Microsoft outlines .NET and XP privacy strategy

Declaring "war on hostile code" here on Tuesday, Microsoft Corp. detailed several new features for securing privacy in both current and future Microsoft products here at the RSA Conference 2001.

On the Windows .NET front, XML-based user authentication technology, code-named "HailStorm", topped the list. HailStorm will allow client-side applications and Web services to exchange user information.

"Privacy is at the core of the HailStorm system," said Dave Thompson, vice president of Windows development, who delivered a keynote address. "The only way that it [is] tractable for a user to deal with ... the myriad of Web services ... is through personalization. The only way to easily move from site to site and have your destiny under control is ... for you to give information up, as you want, to the right sources."

The Windows XP operating system, too, will feature beefed-up security. In particular, Thompson noted that PKI (Public Key Infrastructure) improvements are in the pipeline.

"We're filling in some of the places where we could have done better," he said, adding that new auto-enrollment and auto-renewal services for users "will make it very easy to deploy PKI."

Smart card support will further bolster XP privacy, according to Thompson. "All the functions that an administrator needs to do can be done with smart cards, including Terminal Service sections. You can uniformly require an administrator to use smart cards. That eliminates the risk of using passwords," he said.

XP will also allow for interoperability between smart cards and EFS (electronic filing system), which will let companies accept certificates issued by other PKIs.

Other XP announcements included faster SSL (Secure Sockets Layer) services, version 2 of the company's Security Configuration Wizard, which will let users configure access controls and turn off unneeded services, and an Internet Connection Firewall to allow users to safely connect directly to a network.

Thompson also addressed Microsoft's upcoming Internet Explorer 6.0 browser. As the company announced on March 21, IE 6.0 will feature native support for P3P (the Platform for Privacy Preferences). P3P is a privacy standard developed by the World Wide Web Consortium that notifies users about the privacy rules used at visited Web sites.

Another part of Microsoft's IE 6.0 privacy plan involves the Privacy Statement Generator, which will generate policy statements at IIS (Internet Information Server)-hosted Web sites.

Thompson also announced a strategy to lower the cost of guaranteeing privacy for its customers. By reducing the need for users to reboot patched systems and sending out bulletins that list virus severity ratings and patch availability, Microsoft hopes to streamline its customers' operations, according to Thompson.

As well, Microsoft is trying harder to train its developers to spot privacy loopholes, Thompson said. He noted that the company's Secure Windows Initiative team has been assigned to scrutinize privacy in Microsoft products and train internal developers to create secure code.

Thompson was careful not to overstate Microsoft's role in determining privacy standards.

"I don't want to imply ... that Microsoft is driving or controlling or is the leading expert in security," he said. "[But] because of our role and the products we ship, we have an obligation to provide leadership [by] catalyzing the advancement of security knowledge."

Join the PC World newsletter!

Error: Please check your email address.

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Stephen Lee

Show Comments

Most Popular Reviews

Latest News Articles


PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?