Friday, July 2, 2010

Windows Security revisited

A lot has changed in the Windows security world in the past 3 years.  XP provided only minimal security, so you needed to bolt on after market products to fill the gaps.  Even the included firewall was weak and many people installed ZoneAlarm or other firewall products.  XP did not include antivirus (AV) or anti-malware (AM) protection.  Most PC vendors included trials to security suites, but those suites sometimes caused more problems than they fixed and users seldom subscribed to the updates when the trial expired.

Windows Vista improved the firewall to a useable state, added Windows Defender, an AM product, but still did not provide AV protection.  Microsoft would sell you OneCare, which combined Defender and an AV product they purchased from someone else, but if security was really important, why would they charge for it?  Fortunately, there were plenty of freeware products to choose from, so instead of purchasing from MS, many people got the free stuff.

Finally, MS decided to provide AV protection for Windows 7 (and Vista and XP with at least SP2) via it's Security Essentials product.  SE is really just OneCare without the price tag, so you get AV and AM from MS for free.

Why is this important?  Over the last few years, AV vendors have had problems with their products.  AVG Free Edition was the one I recommended to everyone running XP before Security Essentials was released.  It had a couple of high-profile problems in 2007 and 2008.  Recently McAfee's AV started crashing computers.  Now, I've always shied away from getting everything from the same vendor as they would have incentive to make their products look better than anyone else even if that were not the case.  But given the improvements in Windows basic security over the years, I am comfortable using Security Essentials as my AV/AM product.

I still recommend a hardware firewall as an added layer of protection.  Pretty much any router made in the last 5 or 6 years has a firewall built in.

No comments: