By ECT News Software Desk E-Commerce Times Part of the ECT News Network
08/16/04 3:02 PM PT
The Windows XP Service Pack 2 (SP2) update features architecture changes designed to make it harder for hackers to take over a machine remotely if they do gain access. "SP2 is somewhere between an upgrade and a whole new version of Windows," Gartner analyst Richard Stiennon told the E-Commerce Times.
While eager to take advantage of the enhanced security features of Microsoft's (Nasdaq: MSFT) long-awaited SP2 update, many corporate users of Windows XP will be cautious in activating it.
Microsoft did extensive compatibility testing aimed at ensuring SP2 would work with as many third-party applications as possible, but many network administrators plan to run the update through the paces themselves.
IBM (NYSE: IBM) has confirmed that it is telling employees to delay downloading the SP2 update until network administrators can determine potential effects on Big Blue's systems. Many other companies are expected to follow suit.
Windows XP Architecture Changes
Microsoft released the XP SP2 update, which reportedly cost $1 billion to develop, last week. The software maker expects some 100 million updates to be applied within two months. New machines loaded with the updated version of XP will be available starting next month.
While security and antispam features that block malicious code in e-mails and on Web pages have gotten most of the attention, the update also features architecture changes designed to make it harder for hackers to take over a machine remotely if they do gain access.
"SP2 is somewhere between an upgrade and a whole new version of Windows," Gartner (NYSE: IT) analyst Richard Stiennon told the E-Commerce Times. "For that reason, enterprises are going to want to carefully make sure it's going to work with all the applications they use."
Citing the security enhancements in particular -- which many believe will delay, minimize or stop many hack attacks -- Microsoft has encouraged users to activate the automatic update feature in XP, which would allow the computer to connect to a Microsoft server and download the update in full.
Conflicts in the XP Rollout
Part of the delay in releasing the software can be attributed to its failure to work well with Microsoft's own applications, including its customer relations management software. Now there are reports that other companies' software has experienced problems as well. Some versions of peer-to-peer file-sharing software are among those said to have been affected.
The enhanced security features might also cause conflicts with third-party firewalls and other security appliances. Published reports have suggested that users of Zone Alarm firewalls reported bugs after installing the update.
In most of those cases, the problem can be worked around, but it will take time, said Ken Dunham, director of malicious code intelligence for the computer security firm iDefense
"In each instance, there might be a different workaround, so it's going to take time to get them all in place," Dunham told the E-Commerce Times. "Microsoft did extensive testing, but no one is going to put such a major update onto their networks without doing their own due diligence."
Rushing the update into place would likely place a major burden on corporate help desks, which would be forced to field questions about crashing applications and other problems.
"Users will want the update because it is a security upgrade," Dunham added. "But they don't need to be the first to have it."
SP2 a Boon for Business?
Because of the possible complications, patch-management companies and third-party vendors who help companies manage their networks could see a windfall.
Joi Deaser, a spokesperson for SupportSoft, told the E-Commerce Times that her company's customers have been asking for help, with most of the concerns surrounding security and management of problems that might arise when the service pack goes live.
Foundstone Acquired by McAfee for $86 Million August 16, 2004
McAfee, today announced an agreement to acquire Foundstone, a privately held company founded in 1999. Foundstone offers a combination of enterprise software, appliances, consulting services and education to help organizations protect their assets from threats. Foundstone has a customer base of more than 400 large enterprise customers including AT&T, McKesson and Motorola.
Related Stories
AMD Pushes Security Capabilities of XP SP 2 and Athlon 64 August 09, 2004
"AMD is taking a leadership role to deliver a more secure computing experience for home and business users with the enablement of enhanced virus protection on all AMD Athlon 64 processors in the market today," said Marty Seyer, corporate vice president and general manager of the microprocessor business unit at AMD.
Microsoft Urges Update, But IBM Will Test First August 09, 2004
SP2 will not fully solve the security issues that have cost companies time and other resources, but it will make things more difficult on attackers, who have grown more cunning in their assaults on Windows. 'It doesn't mean you're not going to have a hack, but a hack delayed is often a hack thwarted,' said Yankee Group analyst Laura DiDio.
Windows Users Eagerly Await XP Service Pack 2 August 06, 2004
The security-focused Windows XP Service Pack 2 (SP2) update for Microsoft's main operating system is now only days away, Microsoft's senior product manager Matt Pilla indicated this week.
Related News Alerts
More by ECT News Software Desk
AOL Now Reachable by Desktop Linux Users August 26, 2004
"We've expressed to AOL that America Online dial-up support is the number one request we get from users and OEMs, but they have yet to release anything," said Michael Robertson, chief executive officer of Linspire. "We decided to build an open source dialer on our own so the massive AOL customer base can now use a low-cost Linux computer with their AOL accounts."
Symantec Updates Internet Security Suite August 18, 2004
Norton AntiVirus 2005's new Internet worm protection is designed to safeguard consumer and home office users from new types of fast-spreading blended Internet worms that attack computer users' systems through multiple entry points. Internet Worm Protection blocks inbound online ports to prevent the spread of threats like Sasser and Blaster that propagate through system vulnerabilities.
Microsoft Makes Move on Windows Lite Overseas August 11, 2004
The 12-month pilot program to provide personal computers running stripped-down versions of Windows XP to governments in Thailand, Malaysia and Indonesia will start in October. Microsoft isn't selling the software separately from the Asian PCs, which it expects to sell for as little as $300.