You are here: silicon.com > Software > Security Strategy

Security Strategy

Microsoft shoots the Messenger for bringing security fears

Dropped from the next XP update...

By Robert Lemos

Published: 29 October 2003 08:30 GMT

Spam attacks and security vulnerabilities have prompted Microsoft to plan to turn off its troublesome Windows Messenger service in the next Windows XP update.

The Messenger service is a data exchange mechanism for networked computers that shouldn't be confused with Microsoft's instant-messaging software. Spammers have taken advantage of the service, which is typically only used to manage networks in businesses, to send advertisements that pop up in grey boxes on people's desktops. Microsoft also announced earlier in October that the technology has a flaw that could be used by attackers to bypass a computer's security.

Switching Messenger off "is the current plan of record", said Neil Charney, director of product management in Microsoft's Windows client group. The company made the announcement at its Professional Developers Conference in Los Angeles. "What we are doing at this point is running through the plan with developers," Charney said.

The next update, Windows XP Service Pack 2, is due in the first half of 2004. Microsoft also plans in Service Pack 2 to turn on the Internet Connection Firewall, a basic form of protection that's built into Windows but is currently off by default.

The decision comes as other companies have attacked Microsoft for including a feature that home PC owners largely don't use and that has been the source of security problems. Network administrators worry that the vulnerability in Messenger could be exploited by an online vandal to create a fast-spreading worm similar to MSBlast or Slammer.

Last week, AOL revealed that it automatically turned off the feature for nearly 15 million of its customers. The drastic step was the latest move to quash the effects of the flaw for AOL, which first started filtering out Messenger data nearly a year ago.

The plan to modify the default setting of Windows XP is part of Microsoft's search for ways to better secure its besieged operating system. At the beginning of October, the software giant said it would educate customers and improve its default configurations and its system for patching software.

In many ways, turning off the Messenger feature is an easy decision, because most consumers never used it, Charney said, and companies have the expertise to turn it back on.

"From a consumer, end user point of view, I think it is something that will be left off," he said.

Robert Lemos writes for News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Windows engineer Investment banking city based

Senior windows engineer: My client is seeking to bring on an experienced engineer who has worked on the windows platform in a large, global ...

IT Support Engineer

To apply online please go to www.farn-ct.ac.uk or call our 24 hour recruitment line on 01252 407020 quoting the post reference to receive an ...

Helpdesk Manager - Technologies client - London City 40,000

Excellent opportunity for an experienced Helpdesk Manager to join my technologies client based in the City London, to manage a Helpdesk of 4 support ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: