Wednesday, January 17, 2007

NSA Helped Microsoft Set Security for Vista

Spy agency, vendor teamed to sync OS with standards

Robert McMillan   Today’s Top Stories    or  Other Security Stories  

 

January 15, 2007 (Computerworld) --

Microsoft Corp. and the National Security Agency confirmed last week that the intelligence agency helped the company configure Windows Vista so it meets the Pentagon’s security requirements.

NSA spokesman Ken White said the agency has provided guidance on securing Windows XP and Windows 2000 in the past. But this is the first time the NSA has worked with Microsoft or any vendor prior to an operating system’s release, White added.

By getting involved early in the process, the NSA ensured that there would be a version of Vista that is secure enough for the U.S. Department of Defense and compatible with federal software, he said. Now the NSA can guarantee that Vista’s off-the-shelf security configuration “is at a level that meets our standards,” White said.

Microsoft declined to make any executives available to comment about the NSA’s help. In a statement, the company said that it had asked a number of government entities to review Vista, including the NSA, the National Institute of Standards and Technology and NATO.

Alarm Raised

Still, the NSA’s involvement raised red flags for some privacy advocates. “Some bells are going to go off when the government’s spy agency is working with the private sector’s top developer of operating systems,” said Marc Rotenberg, executive director of the Electronic Privacy Information Center in Washington.

Rotenberg and other privacy advocates said it would be tempting for the NSA to push for a way to gain access to data stored on Vista-based systems.

But White said the NSA didn’t open any back doors into the new operating system. “This is not the development of code here,” he said. “This is assisting in the development of a security configuration.”

The work with Microsoft was done in accordance with the NSA’s mandate to protect the nation’s information systems, White said. “This is the other half of the NSA mission that you never hear much about,” he said. “All you ever hear about is foreign signal intelligence. The other half is information assurance.”

 

0 Comments:

Post a Comment

<< Home

Made4biz Security Translating real-world security knowhow into state of the art security systems.
Made4biz Security

Turn on Sound for Demos:
Bill Gates Demo (Location-based)
Elvis Demo (Location/Context-based)
Clint Eastwood Demo (Temporal-based)

Powered by Blogger

Subscribe to
Posts [Atom]

Technorati Profile

RSS Syndication

Made4Biz Security Inc