, or won't, pay for security software. And now they've decided to go for the free market, but that's a very crowded market. Not everyone, however, agreed with Carpenter. "Security Essentials won't change anything," said Jens Meggers, Symantec's vice president of engineering. "Microsoft has a really bad track record in security," he added, ticking off several ventures into consumer security that the giant has tried, including Windows Defender, an anti-spyware tool bundled with Windows Vista and Windows 7; the released-monthly Malicious Software Removal Tool; and OneCare. "Like OneCare, Security Essentials is a poor product," said Meggers. "It has very average detection rates. There's not much room to grow there." In a company blog, another Symantec employee called Security Essentials a "rerun" of OneCare , and said: "At the end of the day, Microsoft Security Essentials is a rerun no one should watch." It's no surprise that top-tier security vendors like Trend Micro and Symantec dismissed Security Essentials today.

At the time, a Symantec executive said it was a capitulation by Microsoft, which was tacitly admitting it couldn't compete . But Meggers' take today was even more bearish. "We don't like the notion of 'basic,'" he said. "That makes me very worried, because the risk on the Web today is far too high for 'basic.' Tossing a bunch of little basic tools into the computing environment doesn't make it safe." Even Carpenter had some unkind words for Microsoft. "It's better to use something than to use nothing, but you get what you pay for," she said. "But I don't think it will worry the main security vendors. They did the same thing last year, when Microsoft announced the upcoming demise of OneCare and said it would ship a free, streamlined product. If I were a free, focused security company, trying to get my upsell over time, like AVG [Technologies], then I'd be concerned." Symantec's Meggers also wondered what took Microsoft so long to come up with Security Essentials. "It takes them an entire year to remove features from OneCare, to make something even worse than OneCare?" Meggers asked. "I could have done that with three developers in three months." And that's a good clue that Microsoft won't be able to keep up with the likes of Symantec, Trend Micro and McAfee, Meggers added. "Look how long it took them to build it. When was the last time that Microsoft innovated?" The free Security Essentials can be downloaded for Windows XP, Vista and Windows 7 from the Microsoft Web site. Security needs constant innovation.

Microsoft rallies businesses to start Win 7 migrations now

In a last promotional run-up to the Windows 7 release next month, Microsoft is urging business customers to start their upgrades now with examples of customers already using the software, and another acknowledgement that the company learned lessons from how it handled Vista's release three years ago. Additionally, many customers, as has been typical with a major Windows release, opted to wait for the release of the first service pack for Vista to even consider upgrading, and then many others did not move to the OS at all. Microsoft has devoted an unprecedented level of time and attention to making sure business customers will have a smooth migration and reap financial benefits from the new OS, said Microsoft Senior Director of Product Management Gavriella Schuster, in what is likely to be the last of a series of interviews with reporters as the company prepares to release Windows 7 worldwide on Oct. 23. "The real difference that I think people are seeing with Windows 7 is a different level of quality," Schuster said. "We've never reached this level of quality before in terms of performance, reliability, ease of deployment, the tools around it." As she has in previous interviews, Schuster reiterated Microsoft's mea culpa about how the company handled preparing its business customers, ISVs (independent software vendors) and other partners for the release of Vista, which was made available to them in November 2006. At the time, drivers for key hardware and peripherals were not available, and major applications were not compatible.

Schuster assured customers that moving to Windows 7 will be a far smoother process and will set a precedent for how the company will handle desktop OS releases in the future. We have put a lot of effort in really resolving the customer friction point before we come to them [with the OS]. We are being much more proactive and we're saying to customers, 'You don't have to wait.'" Microsoft introduced case studies Monday showing that some customers have taken this advice - among them, Starwood Hotels and Resorts, the city of Miami and Dutch IT services firm Getronics - and are reporting cost-saving benefits because of this decision, Schuster said. In fact, with a release-to-manufacturing version of Windows 7 already in the hands of many business customers, they can begin to move to the OS now. "In the past customers have had to wait for ISV support, they've needed to wait for a service pack release [to deploy Windows]," she said. "Shame on us, we've learned our lesson. Microsoft has a lot riding on Windows 7 after the overall disappointment of Windows Vista and is hoping the OS will jump-start business spending on desktop software. But analysts have said that many companies still using Windows XP don't really have a choice when it comes to migrating to Windows 7 - the question is more of when they will move than if they will. Many companies put a freeze on IT spending in general in the past year during the recession, and while conditions have improved, companies remain cautious about where they put their money.

Overall, customers who have moved already are saving on the time of IT labor devoted to PC management in the range of US$89-$160 per year because of new features in Windows 7, according to the findings of case studies Microsoft released Monday. The OS allows administrators to set policies across multiple desktops for updating software and other features through back-end connections to Microsoft server software that manage these processes, Schuster said. In particular, the city of Miami said it would save $54 per PC per year on power management because of new features in Windows 7 for setting group policies. Microsoft also has changed its plans for a software package that helps customers deploy Windows across multiple desktops, she said. Originally, Microsoft had planned to release a beta of MED-V 2 sometime in the first quarter of 2010, but decided to add Windows 7 support earlier due to customer demand for it, she said. Microsoft plans to release Microsoft Desktop Optimization Pack (MDOP) 2009 R2 in late October 2009, adding Windows 7 support for all components of the suite except for Microsoft Enterprise Desktop Virtualization (MED-V). That support will come in the first quarter of 2010 with MED-V 1.1 Service Pack 1, Schuster said.

Credit-card security standards questioned, survey says

Most IT security professionals who must comply with the industry standards to protect credit card data think those standards have no impact at all on actual security, according to new study by Ponemon Institute. 10 of the Worst Moments in Network Security History And they say the main benefit of meeting the standards isn't better security, its better relationships with business partners who regard payment card industry (PCI) compliance as an easy-to-read sign that businesses are paying attention to protecting the personal data of people who use credit cards, the study says. "PCI does not necessarily mean better security within the hearts and minds of respondents," says Larry Ponemon who conducted "PCI DSS Compliance Survey" for Imperva, which makes database and Web application security products. Those objectives are a list created by the Ponemon Institute as a way to make high-level comparisons of data security among different organizations. Overall, 57% of respondents feel that PCI standards have no impact on a set of 25 security objectives that they were asked about, the survey says.

The benefit of PCI compliance cited most often by the IT security pros polled was that it improves relationships with business partners, not that it made data more secure. No. 3 was that PCI compliance did improve the overall security posture of the business. That was followed closely by helping capture more IT funding for security. PCI compliance can be used as a lever to wrest IT security funding from corporate budget makers, the survey indicates. Much of this money would be spent on the same measures anyway, even if PCI compliance wasn't an issue, Ponemon says. Saying that money will help with PCI compliance is a better argument than saying it will make data safer, Ponemon says. "If you're striving just to improve security, it's hard to get the upper echelons to see the value," he says. "They are more likely to pay for PCI because it helps in working with business partners than because it's the right thing to do." On average the 560 security pros surveyed spend 35% of their IT security budgets on meeting PCI standards.

Protections dictated by PCI would be made simply because they are sound security practices. (Read a story rating apology letters from companies after a data breach.) When asked to assess the value they receive from PCI expenditures, 43% say they get what they pay for and 23% say they get more value than they pay for. In implementing the standards, respondents pick and choose what they protect. The rest, 34%, say they get less. The majority of respondents to the survey (55%) say they direct their PCI efforts toward protecting cardholder data only, with just 12% addressing security of all personal data. The most popular tool for protecting credit card data is the firewall, followed by antivirus/antimalware products and encryption of data at rest and in motion.

Just 22% say all their applications and databases are protected in accordance with PCI standards; 25% say protection of their applications isn't compliant at all. They find those four technologies to be the most cost effective as well. Other results of the survey:* The vast majority of respondents (79%) say they have suffered at least one data breach that resulted in loss or theft of credit card information.* Endpoints and wireless devices are regarded as the two weakest links in meeting PCI security, followed by paper documents and applications, the survey says.* The top three reasons for implementing security standards are to achieve an effective security posture (48%), obtaining buy-in from management (47%) and prioritizing security requirements (46%). PCI compliance most commonly falls to the CISO or the CIO on the technology side, but corporate legal departments are equal partners overall, the study finds, indicating the complex implications of compliance.

Alcatel integrating network layers for efficiency

Alcatel-Lucent on Wednesday set a course for tighter integration of the two main components of long-haul service-provider networks, saying it will help carriers streamline their infrastructure and run it more efficiently. Now, with the Converged Backbone Transformation Solution, it is leveraging its expertise in both technologies so the two can work more smoothly together and be managed more easily. The company is a major player in carrier optical transport and is gaining ground on Cisco Systems and Juniper in IP (Internet Protocol) routing, according to industry analysts.

The payoff for enterprises that rely on carriers to interconnect their offices could be both faster provisioning and lower prices, said Ray Mota of Synergy Research Group. The two domains have remained largely separate, but Alcatel said it will bring its IP and optical systems closer together, with more flexible capacity-handling and unified management. Most service-provider networks use electronic packet routers to direct Internet and private IP traffic, but also optical infrastructure to transport data over long distances. Today's IP and optical network elements effectively just hand off traffic to each other without much interaction, and they typically are managed by separate teams, said Lindsay Newell, vice president of marketing for IP at Alcatel. If you go to an optical vendor, you get an optical answer," Newell said.

His company is best equipped to make these systems work more closely together because it has experience making both parts, Newell said. "If you go to a router vendor, you get a router answer. Alcatel says it is skilled in both. Current routers from most vendors can map one router port to one wavelength of light for optical transport. One thing Alcatel aims to provide is a more granular way of feeding traffic from IP routers into optical infrastructure. Alcatel is introducing that technology, called IP over dense wave-division multiplexing, on its service routers now. Alcatel plans to offer the ability to send traffic from multiple ports or from multiple virtual LANs into a single wavelength, Newell said.

But IP over DWDM isn't ideal, because it wastes optical capacity if there isn't enough traffic from the IP port to fill the wavelength, Newell said. Carriers can use this to make more efficient use of each wavelength, so potentially they won't have to deploy or light up as many wavelengths, he said. The company will implement the capabilities using existing and emerging industry standards, adding some proprietary features of its own but keeping its products interoperable with gear from other vendors at a more basic level. This could save space and power in carrier facilities as well as money. Also through closer integration, Alcatel will allow IP routers to send traffic straight across the optical network, bypassing unnecessary IP routing along the way. At a higher level, Alcatel said it can integrate the management of both network layers because it supplies both.

This core router bypass capability will let traffic destined from, say, Los Angeles to New York go straight to its destination without going through an IP router in Chicago, Newell said. Among other things, the IP and optical management systems will know what resources are available on each and be able to communicate fault management alarms. The Converged Backbone Transformation Solution is a set of features that will roll out over time. Ultimately, the IP network elements will be able to reroute traffic if there's a failure in the optical layer, and vice versa. Immediately, Alcatel is delivering features including IP over DWDM on service routers and the initial elements of information exchange between IP and optical, such as common alarm views and fault isolation.

Later it will offer more dynamic interaction between the layers, including dynamic provisioning for failover, Newell said. Next year, the company plans to provide static provisioning for port-level and VLAN traffic grooming. The integration ultimately can save carriers at least 30 percent in capital expenditures on a network built from the ground up with the new technology, according to Newell. Many carriers are grappling with data traffic that is growing far faster than the revenue they can collect for it, and this type of streamlining approach could help them, Synergy's Mota said. Savings for carrier networks with a large amount of existing infrastructure will be more incremental, he said.

Quick actions help financial firm avoid security disaster

While most of the IT world has been spared a devastating security attack like Blaster and Sasser for the last few years, the damage wrought by all manner lesser-known computer viruses continues to inflict corporate pain. 10 of the Worst Moments in Network Security History For example, New York City-based investment firm Maxim Group, faced a security ordeal this year when a virus outbreak pummeled the company's Windows-based desktop computers and servers. "On early April 15th, a few people called to say they were having problems with their computers," relates John Michaels, CTO there in describing how the investment firm's IT staff started to get an inkling that morning that something was terribly wrong. "After looking into it, we knew something bad was happening, affecting all our users, and my servers." Malware was disabling applications by corrupting .exe files so they wouldn't open once they were closed, while also making thousands of connections to servers, saturating the network. "It damaged all the .exe files by corrupting them," says Michaels. "People were logging on and getting a blank screen." The virus was altering the registry of the computers. Maxim Group didn't have a centralized antivirus product in place, having allowed various groups to go their own way with differing products. In response, Maxim Group told the approximately 325 computer users not to shut down the computers while Michaels and his team contacted vendors for assistance.

The decision to change that practice was made on the spot. It wasn't easy. "Symantec took about three days to identify what the variant of the virus was," Michaels says. "They said they had never seen a variant of this." The virus was finally identified as a variant on "Sality," an older virus that strikes at .exe and now also will install a backdoor and Trojan. "We asked Symantec, are we the only ones telling you about this? Antimalware vendor Symantec was called in to set up a centralized antivirus server, while also attempting to analyze what the malware was and advise on clean-up. And they said 'We have 3 million infected.'"Cleaning up more than 300 virus-riddled PCs was a huge headache. In the course of beating back Sality, Michaels says he also contacted another vendor, Cymtec Systems, whose product he had demoed, to install the security vendor's Sentry gateway, which monitors traffic and bandwidth usage, enforcing Web site policies and blocking antimalware.

Symantec advised total re-imaging of the computers, which Maxim Group undertook, a process that consumed several weeks. The reason for the Sentry gateway is to prevent employees from going to "Web sites they probably shouldn't," especially as Web surfing raises the risks of malware infection, Michaels says. To this day, Michaels says he's not sure how the Sality variant got into Maxim Group's network to explode in that April 15 outbreak. "Maybe it was a Web site or a USB device, I don't know," Michaels says. But the virus outbreak also showed there was communication from the infected PCs to what might be a botnet. "They were connecting to rogue Internet sites," Michaels says, saying Sentry would help monitor for that kind of activity in the future. But on that day things changed in terms of the investment firm deciding to enforce stricter Internet usage policies. "Before this episode, we allowed social network sites, but we don't now," Michaels says. And are the old Blaster and Sasser worms that struck with such devastation over half a decade ago gone?

Social networking sites are gaining a reputation as places where malware gets distributed, and if there's no clear business reason for using them, they're put off limits. Unfortunately not, says the "Top Cyber Security Risks" report released this week by SANS Institute in collaboration with TippingPoint and Qualys. The report — which examined six months of data related to 6,000 organizations using intrusion-prevention gear and 100 million vulnerability-assessment scans on 9 million computers to get a picture of various attack types — notes "Sasser and Blaster, the infamous worms of 2003 and 2004, continue to infect many networks."

DOJ expands review of planned Microsoft-Yahoo agreement

The U.S. Department of Justice has asked Microsoft Corp. and Yahoo Inc. to hand over more information regarding their proposed search partnership. Nina Blackwell, a spokeswoman for Yahoo, said both companies are cooperating with federal regulators. "[We] firmly believe that the information [we] will be providing will confirm that this deal is not only good for both companies, but it is also good for advertisers, good for publishers, and good for consumers," she added. A Microsoft spokesman confirmed in an e-mail to Computerworld today that the DOJ requested additional information, but added that it came as no surprise. "As expected, we received additional request for information about the agreement earlier this week," wrote the spokesman, Jack Evans. "When the deal was announced, we said we anticipated a close review of the agreement given its scope, and we continue to be hopeful that it will close early next year." Evans declined to disclose exactly what information the DOJ is looking for.

Microsoft and Yahoo announced late in July that they had finalized negotiations on a deal that will have Microsoft's Bing search engine powering Yahoo's sites, while Yahoo sells premium search advertising services for both companies. Microsoft officials contend that the deal with Yahoo will improve competition in the search market. The partnership, which was a year-and-a-half in the making , is aimed at enabling the companies to take on search behemoth Google as a united force. Matthew Cantor, a partner at Constantine Cannon LLP in New York and an experienced antitrust litigator, disagrees. He argues that since Yahoo will cease being a competitor in the search market, the DOJ is likely to say the Microsoft/Yahoo partnership is anticompetitive . In an interview today, Cantor applauded the DOJ's request for more information. "Most deals clear without a request for additional information.

Cantor said last month that when Yahoo's own search tool disappears, only two major search engines will remain - Google and Microsoft's Bing. This is not run-of-the-mill," said Cantor. "The government believes there are potential antitrust concerns raised here. Nonetheless, Blackwell told Computerworld that Yahoo is still hopeful the deal will close early next year. They would only request additional information if there was some kind of presumption that the deal will cause antitrust effects." Cantor added that he thinks it could take months for Microsoft and Yahoo to pull this new information together, perhaps until the end of this year.

Debate rages: Is Cisco a better value over 3Com, HP?

By the numbers, IT professionals buy more gear from Cisco than they do from either 3Com or HP, but its obvious by the scores of comments generated by a recent Network World article comparing the vendors, they still like to rail against the network giant and its policies.

"I see new products from 3COM, HP, Juniper, etc. as being comparable to the Cisco offering," one IT pro says, "but Cisco just keeps trudging ahead with some pretty impressive market numbers. What makes Cisco so appealing?"

Review: 10Gig Ethernet access switch shootout

Another reader responded with the theory that Cisco puts the hammer down on its resellers that try to push someone else's gear, and that customers go along with their resellers. Pervasive, though, is the Cisco cachet, which one reader says is perpetuated by Cisco resellers. "There are several aspects at play here with the "Cisco Allure" however it mostly has to do with the reseller that the end user aligns themselves with," the commenter says. "It is quite typical for a company to see a particular reseller as their 'trusted adviser' and do whatever they tell them."

Training needed to run and maintain Cisco gear was a sour note among many readers. "Find a Cisco engineer and spend all your time trying to get them to be effective on just one product line," one wrote. "This tends to drive up TCO with the need for specialized talent, not reduce it."

What several readers would rather see is someone versed in the basics of networking, not the specifics of Cisco gear. "Either they know how IP and Ethernet switching works or they don't," one reader wrote. "Or do they just know how to cut and paste from the Cisco website? When I hire people they need to have an open mind, know how IP and Ethernet switching works and a good ability to read."

One IT pro said the problem is not unique to Cisco because each vendor implements technology with its own quirks. "Some amount of retraining and learning curve is inevitable when moving from one vendor to another in order to become proficient in configuration and the use of debugging/troubleshooting tools," the IT pro wrote. "The protocols may be the same, but there can be vast differences in how you enable them with different vendors."

Each of the vendors had loyalists among the readers. One HP user says he's tried Cisco gear but sticks with HP. "We have looked a Cisco switches several times. Cisco even offered to price match HP a couple of times," the reader says. "But each time we go back to HP switches. They're solid, dependable, and full-featured. I've had one HP switch/hub die in 18 years. The reliability of HP can't be beat."

Another IT veteran says there is a tradeoff in quality picking HP over Cisco: "The value debate is clearly subjective - some people buy their clothes at WalMart, and it shows. I'll gladly pay more for a quality product that lasts." To which another reader responds: "True that. HP has a background in engineering while Cisco is an acquisition company so that makes Cisco the Walmart of networking."

Huawei and its H3C joint venture with 3Com has some fans among commenters, with one claiming it offers a complete portfolio, simple management tools and low power use. But others were harsh toward the company and its strong ties to China.

"R&D in China means 'Reverse Engineering'. No original design will come from there. Huawei is using 3Com to push their low quality and cheap products in North America," one IT pro says. But that comment was countered with this: "So, how come that a lot of the European Telecoms Carriers use Huawei? How come that large enterprises (SNCF, Israeli government, PSA, etc., etc.) have moved to H3C?"

Also an issue was the Cisco 2003 lawsuit against Huawei charging that the company unlawfully copied Cisco's IOS for Huawei products. The suit was dropped 18 months later when it seemed that rogue individuals at Huawei were misappropriating the code, not that the company authorized it as a policy. "So what you are saying," one reader quipped, "is that you get the same switch but for a much lower price, looks like an easy choice for me!"

Juniper should not be left out of the debate when weighing Cisco against other switch vendors. "The [Juniper EX switch] product range is excellent with a stronger feature set compared to the typical Cisco products," one IT professional writes.

"The HP and 3COM alternatives cut it if you want basic switching but when you push them they really start to fall apart."