The Netscaping of Symantec and McAfee

Vendors Symantec and McAfee have looked into the future and don't want to become the next Netscapes.

In 1994 there was one very good Internet browser: Netscape. Created by several members of the team who gave us Mosaic, one of the first browsers, Netscape was immediately successful as a commercial enterprise. Microsoft, realising late that it had failed to seize upon this thing called the Internet, hastily created the Internet Explorer browser and began bundling it with later editions of Windows 95 and, subsequently, with all versions of Windows.

Steadily, Internet Explorer came out of nowhere to dominate the browser landscape. It did so not through innovation but by recognising that people are lazy -- IE came bundled within the OS, so no downloading was required. And as organisations worldwide adopted Windows 98 for the office, workers grew used to seeing internal Web sites developed for IE, and people simply started using IE at home. (Okay, there are many more reasons why IE ultimately beat Netscape, but bear with me...)

I mention Netscape because, if you believe Symantec and McAfee, a similar situation is about to unfold within the security industry. Microsoft, again recognising late that it had failed to seize upon this thing called security, is now about to bundle its own security solutions within Windows Vista and further enforce new security policies that lock out some third-party security solutions altogether.

Vendors Symantec and McAfee have looked into the future and realised that people may one day speak of them in the way that we now speak reverently of the early builds of Netscape. This time, history's on their side; court cases and commissions have found Microsoft guilty of antitrust violations, and the security vendors are now using these to argue their point. Unfortunately for Symantec and McAfee, time may have already run out; Microsoft is ready to ship Vista to manufacturers within the next few weeks.

Petitioning the EU
In recent weeks, vendors Symantec and McAfee have gone public with what they've been saying in private for months: that Microsoft deliberately withheld information about its new security features to put the vendors at a disadvantage. In a recent full-page ad in the Financial Times, McAfee laid out its specific complaints. Last week, representatives of both Symantec and McAfee were in Europe to argue their cases in person.

In recent weeks, vendors Symantec and McAfee have gone public with what they've been saying in private for months: that Microsoft deliberately withheld information about its new security features to put the vendors at a disadvantage.

Why Europe? The historic US antitrust decision against Microsoft in 2000 was largely watered down by a 2004 Justice Department final settlement that did not break up the company (as originally requested) but did ask that Microsoft make the APIs (Application Programming Interface) for its Internet Explorer browser available to rivals. By then, Netscape had already been sold to AOL and its team of programmers more or less gutted.

Thus, the EU is perceived to be a much friendlier environment for security vendors. In Europe now, Microsoft is battling the EU commission empowered to monitor the company's current activities. The EU commission says that Microsoft needs to address some 79 questions the commission has regarding Windows Vista, but Microsoft claims it needs more specifics from the commission before it can answer -- likely a stalling tactic. The EU has already slapped Microsoft with a US$375 million fine for not following its historic 2004 antitrust ruling regarding Windows XP. Symantec and McAfee are hoping that the EU sides with them on Windows Vista.

Windows Defender
As recently as last week, McAfee and Symantec said that they haven't received the APIs for Windows Defender, Microsoft's free antispyware application. At issue here is whether Symantec and McAfee can turn off Windows Defender in favour of their own antispyware technology. I don't really see a problem here because, while there is no agreement among the security vendors as to what is and is not spyware, I recommend having at least two antispyware applications running on your PC, one being the free version of Windows Defender. But the issue is larger than this single application.

Symantec privately alleges that Microsoft is with holding API information to delay its own Release to Manufacture versions of their software. If Microsoft ships Vista code to hardware vendors at the end of November, then Symantec and others must have their own Vista-ready security products ready to ship to their OEM hardware vendors at the same time. Without the APIs, that's impossible.

Symantec and McAfee are hoping that the EU sides with them on Windows Vista.

Security Center
The core issue, however, is over which security centre should dominate your PC. Currently, Windows XP provides its one-stop Security Center for configuring your Windows Updates, antivirus, firewall, and antispyware, informing you in a pop-up message or a taskbar icon if one or more of these has been disabled or is out of date. Symantec and McAfee also offer users a snapshot security status, but the end user doesn't have much control over whose messages are dominant. Thus, in the lower-right corner of your screen, you're likely to see messages from the security centres of both Windows and a third party. To a novice, this information overload could be very confusing.

McAfee and Symantec are asking Microsoft to allow users (and, more importantly, the lucrative OEM hardware manufacturers) the ability to disable the Microsoft Security Center and run third-party security centres instead. That sounds reasonable, except Microsoft isn't playing; turning off the Microsoft security undermines the new security model within Vista that locks down and enforces security throughout the new OS.

PatchGuard
McAfee and Symantec are also upset about PatchGuard, a Microsoft technology that locks the Windows system kernel to all outside vendors. The arguments regarding PatchGuard are about the future; today most people don't have the x64 machines that take advantage of the technology, but when they do security vendors want to be a part. Down the road, new computers will be 64-bit and Vista is already designed to run on this new hardware. Microsoft claims that by locking the kernel to outside vendors, it'll eliminate most of the causes of the Blue Screen of Death, as well as prevent rootkits from installing. Unfortunately, it'll also eliminate most third-party firewalls.

Current firewall technology involves hooking the NDIS (Network Driver Interface Specification), which exists only in the system kernel. Even with the advance notice (vendors have known about PatchGuard for a while; it's within the Windows XP x64 edition, for example), it's too late for firewall vendors to create a new methodology, but Microsoft is adamant in not allowing third parties inside the x64 kernel.

Funny thing is, I watched a standing room-only demonstration at this year's Black Hat where security researcher Joanna Rutkowska was able to hack the kernel of a 64-bit version of Vista running on an AMD processor. So I don't see why Microsoft should lock out security vendors when a diligent hacker can find methods such as the one that Rutkowska used to subvert the Microsoft kernel.

Why only Symantec and McAfee?
Although the headlines read Symantec and McAfee, you could easily substitute your personal favourite security vendor instead. The issues mentioned above affect almost all third-party security vendors. The reality is, most security vendors can't afford to mount a long, sustained fight against the giant that is Microsoft; McAfee and Symantec have those resources. That said, neither McAfee or Symantec has filed for a formal decision against Microsoft, nor has either company broken off talks with the software giant.

Presently all signs point to Microsoft having a Release to Manufacture edition of Vista available by the end of November; if that happens, we'll then see a retail product on store shelves at the end of January 2007. The only wrinkle might come if Symantec and McAfee somehow manage to hold things up for Europe (and Europe only) where the European Commission could block the release of Vista. Personally, I don't think the EU will block Vista's release.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Q&A of the Week: 'The current state of the cybercrime ecosystem' featuring Mikko Hypponen http://t.co/6lUYFs0X

You say that the golden age of cyber crime will be over by 2014/2015. I would like to differ. I believe that cyber criminals are getting ...

19 minutes ago by Staden on Cybercrime golden age over in two years?

Before accusing me of fudging the figures, that was the percentage in April, the latest available. It seems that as the advantage of the ...

3 hours ago by GregoryB1 on NBN FUD: will Abbott ever learn?

Currently about 50% of connections are at the 100Mb/s rate.
As a consequence, ARPU is significantly higher than the projected figures.

3 hours ago by GregoryB1 on NBN FUD: will Abbott ever learn?

Currently about 50% of connections are at the 100Mb/s rate.
As a consequence, ARPU is significantly higher than the projected figures.

3 hours ago by GregoryB1 on NBN FUD: will Abbott ever learn?

Wireless currently carries less than 2% of total internet data traffic. Simply to carry the existing traffic, we would need 50 times the ...

4 hours ago by GregoryB1 on Blowing the digital dividend on wireless NBN

The stupidest part about a wireless solution for the burbs is that it will actually cost more to put an antenna on the roof to get the si...

4 hours ago by GregoryB1 on Blowing the digital dividend on wireless NBN

The problem is not range of the cell in the urban areas where Turnbull wants LTE instead of fibre, it is the number of users. In urban ar...

4 hours ago by GregoryB1 on Blowing the digital dividend on wireless NBN

After the Second World War, the pursuit of pleasure domains the entire world atmosphere, Lancel (Lancel) to adapt rapidly into the demand...

5 hours ago by PokArrackpask on Spam sees Westnet blocked by BigPond

RT @DellEnterprise: Dell Secureworks talks with ZDNet about Android's biggest #security flaws - http://t.co/LSFLQVFq #infosec

NBN users opt for 100Mbps: Customers are picking the top fibre plan that is available on the National Broadband ... http://t.co/sjtFSU3g

"Customers are picking the top fibre plan that is available on the National Broadband Network (NBN), more than a... http://t.co/M3P24Htn

Another thing I found so misleading here is the step on how you assume to make the USB bootable . (The NTLDR needs to be renamed to USBNT...

7 hours ago by WindowsAnalyzer on Boot Windows XP from a USB flash drive

You can also use the help of these links, just incase your stuff failed, I probably got Windows build by using the Pebuilder as per the i...

7 hours ago by WindowsAnalyzer on Boot Windows XP from a USB flash drive

RT @CorrieB: An iPad for every child: Inevitable or impossible? http://t.co/I7uS8l9s Thx to @timbuckteeth for this; http://t.co/jxkqIRIp

RT @MADinMelbourne: roxon "will enable more families to access credit" @MLolderandwiser: Privacy Act amendments http://t.co/Mv4c7PC2 via @zdnetaustralia

NBN users opt for 100Mbps - ZDNet Australia http://t.co/fLfHMzPn #australia #technews

RT @konradski: Whaddayaknow - turns out Wi-Fi CAN interfere with a plane's navigation systems http://t.co/ospQCU2S

This story has been voted 5 times in the last 24 hours!

10 hours ago, NBN's Tassie upgrade to cost $1.3 million

Sorry no deal Cinders, I'd rather send my money to someone and watch them desperately try to stop the NBN as this has much better enterta...

10 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

What else can you expect from a Dodo customer?

11 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

NBN users opt for 100Mbps - Communications - News - ZDNet Australia: NBN users opt for 100Mbps - Communications ... http://t.co/btB9gKWg

NBN users opt for 100Mbps http://t.co/xKqEb4bE via @zdnetaustralia

Biometric bugs too dangerous for public? http://t.co/8JLz5tdF via @zdnetaustralia

Oh please dont be unkind, I gotta have some fan's. btw I agree I dont set the standard, but who does I wonder?

13 hours ago by Doubt on NBN users opt for 100Mbps

You agree but give him thumbs down... I think you'd better take the medication before one of your alter ego's Fred/Frank/Frergers appear...

13 hours ago by Beta on NBN users opt for 100Mbps

Exploring: http://t.co/rT7RPZLA

+1

13 hours ago by Beta on NBN users opt for 100Mbps

War talk dominates #AusCERT 2012 - http://t.co/SlBpMj0c - #security #cyber

So we agree it was a stupid idea and even stupider comment then ;-)

13 hours ago by Beta on NBN users opt for 100Mbps

Not you obviously ;-)

And stop giving yourself thumbs up FFS.

13 hours ago by Beta on NBN users opt for 100Mbps

Ok Beta, understand now, just one point who sets the standard?

13 hours ago by Doubt on NBN users opt for 100Mbps

Oh no Beta you misunderstand me. I like my waterfront home and deep water jetty, it's those "other" people who can move to Willunga.

13 hours ago by Doubt on NBN users opt for 100Mbps

I agree with you Magnus, but really most people like living on the coastal fringe.

13 hours ago by Doubt on NBN users opt for 100Mbps

Travel Tech Q&A: Skyscanner's Ewan Gray http://t.co/vYexrDwu #ipad

Exploring: http://t.co/YNVjdrct

Exploring: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia ... http://t.co/bNLCyobv #ICTChallenge

Exploring: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia ... http://t.co/HEPuJgyt #ICTChallenge

#NewSouthWales ditches registration stickers 4 light #vehicles in favour of #technology http://t.co/xX5N0Rp9

Anonymous hacks Reliance's Internet filtering server - ZDNet (blog) http://t.co/uObU1HBP http://t.co/0UBXxwX4

Which Windows will make for a better tablet? http://t.co/4mAHg850

Listening to @stilgherrian cover AusCERT and cyberwar, http://t.co/6lGUEz8H

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/VN5tGJzC

#Westpac Board goes paperless with #Ipads with #Tabula #App http://t.co/duxuj2fd #Cybersecurity #Bank

Microsoft is serious about open source??? http://t.co/mqQGgta7

@joedamato just try varying caps randomly. Maybe they do this http://t.co/1FN5FwYv

NSW outlines datacentre migration plans - Hardware - News - ZDNet Australia http://t.co/OQfUl0D1

"on the new fast Internets everyone wants the fast plan" #orly #nareally #yarly http://t.co/kvfCa84A

Chrome overtakes IE: does it matter? http://t.co/e4SILk8a

A ZDNet study showed that British Facebook users are drunk in 76 percent of their photos.

The HDMI cable ripoff and why retail is really dying http://t.co/eFT7zEW7

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/IUysbyKf

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/V7vL5QB9

ZDNet reports Microsoft launches its own social service http://t.co/VJS5BkwF

by http://t.co/vmlLt4bh: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia P... http://t.co/4bfDRXo4

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/CtNlVWN7

This story has been voted 12000 times in the last 24 hours!

2 days ago, Is Bill Gates a great leader?

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar