Skip to content
Author
PUBLISHED: | UPDATED:
Getting your Trinity Audio player ready...

Microsoft Corp.’s Bill Gates is planning Windows XP security damage control that bodes big changes in how our computers will look, feel and protect us from getting mugged online.

It’s about time.

Over the past half year, we’ve been attacked by the Nimba worm, followed by the virulent SoBig worm, then by the extraordinarily virulent Blaster32 worm and finally, in recent weeks, by MyDoom.a and its variants. We were up to MyDoom.f last week.

Each one seized upon some weakness in the Windows XP components designed to integrate PCs with the Internet. Windows users become ever more exasperated as they are forced to rush to www.microsoft.com/support to download patch after patch to mend newly discovered security holes.

Microsoft’s damage control scheme was outlined last week at a San Francisco gathering of the high-tech elite, the RSA Security Conference. Gates disclosed plans for a megapatch called Service Pack 2, or SP2, for release probably around July.

We’ve been expecting SP2 for more than a year.

But SP2 was expected to be along the lines of SP1, which was issued less than a year after Windows XP shipped. SP1 was used to tie up a number of loose ends, such as adding new drivers and enhancing the security features of the Microsoft Internet Explorer Web browser.

But Gates, wearing his hat as chief software architect, described a far more robust SP2 to the San Francisco crowd. Attendees included officials from the computer security side of the Homeland Security office and information technology czars from the cream of academia and Fortune 500 shops.

They were told that due to the virtual crime wave from hacker attacks, Microsoft expects SP2 will be much more important than SP1. Gates indicated that SP2 will amount to a significant rewrite of Windows rather than just another of the seemingly endless string of patches XP users are urged to download almost every time they go online.

Installing SP2 will make substantial alterations all over the operating system because the XP vulnerabilities are scattered all over Windows. Current XP computer owners will be able to either download SP2 over high-speed Internet lines or request the code on a CD from Microsoft.

When SP2 gets done loading, your computer not only will scan incoming stuff for viruses, it will put pressure on you to buy some outside antivirus software from the likes of Symantec Corp. or Networks Associates Technology Inc. Merry Christmas, guys.

Every e-mail you send will carry a code divulging your Internet address to allow a sort of call-waiting process. This will make it very difficult for mass e-mail spammers to get inside your mailbox.

After installing SP2 you’ll also get nagged to buy a firewall such as the highly popular Zone Alarm.

Other dramatically visible changes will be a pop-up stopper built in to the Microsoft Internet Explorer and a change to make the limited Internet Connection Firewall built into Windows activated by default instead of making it an option as it is now.

The firewall will be beefed up to report to users if and when some suspicious program attempts to transmit something from your computer to the Internet, such as so-called Zombie spam attacks.

Gates reportedly told the computer security technicians that Microsoft was forced to divert a lot of the work it had planned to do building the next Windows version, called Longhorn and not due until 2006, to SP2 because it is both crucial and complex.

It has been reported recently that Microsoft plans to follow SP2 with an interim version of Windows XP called XP Reloaded in early 2005. The reasoning is that the company will have gone almost four years from the release of XP, which replaced Windows ME after less than three years.

Going five years without the excitement and revenue from a new operating system worries stock analysts and others with microscopes on Microsoft’s every move.

Another knot of researchers with microscopes on Internet stocks must be smiling at the prospects of Symantec (Norton Antivirus) and Network Associates (McAfee Security) and others because every version of Windows will greet users with strong recommendations that they quickly add outside security software.

These virus-fighting companies deserve kudos for how quickly they reacted to the latest round of hack attacks by posting fixes on their Web sites for all victims to use free of cost. Of course, this also was an advertising bonanza to pitch new customers.

Still, it just doesn’t sit well for Microsoft to produce and sell a product with the potential for huge security vulnerabilities and then cop out on its own shortcomings by telling people they need to buy costly but essential components from another company.

Meanwhile, this writer will fret over the chaos that installing a new Service Pack will cause as the consumers I help in the Ask Jim columns load the new software and start reporting the kinds of bugs, blue-screen crashes and bedlam that accompanied SP1.

———-

Binary beat readers can participate in the column at chicagotribune.com/askjim, or e-mail jcoates1@aol.com. Snail-mail him in Room 400, 435 N. Michigan Ave., Chicago, IL 60611.James Coates