Will XP allow hackers into your fridge?

Consumer electronics makers are set to come out with devices based on Microsoft's latest operating system, but first they'll have to learn how to keep viruses out of your VCR.

Microsoft's release of a version of Windows XP that can squeeze into all sorts of devices, from slot machines to set-top boxes to cash registers, has a catch: If you're not careful, you could find that a virus has crashed your video recorder, or a hacker has invaded your refrigerator.

With Windows XP Embedded, the software company is aiming to give makers of so-called "embedded" devices -- basically, any digital device that isn't a PC -- an easy way of building machines that are compatible with the software of the PC world, while including only as much complexity as is needed. The software is to be used in cash machines from NCR, slot machines from Bally Gaming and Systems, in point-of-sale devices from Olivetti, and in a next-generation video set-top box from Fujitsu-Siemens. It will doubtless find other applications too.

But manufacturers are finding that they have to deal with the security issues inherent in the PC world. With Windows compatibility comes vulnerability to all sorts of Windows-specific attacks. "When you add functionality, these things become an issue," said Craig Robertson, business development manager with Fujitsu Siemens' broadband solutions division.

In developing Fujitsu Siemens' Activy broadband video device, the company had to deal with problems that don't come up in the design of, say, the typical DVD player. For example, the device can browse the Web, so the company had to make sure it couldn't accidentally download a virus embedded in a Web page. "You could get viruses, unless it is dealt with. You have to configure the gateway not to execute code," Robertson said. "That way, an HTML document or a Flash file could contain a virus, but it could not be executed."

Manufacturers also have the option of allowing more expandability, such as the ability to update browser software, but allowing only "signed" drivers and applications, which have been approved by Microsoft.

"There is always complexity in terms of how you set it up," said Aubrey Edwards, director of the embedded and appliance platforms group at Microsoft.

Microsoft has gained a reputation for favouring openness and functionality over security, but it is trying to correct that with newer releases of Windows. Edwards pointed out, for example, that the most recent version of the email program Outlook blocks some files by default.

Outlook is notorious for its vulnerability to virus attacks, since it allows users to easily execute programs attached to incoming messages.

Companies such as Fujitsu Siemens say they are attracted to XP Embedded because it makes it relatively quick easy to build new devices. Microsoft provides all the software they need in most cases, including hardware drivers and Internet software. XP may not be as customisable as Linux -- which gives companies open access to the source code so they can make whatever changes they like -- but devices using it are guaranteed to keep up with the latest technologies on the PC desktop, Microsoft argues. "If you use XP Embedded you don't have to be in the software maintenance business," Edwards said. "Microsoft will do that for you."

Microsoft has high hopes for XP Embedded, which follows more than two years on from its predecessor, Windows NT Embedded. NT Embedded was itself based on 18-month-old technology, having been developed from the Windows NT 4.0 desktop operating system, and Edwards says that is the main reason it did not have wide appeal.

NT Embedded lacked some basic features, such as power management and Direct X, which had already made their way into newer versions of the desktop OS, and it would not run some newer applications, such as the newer versions of Internet Explorer.

With XP, Microsoft began developing the embedded OS at the same time as the desktop version, and XP Embedded launched a month after the version for PCs. "Now it is in synch with the desktop," Edwards said.

Advertisement

Talkback 5 comments

    I don't think that I would be ...Anonymous -- 06/12/01

    I don't think that I would be unwise enough to intentionally buy a refrigerator or anything else that contained Microsoft software. More generally I would try to avoid net-enabled things because I seriously doubt whether the benefits are as great as marketing people would have us think. Were it to be the case that I had no choice but to buy a net-enabled device then I would make damn sure it wasn't connected to the Internet.

    Unfortunately it's Mr or Ms Average who doesn't understand technical things who is going to hook everything up - expecting to gain some sort of benefit - and then find that the hackers strike and mess things up. Who picks up the mess and puts things right is anyone's guess. Likely whoever does it will present an extortionate bill for their services.

    I don't see any advantage at a ...Nathar Leichoz -- 06/12/01

    I don't see any advantage at all to anyone in running Windows XP for your fridge, microwave, clock or washing machine. Wouldn't the machine run faster and more reliably if the control mechanism were simple electronic circuit boards instead of complex instruction executing machines?

    And what are the advantages of connecting your fridge to the Internet? Does my fridge have to communicate with the fridge next door? Can I send email with my fridge?

    And why Windows XP? Can I play Solitare or launch Microsoft Word from my fridge? Wouldn't a lightweight and simple processor like the Motorola HC12 be sufficient?

    hmm, Microsoft maintaining the ...Anonymous -- 07/12/01

    hmm, Microsoft maintaining the version of firmware on my refrigerator/video/home security system - that is not something that really fills me with confidence.

    leave M$ on the desktop - where (arguably) they seem able to deliver into the stifled world they have created. The sooner that paradigm is left behind the better.

    I have to vote for Sun/Jini in this sort of instance - the frigo is not all that complex (unlike Microsoft's offerings) although it would be useful to know how much beer is left!

    WIndows has bug in it on purpo ...Brian -- 11/01/02

    WIndows has bug in it on purpose so it makes it easy for NSA and other feds to get in as easy as possible thats why once the hole has been fixed the patch creates a new hole. We are not as retarded as you think Microsoft!

    RE: Zomg NSA Anonymous -- 07/07/09 (in reply to #120007876)

    "WIndows has bug in it on purpose so it makes it easy for NSA and other feds to get in as easy as possible thats why once the hole has been fixed the patch creates a new hole. We are not as retarded as you think Microsoft!"

    You're right. Be careful people, if you get one of these the NSA will know about your lactose intolerance, and that you drink west coast coolers instead of beer after a hard day at work :(

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Renai LeMay How reliable is IP telephony?
    Have you ever heard a weird kind of hissing, crackling or popping noise when calling someone on an IP telephony line? How rare is the phenomenon these days?
  • Array Forget the NBN, 100Mbps is already here
    Telstra and TransACT will shortly begin offering 100Mbps broadband to many customers. By moving early, the companies have not only raised the bar for Australia's broadband services, but thrown down a challenge to a government that now faces increased pressure to deliver the NBN as promised.
  • Array IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • More blogs »

Tags

Back to top

Featured