Spyware-killing Vista could take out rivals

There's a software product coming that has the potential to demote spyware from a security priority to an afterthought: Windows Vista.

Spyware has become a serious security problem for users of Microsoft's operating system over the past years, giving rise to a host of third-party tools to fight the insidious software. But perhaps the best defensive program has yet to ship, some analysts believe.

Microsoft later this year plans to release Windows Vista, the long-awaited successor to Windows XP. The operating system is being designed to shut the door on spyware. It will introduce important changes at the heart of the operating system, as well as to Internet Explorer, and include Windows Defender, an anti-spyware tool.

"The spyware threat will definitely shrink or shrivel" as Vista gets adopted, said John Pescatore, an analyst with Gartner. "We got a handle on spam. It still gets through, but it is such a small percentage now, we know how to deal with what gets through. That same thing will happen to spyware. It will be under control."

While Microsoft was working on Vista, spyware grew into a security nightmare. Experts believe the malicious software, which pops up ads on screens or spies on PC users, has been surreptitiously put on more than three-quarters of PCs. In an FBI survey published earlier this year, 80 percent of businesses reported spyware trouble, making it the most common security woe after viruses, worms and Trojan horses.

Every new version of Windows offers some security improvements, but Vista more so, said Rob Enderle, an analyst with the Enderle Group. "Vista, because it was pretty much conceived during the toughest times for Microsoft with regards to malicious software, has the most protection in it compared to any of their platforms," he said.

Spyware and its less-noxious cousin adware are widely despised for their sneaky distribution tactics, unauthorised data gathering and slowing of PCs. The unwanted software does not typically land on a computer the way a virus or a worm does. Instead, it creeps onto a system by tricking the user into clicking on a malicious link on a Web site or in an instant message. Alternatively, the distributor may secretly bundle it with an innocuous application that the user does want, such as a free application for file sharing.

Though spyware has been able to haunt users of XP, it won't be as easy for miscreants to get their malicious software onto machines that run Vista, said Austin Wilson, a director in the Windows Client group at Microsoft.

"We have taken out a significant number of the attack vectors that spyware authors use today," said Austin Wilson, a director in the Windows Client group at Microsoft. "We're not saying that spyware will be gone because of Windows Vista. We do think we will make a significant impact."

Microsoft is taking a multipronged approach to fight spyware. Unlike XP, Vista will run by default with fewer user privileges. People will have to invoke full, "administrator," privileges to perform tasks such as installing an application.

Also, Internet Explorer 7, included with Vista, will prevent silent installs of malicious code by stopping the browser from writing data anywhere except in a temporary files folder without first seeking permission. Lastly, Windows Defender will clean up any infections that do make it through.

"It is three layers of protection," Wilson said.

While this may be good news for buyers of Vista, it is not for anyone who makes a living from selling anti-spyware software. The worldwide market has boomed recently, reaching US$97 million in revenue in 2004, up 240.4 percent from a year earlier, according to IDC. However, companies such as Webroot Software and Sunbelt Software are in for tough times, analysts said.

"The aftermarket for Windows anti-spyware is going to dry up almost completely," said Yankee Group analyst Andrew Jaquith. "Windows Defender is going to become the default anti-spyware engine, certainly for most consumers that have Vista machines."

Gartner's Pescatore agreed. "Integrating Windows Defender into Windows Vista is sort of the last nail into the standalone anti-spyware coffin," he said.

But the anti-spyware market won't disappear overnight. Vista will ship at the end of 2006, and users aren't likely to instantly buy a new PC or upgrade. "You will have a two-to-three-year window before Vista has a major impact on anti-spyware," Pescatore said.

Microsoft is also making security moves outside the anti-spyware space. The Redmond, Washington, company is readying a consumer antivirus product called Windows Live OneCare and enterprise software called Microsoft Client Protection. "The Windows security aftermarket has become too large for Microsoft to ignore it," Jaquith said.

Consumers and small businesses will get their anti-spyware protection mostly from Microsoft and may also opt for the company's antivirus product, analysts predicted. However, larger organisations will look to their trusted antivirus software makers, such as Symantec, McAfee and Trend Micro, for protection, they said.

But not everyone agrees that Vista can make spyware disappear or that its arrival spells the end of the anti-spyware industry.

"I think all of these operating system enhancements are going to be helpful in the battle on spyware. I don't think there is a silver bullet, though," said David Moll, chief executive officer of Webroot, the largest standalone anti-spyware seller.

Vista will have an impact, but it won't shut the door on spyware, agreed Alex Eckelberry, president of Sunbelt Software, maker of the CounterSpy tools. There's a huge economic benefit for spyware creators and hackers to continue their practices, he said.

If Vista and Defender don't completely eliminate the threat, then there will always be a market for third party solutions, said Chris Swenson, an analyst at The NPD Group.

"I think Microsoft's new products look excellent, and they will significantly reduce the threat," Swenson said. "But...I'm more of a sceptic about their ability to prevent every single instance of spyware from infiltrating PCs."

The purveyors of spyware will respond to Windows Vista with more sophisticated attacks, Moll said -- and that means people will have to be as vigilant in dealing with spyware in the Windows Vista world of the future as they are today.

"It is going to remove the low-hanging fruit. It is going to make it that much harder for dumb spyware to work," Gartner's Pescatore said. "What it will really do is start forcing the threats further up the food chain," he added. Attackers will have to get smarter in fooling the user -- what's called social engineering.

Microsoft's Wilson predicts a rise in phishing attacks, which seek to dupe users into giving up personal information by using fraudulent e-mail messages and Web sites. "The profit motive is always there. They are looking for the easiest way they can trick people to getting things on their machines," he said. "We have seen a transition from spyware to phishing."

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

The HDMI cable ripoff and why retail is really dying http://t.co/eFT7zEW7

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/IUysbyKf

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/V7vL5QB9

Dazza - lets make a deal. I won't call you a troll if you don't call me a sheep. Anyway let's get some perspective on this. You cannot ...

59 minutes ago by dickster on NBN users opt for 100Mbps

Further to the comments from James, I can add that most botnets will test the bandwidth of the end host before they take control of that ...

1 hour ago by patrickbutler on National Botnet Network coming: Earthwave

ZDNet reports Microsoft launches its own social service http://t.co/VJS5BkwF

by http://t.co/vmlLt4bh: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia P... http://t.co/4bfDRXo4

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/CtNlVWN7

Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia Pacific, shares some of h... http://t.co/ZxjpmqiM

Seriously, every business is slow to start off, that's common sense. But the NBN is attempting to replace an incumbent monopoly. So wait ...

1 hour ago by Beta on NBN users opt for 100Mbps

Microsoft is serious about open source: 10 proof points http://t.co/iv2ji74q

Ok, for all of those that are complaining about price lets look at it this way, Australia started using copper wiring back in the late 18...

1 hour ago by Kalthae on NBN users opt for 100Mbps

Ah so you have an anti-NBN website then...ok!

1 hour ago by Beta on NBN users opt for 100Mbps

@ Doubt, I think you should be a policy advisor to Tony Abbott. I can see it now pre-election 2013, Press Club - Journo: Mr Abbott, yo...

1 hour ago by Beta on NBN users opt for 100Mbps

@beachking, that's why the first N in NBN is of importance, because while this may come as a shock, the universe does not revolve around ...

1 hour ago by Beta on NBN users opt for 100Mbps

Err the words give it away "world class"... it's not Huawei class, China class or India class, it's world class! World Class from Farlex...

1 hour ago by Beta on NBN users opt for 100Mbps

How many billions of dollars have they spent for these 3500 connections? Whats the return in profit? How long are they going to keep subs...

1 hour ago by Dazza152 on NBN users opt for 100Mbps

Accelerator targets 'clean-tech' start-ups http://t.co/p9VPCzCa

RT @vexnews: NBN users opt for highest speed plan http://t.co/8eUvvVvQ

OutsourcingLive: #Outsourcing is still on the rise http://t.co/5U6R431A ^NK http://t.co/B8HtVvAD

In Facebook IPO fiasco the 'smart money' got burnt - ZDNet (blog): TIMEIn Facebook IPO fiasco the 'smart money' ... http://t.co/3iD1g6lG

So thats $2000 per premise just to replace the NTU...wow. Somebody is making a fortune on that work

2 hours ago by Coops1 on NBN's Tassie upgrade to cost $1.3 million

But will we actually get 100mps Internet speeds often overstated RT@vexnews: NBN users opt for highest speed plan http://t.co/1uTiHXrd

RT @JamesVickery: NBN users opt for 100Mbps http://t.co/atP8fi1L

I guess fixed connections are not for the free spirits amongst us. Long live choice, it seems prepaid wireless for you is the go.

2 hours ago by Doubt on NBN users opt for 100Mbps

more cloud TV recording services tumble in wake of court victory for copyright monopolies - http://t.co/FEWm6Z7Y

Mike Quigley | Only 3500 NBN customers with active fibre services to date http://t.co/6eB525Ur via #auspol NBN very expensive failure

The take up figures are all a bit meaningless until NBN hits the big population centres.

2 hours ago by Doubt on NBN users opt for 100Mbps

Allow me to take your money if you are keen to give it away, a Western Union transfer is ok.

2 hours ago by Doubt on NBN users opt for 100Mbps

NBN users opt for highest speed plan http://t.co/8eUvvVvQ

The choice of connecting to fibre rests entirely in your hands, if you are so desperate to have a fibre connection, pack your bags and mo...

2 hours ago by Doubt on NBN users opt for 100Mbps

Funny argument the term "world class" , what does that mean when considering data networks. If NBN rolled out fibre but use Huawei equipm...

2 hours ago by Doubt on NBN users opt for 100Mbps

http://t.co/ZWOl5p8F

I agree it would (will) be nice to have a common platform. People are funny creatures and like to have choice. Some may feel they get bet...

2 hours ago by Doubt on NBN users opt for 100Mbps

Mr Quigley has to be politically aware, as does any CEO.

2 hours ago by Doubt on NBN users opt for 100Mbps

In essence the waiver of charges by NBN appears to be a subsidy to smaller or more remote areas. Idea! Setup a number of smaller service ...

2 hours ago by Doubt on NBN users opt for 100Mbps

http://t.co/JWINuozI

Remember, these are the high speeds that Mr Abbott believes you guys don't want.... http://t.co/Jtqnwb2M

Three tips for businesses to support connected customers http://t.co/to8fCl1N via @zite

Which Windows will make for a better tablet? http://t.co/wxr95itf via @zite

Cloud based TV recording services in Australia shutdown after negative ruling. http://t.co/9zlnSVJd

AD on azure, is all about APPS .. http://t.co/EMdsrHZF

children porn video

5 hours ago by nmhcqogu on Google to encrypt searches by default

#Biometric bugs too dangerous for public? http://t.co/IdIBiRUJ (via @zdnetau by @mukimu)

#Outsourcing is still on the rise http://t.co/ANaHIofI ^NK

#NBN users opt for 100Mbps
http://t.co/SmMFpItP #auspol

IBM's Intelligent Clusters - an old idea done well: IBM's pre-configured, pre-tested clusters take the uncertain... http://t.co/Z64vEYiL

33 must-have business and marketing iPad apps from Docstoc http://t.co/Bu7BhFRv

when and if NBN gets to Cairns FNQ, it is going to be a big white elephant tooo costly and to much of a monthly commitment. I am qui...

7 hours ago by beachking on NBN users opt for 100Mbps

Dell Secureworks talks with ZDNet about Android's biggest #security flaws - http://t.co/08kaKg6R #infosec RT @dellenterprise

33 must-have business and marketing iPad apps from Docstoc http://t.co/0XqdwbAN

33 must-have business and marketing iPad apps from Docstoc http://t.co/pf1m0CNP

RT @sergicles: Google vs Oracle, that was a quick one. http://t.co/AFIEf8vG Oracle trolling pw4ned

RT @MobiMediaMarket: Mobile Devices Were Wrecking My Health. Here's How I Plan to Change That. - ZDNet (blog) http://t.co/zMWCOZOr #mobiledevices

Mobile Devices Were Wrecking My Health. Here's How I Plan to Change That. - ZDNet (blog) http://t.co/zMWCOZOr #mobiledevices

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar