Skip to main content
  1. Home
  2. Computing
  3. Legacy Archives

Vista Kernel API Opened to Security Firms

Add as a preferred source on Google

The brouhaha over developing third-party security applications for Windows Vista may be far from over, but Microsoft has followed up on a pledge it made last October to clue third-party security developers into the APIs they’ll need to use to tap into the Vista kernel.

In order to improve security in Windows Vista—at least, compared to the long-standing nightmare which has been security under Windows XP—Microsoft extended its PatchGuard technology to isolate the operation system kernel in the 64-bit edition of Windows Vista. The decision left no mechanisms for developers of third-party security applications—like Symantec and McAfee—to create security, scanning, and firewall products for the 64-bit version of Vista.

Recommended Videos

Microsoft has made the draft APIs available to third-party developers for testing and comment through the end of January, 2007, and promises a final version of the APIs will be available when Microsoft releases its first service pack for Windows Vista, expected in mid- to late-2007. So far, no security vendors have commented publicly on the API information received from Microsoft.

“These new APIs for Windows Vista have been designed to help security and non-security ISVs develop software that extends the functionality of the Windows kernel on 64-bit systems, in a documented and supported manner, and without disabling or weakening the protection offered by Kernel Patch Protection,” said Ben Fathi, Microsoft’s Windows security chief, in a statement. Fathi also noted that the APIs are not finalized, and it expects to modify the specifications in response to feedback from security experts and developers. Microsoft has published a document (MSWord) outlining the process it uses to prioritize and evaluate requests for Kernel Patch Protection APIs.

In the meantime, computing enthusiasts, enterprise customers, and others interested in 64-bit editions of Windows Vista remain concerned that no third-party security products will likely be available for the operating system until some time after the release of Vista Service Pack 1.

Geoff Duncan
Former Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
Apple will finally stop making iPhone-to-Windows copy-paste such a chore
Your iPhone may finally copy and paste with a Windows PC like it should
Apple Universal Clipboard feature

Copying something on an iPhone and pasting it onto a Windows PC should be one of the least remarkable features imaginable. While this simple process seems effortless between an iPhone and Mac, Windows users are still left waiting.

Now, Microsoft is formally asking Apple to provide interoperable clipboard access through the company’s European Union interoperability process. The request, submitted on March 25, argues that iOS restrictions prevent third-party platforms from creating an experience comparable to Apple’s Universal Clipboard. Apple has now reached Phase III and committed to developing a solution.

Read more
Chrome wants more extension reviews, but good ratings won’t keep malware out
Google is testing built-in extension review prompts, but good ratings can still hide malware
malicious-google-chrome-extensions-on-web-store

Google is preparing to add extension review links directly inside Chrome, putting feedback closer to the menus people already use to manage their add-ons.

A Chromium change, first spotted by Windows Report, points to review options in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would qualify, and the feature is still under development.

Read more
Passkeys were pushed as a safer future. Hackers have figured out ways to break those synced to Google
Google’s “uncopyable” passkeys may be easier to steal than promised
google-lawsuite-AI-Scams

Passkeys have been pushed as the safer successor to passwords. It promised protection from phishing, credential reuse, and password leaks. Google even claims that it cannot be copied or accidentally handed to someone else. But it might not be as secure as the company wants it to be.

Security researchers (Via BleepingComputer) have now found three ways malware can undermine those promises for passkeys synced through Google Password Manager. The techniques, collectively named Pass-ta-key, target Google Password Manager inside Chrome on Windows computers equipped with a Trusted Platform Module. Every attack requires malware to already be running on the victim’s computer.

Read more