NEWS By Matthew Broersma A security expert has sparked fresh controversy regarding the security of Microsoft's Windows operating system. Chris Paget, a freelance security researcher, has claimed a flaw in the design of the Windows architecture has led to vulnerabilities in an unknown number of Windows applications. Paget published a whitepaper demonstrating what he calls a 'Shatter Attack', which allows a user to elevate his or her privileges and gain control of a system. The attack makes use of a flaw that Paget says may be found in many Windows applications, due to the way the Windows application programming interface (API), Win32, is designed. The security of Windows APIs has come under the spotlight recently because of Microsoft's antitrust case. Under the terms of a proposed settlement, Microsoft would be required to disclose the workings of previously secret APIs - a process the company has already begun. However, Microsoft would reserve the right not to disclose APIs which are important for Windows security, in keeping with what the company's critics say is a strategy of "security through obscurity". Paget argues that his research shows that far from obscurity providing the best security, the reverse strategy is more effective. "If people know about these problems, they can work around them," he said. "If they don't, they've got no choice but being vulnerable to them. It comes back to whether you think full disclosure is a good thing." Click here to read more about the 'Shatter Attack': http://www.silicon.com/a55026 What do you think about this story. Does it highlight the need for more openness in the security field? Should Microsoft be more of a sharing, caring company. Register a reader comment below. Matthew Broersma writes for ZDNet UK
Windows API flaw sparks security row
More mud sticking to Microsoft...
Post your comment
In order to post a comment you need to be registered and logged in.
You can also log in with Facebook. Log in or create your silicon.com account below
Get silicon.com's daily newsletter
-

Enter your email to register
Featured white papers
-
Why is encryption important?
Data protection has become a hot topic, but where is the real threat and what can you do to protect your business? How...
-
CIO challenges: Bringing your iPad to work
The arrival of personal technology in the office is a challenge for all organisations. The technology is here, but not...
-
2012 Olympics: Is your business prepared?
Athletes prepare for all kinds of conditions and problems in competition. With the London-hosted Olympics fast...
Keep in touch with silicon.com
-
Connect with silicon.com on Facebook
Discuss the news of the day with the silicon.com team
-
Follow silicon.com on Twitter
Get regular updates from the silicon.com editors
-
Join the silicon.com LinkedIn networking group
Network with your peers and share expertise
Latest jobs
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
-
Managing Director - NBA3045
Managing Director – Cash and Transit Salary: £95K - £140K Basic, Bonus, Pension Scheme, Family...
silicon.com newsletters
-
Stay up to date with silicon.com newsletters
Keep up with the latest news and analysis from silicon.com with our free email newsletters




