CIO Update   Earthweb  
Images Events Jobs Premium Services Media Kit Network Map E-mail Offers Vendor Solutions Webcasts
   subjects:
IT Management Webcasts:
The Role of Security in IT Service Management

Preparing for an IT Audit

More Webcasts


Search EarthWeb Network

internet.commerce
Be a Commerce Partner














CIO Update: Is Microsoft Licensing Forcing Banks to Break The Law?

Turbo Screen Sharing
Adobe Acrobat Connect Professional offers users the ability to have a more productive and engaging web conferencing experience while providing the IT department with a program that efficiently utilizes bandwidth and minimally impacts the infrastructure. Learn More! »

Informal Learning: Extending the Impact of Enterprise Ideas and Information
Forward-thinking organizations are turning to enterprise learning in their quest to be better informed, better skilled, better supported at the point of need, and more competitive in their respective marketplaces. Learn More! »

Rapid E-Learning: Maturing Technology Brings Balance and Possibilities
Rapid e-learning addresses both time and cost issues by using technology tools to shift the dynamics of e-learning development. Learn why more skilled learning professionals use these tools and how you can get a solution to keep pace with your business demands. »

Delivering on the Promise of ELearning
This white paper defines the framework to launch e-learning as a set of teaching, training, and learning practices not bound by a specific technology platform or learning management system. It offers practical suggestions for creating digital learning experiences that engage learners by building interest and motivation and providing opportunities for active participation. »

XML/RSS feeds

EarthWeb IT Management news and headlines
CIO Update headlines
See more EarthWeb Network RSS feeds

FREE Tech Newsletters

Special Reports
SOA, ITIL and the Strategic CIO
Going Green in the Data Center
Enterprise 2.0 - Giving the Hype a Second Thought
ITIL v3: Bridging the Gap Between IT and Business
Outsourcing’s Seven-Year Itch
The Productivity of Technology is in Jeopardy
Offshore Considerations for Infrastructure Management
Disaster Waiting to Happen
Friday’s Top 5
Top 10 Money Savers for 2008
More Special Reports
IT Focus
Tech Focus: Security

Cybersecurity: Laws Only Go So Far

Mozilla Firefox vs. Internet Explorer: Which is Safer?

Is Your Blog Leaking Trade Secrets?

The Las Vegas Counterfeiting Story: Is Your Privacy Worth More Than a Poker Chip?

Stopping Spammers at The Point of Sale

Today on EarthWebNews.com
Palm's Thin Treo Pro Unleashed
HP Rescues Stocks
Microsoft's Novell Investment Tops $340M
Intel Sets Sights on Solid State Drives
Salesforce.com Buys More Service With InStranet
More EarthWebNews.com

Symantec Online Storage for Backup Exec is an easy, cost-effective way to back up your Backup Exec 12 data to secure off-site storage for disaster recovery and long-term retention. Try it free for one month.

Is Microsoft Licensing Forcing Banks to Break The Law?

By Dan Orzech

October 22, 2002: Financial institutions using Microsoft software may find themselves in conflict with new federal privacy regulations.

Lester Warby is the kind of guy who reads the fine print. And the fine print for the latest updates to Microsoft Windows has him worried.

Warby -- who is the chief information officer at Seattle Metropolitan Credit Union -- believes that the terms for the end user license agreement (EULA) for Microsoft's Windows 2000 Service Pack 3 (SP3) and XP Service Pack 1, might well put the credit union in violation of new federal privacy laws.

At issue is Microsoft's "automatic update" feature, which allows users to automatically get upgrades and patches to their systems. To get the updates, users must agree to give Microsoft access to information on their systems.

That, says Warby, conflicts with federal regulations for financial institutions, such as the Gramm-Leach-Bliley Act of 2001. The new law, which goes into effect next May, forbids financial service companies from giving third parties access to customer data without express consent from the customer. European countries generally have even stricter data privacy laws.

"We're forced into a position where we're either out of compliance with Microsoft's licensing, which is not acceptable, or we're out of compliance with the law, which is not acceptable either. Under these circumstances, we'll probably change our operating system," says Warby.

Warby is considering shifting his servers to another operating system like Novell or Linux, if Microsoft doesn't change its policy.

What -- exactly -- is software?
To use the "auto update" feature, according to the Microsoft Windows 2000 SP3 license, "it is necessary to use certain computer system, hardware, and software information..." By using these features, users authorize Microsoft or its designated agent to access and utilize the necessary information for updating purposes."

The problem with that language, says industry analyst Joshua Greenbaum, of Enterprise Applications Consulting, in Daly City, Calif., is that the phrase "software information" is vague.

The term could include "information about proprietary systems, or about data," he says. "Does a stored procedure -- which could contain proprietary algorithms -- constitute software? Does the term include information about competitor's products, or about the use of software from a company with whom Microsoft might have a legal dispute?"

Microsoft does provide users with a high level of control over the auto update feature. Windows XP ships with the feature turned off, for example, so users must choose to activate it. And Microsoft notifies users of any updates, requiring them to agree to install them.

"Most home and small office users don't like to apply patches and updates," says Warby -- who describes himself as "pro-Microsoft" in general -- "so having Microsoft do this automatically for them would be a real value-added service." Microsoft is not the only company that offers such a service: Apple Computer's latest operating system, OS X, offers a similar feature called Software Update.

But what works for home users is not necessarily suitable for financial institutions, with their high level of security concerns, says Warby. And Warby says Microsoft has told him that it plans eventually to eliminate users' ability to disable Microsoft's access to their systems.

Microsoft had no comment on this issue, but if true, it is likely motivated by Redmond's concern about illegal copies of its software. Microsoft's license for Windows XP SP1 says:

Solely for the purpose of preventing unlicensed use of the applicable OS Software, the OS Components will include installation on your computer of technological measures that are designed to prevent unlicensed use, and Microsoft may use this technology to confirm that you have a licensed copy of the OS Software.

This is done through a product key that is sent to Microsoft over the Internet. That means Microsoft must send an authorization back to your system, says Warby, requiring it to have access to your system.

That makes Warby nervous. "Microsoft is definitely not known for their internal security," he says, citing undocumented macros in some Microsoft programs, which can be accessed by those who know the right combination of keystrokes. "The idea of Microsoft coming into a server, creates a potentially huge security risk," he says.

Of equal concern, says Warby, is that by agreeing to the Windows 2000 SP3 licensing terms, the credit union is potentially granting access not just to Microsoft, but to its "designated agents" The Microsoft license offers no assurances about who those companies might be, says Warby. "What if the designated agent is some small company overseas," he says, "in a country with a lax legal system?"

Financial institutions generally require background checks and assurances such as bonding before giving any outsider access to their systems. Oxford Global Technologies, for example, a Beverly, Mass.-based systems integrator, went through extensive security checks before it was allowed to provide remote Oracle database administration to financial industry clients. "One of our clients is a major brokerage house," says Paul Campbell, the firm's CTO. "They not only did background checks on our employees, but reviewed our software systems, and insisted that the security company which guards our building be approved as well."

Tools:
Add www.cioupddate.com to your favorites
Add www.cioupddate.com to your browser search box
IE 7 | Firefox 2.0 | Firefox 1.5.x
Receive news via our XML/RSS feed

 Return to CIO Update Index
 Return to www.cioupdate.com Homepage





JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers