Palladium concerns Microsoft's competitors, not lawyers

By Sam Costello, IDG News Service |  Security Add a new comment

Microsoft Corp.'s Palladium security system has sparked concern among some of the company's competitors in the operating system market, as well as with consumer and digital-rights advocates, but lawyers and security companies are less troubled.

Palladium is the code-name for Microsoft's new security initiative, announced Monday, which is designed to create a "trusted space" within a PC for certain programs and other sensitive operations to run in. The system will require security hardware, in the form of a chip, as well as software, the company said Monday. The combination of hardware and software security could let users create documents and e-mail messages that expire after a certain amount of time, Microsoft said. It could also let music and movie companies take advantage of native support for digital rights management software that could let them limit how their content is copied or shared, and could stop users from running code that isn't digitally signed, Microsoft said.

Windows users will get the majority of Palladium's benefits, at first, though Microsoft said that it plans to make the system interoperable with other platforms. Microsoft may publish the source code to Palladium to allow third parties, including competitors, to create systems that interoperate with Palladium, the company said.

Some Microsoft competitors were, unsurprisingly, less-than-excited about the announcement of Palladium.

"Microsoft is enamored with the closed world they've built with the Xbox where they control what software can run. They believe they can use that strategy to restrict competition and increase their control in the PC arena," said Michael Robertson, chief executive officer of Linux desktop operating system startup Lindows.com Inc., in a statement. The Xbox includes a security system that restricts what kind of code the console will run.

Lindows, based in San Diego, and Microsoft, based in Redmond, Washington, are currently engaged in a lawsuit in which Microsoft is asking a court to bar Lindows from using that name for its Linux-based operating system, saying that it infringes on Microsoft's Windows trademark.

"Open systems beat closed systems -- it's what has made the PC and Internet so successful," he said.

"Microsoft is proposing reduced consumer freedom over their computer and their media while cleverly disguising it as improved privacy. I don't care what big companies they have extorted to endorse this strategy, consumers will see through it and reject it," he said.

Another Microsoft foe, Sun Microsystems Inc. said in a statement that "Sun watches with keen interest as Microsoft's Palladium initiative, whose technology is years away, unfolds. We look forward to Microsoft addressing its immense security issues: bug fixes are only a temporary treatment for the symptoms of flawed product design and is not a permanent cure for the disease. However, it is good to see Microsoft finally taking code quality seriously."

Third-party security companies have long been the beneficiaries, and borne some of the burden, of the security flaws in Microsoft's operating systems and applications. Though Microsoft may now be moving into its market, one such company, RSA Security Inc., welcomes Palladium.

Palladium is "a great thing for security," said John Worrall, vice president of product management at RSA, based in Bedford, Massachusetts.

RSA is "really pleased to see Microsoft taking a lead in security," he said, adding that "starting from the base hardware and building up is a great model."

Though Microsoft has said that further announcements about Palladium are certain, it is less certain, though possible, that some of those announcements could involve other vendors.

RSA will be making an announcement about its relationship with Microsoft in the near future, said Worrall. When asked whether Microsoft has consulted RSA in designing Palladium, Worrall declined comment. Microsoft said Monday that it was consulting with other companies on the design of the system.

Questions about the involvement of third party software and hardware developers aren't the only ones that hang over the venture.

With a judge poised to rule in Microsoft's antitrust suit with the nine states that did not agree to the company's deal with the U.S. Department of Justice, another broad, Windows-centric initiative may seem ill-timed to some. However, these concerns may not be well-founded, said Bob Schneider, a partner and the head of intellectual property department at the Chicago law firm Chapman & Cutler.

Palladium "could be (an extension of the Windows monopoly), but I don't think at this stage it has risen to that level," he said.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question