Risk
6/18/2009
06:13 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Microsoft Security Essentials Beta Coming Tuesday

Previously code-named "Morro," the free software will replace Windows Live OneCare, which included both security and utility services for $49.95 per year.

Microsoft has confirmed plans to release a beta version of Microsoft Security Essentials, its new free anti-malware software, on Tuesday, June 23, at about 9 a.m. Pacific.

Microsoft Security Essentials, previously known by the project name "Morro," will replace Windows Live OneCare, which included both security and utility services for $49.95 per year.

Last November, Microsoft explained its decision to phase out Windows Live OneCare by saying that a product more focused on security would serve consumers better. The company will stop selling Windows Live OneCare through retail channels at the end of June.

Microsoft Security Essentials works with Windows XP, Windows Vista, and the forthcoming Windows 7 operating system, according to the company. It's designed to require less space and fewer computing resources in order to be useful on less-powerful PCs and in situations with constrained bandwidth.

But the software, Microsoft claims, offers the same protection as the company's enterprise malware products, which provide, or attempt to provide, protection against viruses, spyware, rootkits, and Trojans.

Amy Barzdukas, senior director of product management for the Online Services and Windows Division at Microsoft, said in November that customers want "comprehensive, ongoing protection from new and existing threats" and that this new free offering will enable the company to reach more customers, particularly in emerging markets.

Free seems to the way the consumer security market is going. Panda Security began offering Panda Cloud Antivirus for free in April. AVG Technologies and Symantec also have free security products.

The goal of such products is often to convince users to pay for more-comprehensive protection. There's also value to be gained from analyzing the data available from large number of users about active threats.

J.R. Smith, CEO of AVG, says Microsoft's new offering will be good for consumers and good for the security market overall because it will raise awareness that security products are necessary. He expects that companies like AVG, Kaspersky, and Symantec will be able to provide more extensive protection than Microsoft is offering.

"There's room for Microsoft to come in and protect the platform but there's a lot more to be done," he said. "Antivirus is the least of the worries these days. The Web threats are where we see 90% of the problems come through."

The Microsoft Security Essentials Web page isn't working at the moment, but it should be by Tuesday.


InformationWeek Analytics has published an independent analysis on what executives really think about security. Download the report here (registration required).

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7402
Published: 2014-12-17
Multiple unspecified vulnerabilities in request.c in c-icap 0.2.x allow remote attackers to cause a denial of service (crash) via a crafted ICAP request.

CVE-2014-5437
Published: 2014-12-17
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php,...

CVE-2014-5438
Published: 2014-12-17
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.

CVE-2014-7170
Published: 2014-12-17
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

CVE-2014-7285
Published: 2014-12-17
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.