---
Email this article   Print article 

Microsoft Fires Back At Sophos On Windows 7

By Kevin McLaughlin, CRN
November 09, 2009    6:17 PM ET

Microsoft is disputing security vendor Sophos' recent claim that Windows 7 without antivirus software installed is vulnerable to most malware currently in circulation.

Although Windows 7 comes with 'defense-in-depth' security that includes features like User Account Control (UAC), Kernel Patch Protection, Windows Service Hardening, Address Space Layout Randomization (ASLR), and Data Execution Prevention (DEP), it's still a good idea for customers to use antivirus software, said Paul Cooke, director of Windows Enterprise Client Security at Microsoft, in a Friday blog post.

"So while I'm not a fan of companies sensationalizing findings about Windows 7 in order to sell more of their own software, I nevertheless agree with them that you still need to run antivirus software on Windows 7," Cooke wrote in the blog post."This is why we've made our Microsoft Security Essentials offering available for free to customers."

Last week, Chester Wisniewski, senior security engineer at Boston-based Sophos, claimed that Windows 7, configured with default User Account Control settings and without antivirus software running, was found to be vulnerable to 8 out of 10 unique virus samples in recent tests in Sophos' labs.

On Monday, Wisniewski said Microsoft's marketing of UAC as a complement to the security of Windows 7 is somewhat misleading.

"Most malware these days is behaving in a way that UAC doesn't help," Wisniewski said in an interview. "A lot of fake antivirus software doesn't elevate privilege, so users don't get any UAC warnings. We're seeing more of these threats operating in userland and not necessarily doing things that trigger UAC."

Given that Sophos sells antivirus software, Wisniewski has taken some heat from Microsoft proponents who claim he's just trying to drum up fear to sell more products. Although Microsoft is giving away its Microsoft Security Essentials antimalware offering for free, Wisniewski doesn't see that as a threat to Sophos' business. "The more PCs that are protected, the better," he said.

To continue reading this article, please download the CRN Tablet Edition app from the iPad App store.

SHARE THIS ARTICLE

More Security

Recent Articles

Bit9 Security Survey: Nobody Wants To Be A Headline

What's keeping IT security professionals awake at night? These survey results provide insight into perceived threats and vulnerabilities, the effectiveness of security practices, and opinions about disclosure practices.

Nix That Click: Six Scareware Scams To Watch Out For

SpywareRemove.com provides a list of some of the nastiest rogue antispyware programs out there -- designed to trick people into paying to remove malware from their computers.

Malicious Malware: Six Ways Cybercriminals Beat Security

Cybercriminals have become adept at going around the latest security defenses. Here's a list of some of the most innovative malware in use today.

  More Slide Shows




Related Videos
Loading...