Page 1 of 1

Vista quite resistent to malware

Posted: 2006-12-22 09:49am
by Ace Pace
So people say.

In the mean time, Microsoft has been testing Vista's defenses to the top malware threats as reported by Sophos on November 30. The results from Microsoft's internal testing were quite promising according to Jim Allchin.

Testing showed that when using a clean install of Windows Vista with no third-party security applications installed, Vista was immune to all ten of the malware threats.

When using Outlook or third-party email applications which prevent users from running executables known to be malware threats, Vista was protected eight out of ten times. Bagle-Zip and Mydoom-O were the culprits in this test. Microsoft contends that it's not the fault of the Windows Vista operating system, but rather a function of the email program and users who open up suspicious .ZIP files and then run the executables found within.

It's interesting to note that Windows Mail, which comes standard with Vista, blocks .ZIP attachments. Microsoft's Outlook client does not do the same. Microsoft does note, however, that email clients can support .ZIP blocking via its Attachment Manager API.

Posted: 2006-12-22 10:49am
by Edward Yee
Microsoft contends that it's not the fault of the Windows Vista operating system, but rather a function of the email program and users who open up suspicious .ZIP files and then run the executables found within.
Well, relevance depends on whether Vista has to defend "itself" (the particular installation) against user stupidity, I believe...

Posted: 2006-12-22 11:02am
by Velthuijsen
Good thing that the Vista blocks current trash better then the existing Windows types in the wild. The problem is that they can't make this claim until about 5 years have passed and the crackers have used that fine toothcomb of them on the code to find new holes and see if it holds up better to that as well.

Posted: 2006-12-22 11:14am
by General Zod
It's only resistant because nobody's written anything for it yet. Wait until it's on 80% of all PCs and then come back to us.

Posted: 2006-12-22 11:15am
by aerius
So it works in controlled lab conditions on a clean install. Ok, everyone with a clean install and no 3rd party software please raise your hand. The fact that its performance is degraded by 20% with Outlook or some other 3rd party email application ain't promising, especially since they're using known threats and have zip & exe disabled. I'd hate to see what happens in the real world where it has to deal with shitloads of new malware every week, nevermind user stupidity.

Posted: 2006-12-22 11:47am
by Ace Pace
aerius wrote:So it works in controlled lab conditions on a clean install. Ok, everyone with a clean install and no 3rd party software please raise your hand. The fact that its performance is degraded by 20% with Outlook or some other 3rd party email application ain't promising, especially since they're using known threats and have zip & exe disabled. I'd hate to see what happens in the real world where it has to deal with shitloads of new malware every week, nevermind user stupidity.
Just to nitpick.
It's interesting to note that Windows Mail, which comes standard with Vista, blocks .ZIP attachments. Microsoft's Outlook client does not do the same.
Outlook dosn't have Zip disabled.