On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

May 20th, 2008

Puncturing the myth of the invulnerable OS

Posted by Ed Bott @ 2:37 pm

Categories: Security, Windows Vista

Tags: Operating System, PC Tools, Microsoft Windows Vista, Malware, Spyware, Spyware, Adware & Malware, Cyberthreats, Microsoft Windows Vista (Longhorn), Viruses And Worms, Security

I keep trying to come up with explanations for why rational technical publications continue to amplify the nonsensical research coming out of Australian security vendor PC Tools in the past few weeks.

Jedi mind tricks? Post-hypnotic suggestions embedded in web pages served from the Southern Hemisphere? Sunspots? There’s certainly no rational explanation for anyone with a lick of security experience to take this stuff seriously.

But here’s Information Week, with its scare headline “Windows Vista More Vulnerable To Malware Than Windows 2000.” There’s a pro forma note in the second graf that PC Tools “has a financial interest in the vulnerability of Microsoft’s software,” but otherwise it’s just a rehash of the press release. InfoWorld picked up the same release and reprinted it practically verbatim. And today my normally super-smart ZDNet colleague Adrian Kingsley-Hughes took the bait on a new PC Tools release, starting his post Does running Vista make you feel safe from malware? with this line:

Another day, another report casts doubt on Vista’s immunity to malware.

That, of course, echoes the title of (and links directly to) the press release from PC Tools. (And with the exception of press releases from companies trying to sell security software, where are those other reports, anyway?) Adrian goes on to catalog the security improvements that distinguish Vista from XP but then says, “despite all this I don’t subscribe to the idea that Vista is somehow invulnerable to malware.”

So, what operating system is invulnerable to malware? When did that become the criterion for success in security?

If I send you an e-mail with the file HotBabes.exe attached to it, you have to decide whether to run it or not. If you are deluded enough to double-click that icon, and you are running Windows Vista, several things are going to happen:

  • If you are running under a standard user account set up by your parent or your IT department, you will be unable to install that program until you find adult supervision and convince them to enter the administrator password. Good luck with that.
  • If you are the administrator, you will see a UAC prompt that will provide you with some information placed there by the  creator of the program, which might or might not help you decide whether it’s safe to install. If the program is digitally signed, you will be able to get a third-party service to confirm the identity of the person or organization that signed the program.
  • Ultimately, you will decide to click Continue or Cancel. If the file I sent you was a Trojan or virus and you say Continue, you lose.

It’s as simple as that. If you’re the admin and you tell the OS you want to run an executable program, the OS has to respect your judgment and allow it. It has no way of knowing whether a program is good or evil, well written or buggy, or whether it will cause your system to lock up with a STOP error. As the boss, you get to make the decision.

And that’s the way it should be. Do you want an OS that refuses to allow you to install a remote access program so you can do online help or access your home PC from the road? Do you want Microsoft or Apple or your favorite Linux distro to say, “I’m sorry, Dave, I can’t allow that,” when you install a password cracking tool to recover the information in a lost file? Of course not. But I’ve seen antivirus programs squawk for years over some of my most useful security tools in these categories, claiming they are threats and offering to neuter them for me. No thanks.

If you want help analyzing the actual contents of a program you’re thinking of installing, you need additional software that can crack open the executable and compare its code or behavior to other known species of malware. In other words, you want antivirus software. That’s true of every OS platform.

The information that PC Tools provides in its press release is, to put it charitably, sketchy. The release says, for example, that “approximately 121,000 pieces of malware were detected on approximately 58,000 unique Vista machines in the ThreatFire community.” (ThreatFire is the name of the anti-malware software PC Tools is pitching.) A footnote points to a Data Summary Sheet, but it, unfortunately, is unlinked and unavailable. (I’ve asked PC Tools to send me this data sheet.) Without knowing the sample size or how that malware was installed, it’s impossible to come to any valid conclusions.

And what does the company define as “malware,” anyway? The release says “17% of all threats found on Vista machines involved in the research were Trojans, while worms accounted for 5%, spyware for 3% and viruses for 2%.” That pretty much encompasses every category of true malware that I can think of (and it includes all the big threats on this highly regarded list from Kaspersky). So, what makes up the other 73%? Adware? Browser toolbars? Tracking cookies? Without those details, there’s no way to know, but how dangerous can a threat be that isn’t classed as a virus, worm, Trojan, or spyware program?

Update 20-May, 745PM PDT: A representative of PC Tools replied to my request for additional information with an e-mail message that includes the one-page data sheet and confirms that the remaining 73% of “threats” all fall into the category of adware. Examples include “PuA.Adware.SweetBar, Adware.HotBar, PuA.Adware.StarBar, PuA.Adware.SmartShopper, PuA.Adware.Rotator, and PuA.Adware.ALot.”

Meanwhile, I continue to be impressed by the fact that my phone is not ringing with friends, family members, and clients looking to clean up virus or spyware infestations on their Vista-based PCs. I’m not alone, either. My colleague Dwight Silverman (who certainly can’t be characterized as a Vista fanatic) wrote in March:

I have yet to see a Windows Vista system infected with spyware or a virus — nor have I heard from any readers who have experienced this.

That’s an echo of what Dwight noted last fall when he and I had a similar conversation:

I get a lot of cries for help from Windows users whose machines have been infected with spyware, but all of them come from XP users. Since Vista’s release, I haven’t heard from one Vista user with the same problem, and a scan of Jay Lee’s HelpLine e-mail (yes, I have access to it) shows a similar pattern.

Is Vista significantly more secure than XP? Unquestionably. Is it invulnerable to malware? Absolutely not. Will Windows or any computer operating system ever be immune to break-ins and scams that involve social engineering? Sadly, as long as dishonest human beings exist, the answer is no.

Ed BottEd Bott is an award-winning technology writer with more than two decades' experience writing for mainstream media outlets and online publications. See his full profile and disclosure of his industry affiliations.

Email Ed Bott

Subscribe to Ed Bott's Microsoft Report via Email alerts or RSS.

  • Talkback
  • Most Recent of 233 Talkback(s)
Thanks. Pshaw on Adrian then. (NT)
sad (Read the rest)
Posted by: Mike Hunt Posted on: 06/03/08 You are currently: a Guest | | Terms of Use
Well ...  MisterMiester | 05/20/08
That's not true  aka_tripleB@... | 05/23/08
And furthermore  Ed BottZDNet Moderator | 05/23/08
Short term workaround  grail@... | 05/25/08
Oh, please  Ed BottZDNet Moderator | 05/25/08
" Well...  vizenos | 05/26/08
Invulnerable homo sapiens = user error  klumper | 05/20/08
OK, that is most of it.  Sagax- | 05/25/08
UAC Security Hole  chessmen | 05/20/08
Give them some credit  itpro_z | 05/20/08
Hope Springs Eternal  chessmen | 05/21/08
Did I say that?  itpro_z | 05/21/08
How do you know all this?  hasta la Vista, bah-bie | 05/22/08
Think of it as evolution in action....  vizenos | 05/26/08
what I hear from you is far more typical  marks055@... | 05/21/08
That's not what he's suggesting  brad@... | 05/22/08
Backward compatibility  craig.soderland@... | 05/22/08
Couldn't agree more  ghost_ghost | 05/23/08
Why not?  vizenos | 05/26/08
What your saying about Windows  alaniane@... | 05/22/08
It doesn't matter where it comes from  Mikael_z | 05/22/08
No, he was saying Vista  alaniane@... | 05/22/08
Real consequences of poor...  arminw | 05/23/08
The problem with your  alaniane@... | 05/23/08
Okay, if that;s what you really want happy....  vizenos | 05/26/08
Give them some credit  vizenos | 05/26/08
right on the head  cwhull | 05/27/08
Did you copy/paste this  soonerproud | 05/20/08
Same Story, Same Comment  chessmen | 05/20/08
Same story?  Ed BottZDNet Moderator | 05/20/08
re: Same story?  M.R. Kennedy | 05/20/08
Are we disagreeing?  Adrian Kingsley-HughesZDNet Moderator | 05/21/08
Ed Bott and Adrian Kinglsley-Hughes Must Be Disagreeing  chessmen | 05/21/08
You fall short, Adrian  Ole Man | 05/21/08
Ed's books are great resources  BillDem | 05/22/08
"He just tells it like it is"  Ole Man | 05/22/08
Everyone has biases, Ole Man  Ed BottZDNet Moderator | 05/23/08
That's right, Ed  Ole Man | 05/24/08
I think it's more this  klumper | 05/21/08
I came across a Windows Vista infected  TristanGrimaux | 05/22/08
Microsoft did not create Basic  alaniane@... | 05/22/08
Only if  rtk | 05/22/08
Answer to rtk  TristanGrimaux | 05/22/08
To be fair Basic programs  alaniane@... | 05/23/08
So because you disagree,  bmerc | 05/21/08
Correct  chessmen | 05/21/08
Ah so you agree with me completely  bmerc | 05/22/08
Same Story, Different Point Of View  chessmen | 05/21/08
He's not all there...I wouldn't worry...nt  ItsTheBottomLine | 05/22/08
Disagree  Jhaks | 05/21/08
Good Argument  chessmen | 05/21/08
Very well put...  ItsTheBottomLine | 05/22/08
It can...  ItsTheBottomLine | 05/22/08
Wrong.  dwest_z | 05/22/08
What are you talking about........  willpd13 | 05/21/08
Microsoft Accomplishes Goal  chessmen | 05/21/08
Only if they are totally incompetent - and guess what  ItsTheBottomLine | 05/22/08
Personally...  JCitizen | 05/22/08
again.  rtk | 05/22/08
Firewalls are good at blocking  alaniane@... | 05/23/08
As I understand it...  JCitizen | 05/26/08
Why does a program need...  arminw | 05/23/08
You're missing the point of UAC  Kerry from BC | 05/21/08
According to Microsoft  Ole Man | 05/21/08
Which is another way of saying the same thing  Kerry from BC | 05/21/08
you are quite the spinmiester yourself and unlike  marks055@... | 05/21/08
Looks to me like electronista.com is the spinmiester  Ole Man | 05/22/08
Can be turned off, actually  CobraA1 | 05/22/08
Is Vista more secure?  itpro_z | 05/20/08
Giving a user the freedom....  arminw | 05/23/08
Actually, it's even more basic than that  alaniane@... | 05/23/08
RE: Puncturing the myth of the invulnerable OS  martin23 | 05/20/08
You again  Ed BottZDNet Moderator | 05/20/08
Reasons to be rude, part 3  martin23 | 05/20/08
so selective in your (Ed's) choice of facts and the slant you give them  Ole Man | 05/21/08
Actually.  Bozzer | 05/22/08
Stories are BS based on what???  jasonp@... | 05/21/08
Must be tough  nizuse | 05/21/08
Partisan and then some  klumper | 05/20/08
Oh to be partisan  martin23 | 05/21/08
And you are the voice of impartiality?  soonerproud | 05/20/08
@martin23  M.R. Kennedy | 05/20/08
oh a troll  martin23 | 05/21/08
Yes, a troll  M.R. Kennedy | 05/21/08
Not A Troll  chessmen | 05/21/08
re: Not a Troll  M.R. Kennedy | 05/21/08
An answer to your question  martin23 | 05/21/08
You don't really need an answer, do you?  Ole Man | 05/21/08
yes a troll  SO.CAL Guy | 05/21/08
Telling someone who has purchased a product  Ole Man | 05/21/08
another clairvoyant  martin23 | 05/21/08
@martin23: Criticism of MS is fine. FUD is not.  ye | 05/21/08
Bravo  marks055@... | 05/22/08
Question Time  M.R. Kennedy | 05/21/08
Answer time  martin23 | 05/22/08
Martin. Wrong. Again.  Ed BottZDNet Moderator | 05/22/08
Wrong again ???  martin23 | 05/22/08
I guess Martin is never wrong  Ed BottZDNet Moderator | 05/22/08
Just as a reminder...  Ed BottZDNet Moderator | 05/22/08
I'm always wrong  martin23 | 05/23/08
You actually find that strange?  bmerc | 05/21/08
re: You actually find that strange?  M.R. Kennedy | 05/21/08
bmerc Is Right  chessmen | 05/21/08
@chessmen  M.R. Kennedy | 05/21/08
RE: Puncturing the myth of the invulnerable OS  Donald75 | 05/20/08
Trojan without admin privileges?  Ed BottZDNet Moderator | 05/20/08
simple example  Donald75 | 05/20/08
Right, but...  Ed BottZDNet Moderator | 05/20/08
Data is more valuable  Donald75 | 05/20/08
The three B's  klumper | 05/20/08
Even with daily backups  Michael Kelly | 05/21/08
Backup no help  frgough | 05/21/08
Backup no help?  tim@... | 05/21/08
Backup no help  frgough | 05/21/08
I don't have to make backup copies...  jasonp@... | 05/21/08
Klumper Is Right, Backups Are Essential!  chessmen | 05/21/08
Back to ABCs  klumper | 05/21/08
Aunt Tilly is not a Lan Manager  Donald75 | 05/21/08
It applies to one and all  klumper | 05/21/08
To add to your backups  alaniane@... | 05/22/08
RE: Puncturing the myth of the invulnerable OS  phil321 | 05/20/08
Adrian Kingsley-Hughes Is Super Smart  chessmen | 05/21/08
Whoa  klumper | 05/21/08
RE: Puncturing the myth of the invulnerable OS  Donald75 | 05/20/08
Double Standards  soonerproud | 05/20/08
re: Double Standards  Badgered | 05/21/08
re: Double Standars  chessmen | 05/21/08
Enough with the "Vista is slow" dead horse already.  ye | 05/21/08
That Dead Horse Looks Very Spry!  chessmen | 05/21/08
Note my use of the word "recently". All of those links are...  ye | 05/21/08
Has Vista Been Re-Written In the Last 6 Months?  chessmen | 05/21/08
@chessmen: Not that I'm aware of. However things like drivers have...  ye | 05/21/08
Yes it has changed:  gtg781w | 05/21/08
Is Vista slow?  deowll | 05/22/08
I partially agree  Badgered | 05/21/08
re: chessman on Double Standard - I have to disagree...  ItsTheBottomLine | 05/22/08
True, a double standard  Richard Flude | 05/21/08
Ed, please forward HotBabes.exe to me  klumper | 05/21/08
Will do...  Ed BottZDNet Moderator | 05/21/08
Thanks. wink I lose. (nt)  klumper | 05/21/08
Anything to help a reader?  nizuse | 05/21/08
Helps plenty - beyond HotBabes too  klumper | 05/21/08
NICE JOB! Well Said....but you forgot old chess"child"..  ItsTheBottomLine | 05/22/08
More secure = Meaningless  jasonp@... | 05/21/08
More secure = Meaningless  deowll | 05/22/08
Our hero, the debunker  Ole Man | 05/21/08
re: Our hero, the debunker  chessmen | 05/21/08
I know Ed's technical prowess is excellent, superb, even  Ole Man | 05/21/08
Mark Twain Quote  chessmen | 05/21/08
You've got the picture  Ole Man | 05/21/08
Poor Drivers an issue  deowll | 05/22/08
Congratulations  notsofast | 05/22/08
It's not an excuse, it's a business decision  alaniane@... | 05/23/08
RE: Puncturing the myth of the invulnerable OS  aureolin@... | 05/21/08
Almost as bad  Ole Man | 05/21/08
the OS has to respect your judgment and allow it  Henry Miller | 05/21/08
Okay...  Jeremy W | 05/21/08
What doesn't impress me about mac users.  deowll | 05/22/08
Incorrect  dprozzo | 05/22/08
The OS should be in the CPU  BALTHOR | 05/21/08
Uh... Do you know that CPU processes instructions?  Grayson Peddie | 06/01/08
RE: Puncturing the myth of the invulnerable OS  Donald75 | 05/21/08
Good post Ed, but one correction  georgeou | 05/21/08
Sharp advice  klumper | 05/21/08
Default setting for K-Lite works best  georgeou | 05/22/08
Something says we're in agreement  klumper | 05/22/08
Still like ActiveX?  Richard Flude | 05/21/08
I can write a batch file that will nuke all your files too  georgeou | 05/22/08
...  Linux User 147560 | 05/22/08
Whenever you have system  alaniane@... | 05/22/08
not the same thing at all  jjarman | 05/22/08
ActiveX isn't the only exploit  alaniane@... | 05/22/08
Thanks George...nt  ItsTheBottomLine | 05/22/08
RE: Puncturing the myth of the invulnerable OS  Joschibaer | 05/21/08
No Myth...  mikifinaz1@... | 05/21/08
wow...  rtk | 05/21/08
RE: Puncturing the myth of the invulnerable OS  pdwarren | 05/22/08
What nonsense  gregoryk@... | 05/22/08
only a communist  Khyron | 05/22/08
Vista vs Windows 2k.  magallanes | 05/22/08
RE: Puncturing the myth of the invulnerable OS  dwurz | 05/22/08
Great Article!  Narg | 05/22/08
no, no, no...  gdstark13 | 05/22/08
What an OS ough to be like  deowll | 05/22/08
Atari 2600 is an example of your  alaniane@... | 05/23/08
RE: Atari 2600 is an example of your  gdstark13 | 05/27/08
The problem with that model isn't  alaniane@... | 05/29/08
RE: The problem with that model isn't  gdstark13 | 05/29/08
Actually, the vertical apps  alaniane@... | 05/30/08
RE: The problem with that model isn't  gdstark13 | 06/02/08
RE: Puncturing the myth of the invulnerable OS  teakilla | 05/22/08
i dont have vista yet and dont know if i want one  deowll | 05/22/08
Absolutely true, no OS is invulnerable, however...  ron@... | 05/22/08
Your "however" is wrong  rtk | 05/22/08
RE: Puncturing the myth of the invulnerable OS  mwagner@... | 05/22/08
Some Sanity from Mr. Bott  jpr75_z | 05/22/08
Close the Safety Gap !  cquirke | 05/22/08
All OS's have malware, linux too: because a malware is a piece of code run  qmlscycrajg | 05/22/08
Huh?  6feet_ | 05/22/08
wow, you have a lot to learn, start here...  jjarman | 05/22/08
You're missing MAC/RBAC  rpmyers1 | 05/22/08
MAC/RBAC provides better security. Unfortunately...  ye | 05/22/08
You're right  rpmyers1 | 05/22/08
Vista laid low by new malware figures  n0neXn0ne | 05/22/08
Other than Windows....  epcraig | 05/22/08
Other than Windows....  deowll | 05/22/08
And this means what? (nt)  ye | 05/22/08
Malware has already been  alaniane@... | 05/23/08
Most Home and Small Office  starcannon99022@... | 05/22/08
Five years? That's all? I can boast 18 using Windows.  ye | 05/22/08
AMEN - ...  ItsTheBottomLine | 05/22/08
Humm - I have been using Windows since 3.0  ItsTheBottomLine | 05/22/08
RE: Puncturing the myth of the invulnerable OS  techfix | 05/22/08
RE: Puncturing the myth of the invulnerable OS  SirCatlord | 05/22/08
Now you've done it.  gypkap@... | 05/22/08
Check your own pipe.  rtk | 05/22/08
RE: Puncturing the myth of the invulnerable OS  FateJHedgehog@... | 05/23/08
RE: Puncturing the myth of the invulnerable OS  lennycald@... | 05/22/08
New Vulnerability Found in Chair-Computer Interface  hnkelley | 05/22/08
Re: New Vulnerability Found in Chair-Computer Interface  FateJHedgehog@... | 05/23/08
White is the new black?  FateJHedgehog@... | 05/23/08
RE: o you want an OS that refuses to allow you to install a remote app.?  Samun56 | 05/23/08
OpenVMS -- Security is a Design Decision  rboblee@... | 05/23/08
very interesting...  Ed Lin | 05/26/08
VMS can be run on a PC with emulation  ckronenw@... | 05/30/08
RE: Puncturing the myth of the invulnerable OS  rileinc | 05/23/08
We miss our Ozone...  alexDaPez | 05/25/08
More malware resistant  jorjitop | 05/25/08
average users  rtk | 05/25/08
Whoopsy - daisy!  hasta la Vista, bah-bie | 05/28/08
RE: Puncturing the myth of the invulnerable OS  Mike Hunt | 06/03/08
From Adrian's post  Ed BottZDNet Moderator | 06/03/08
Thanks. Pshaw on Adrian then. (NT)  Mike Hunt | 06/03/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here