Microsoft urges users to protect themselves better from viruses

In the latest update to Windows XP, Microsoft has focused on helping people become more aware of what they need to do, and...

In the latest update to Windows XP, Microsoft has focused on helping people become more aware of what they need to do, and encouraging them to actually do it,  said lead program manager for Service Pack 2 Ryan Burkhardt.

A test version of Service Pack 2 (SP2), called Release Candidate 1 (RC1), was made available to beta testers and the completed update will be released in mid-2004.

In RC1, if someone received an e-mail with an .exe attachment, or other file type that is regularly used to spread so-called malware, it will be identified and either blocked or the receiver will confirm that he wants to open it, Burkhardt said at the CeBIT trade show in Hannover.

The AES (Attachment Execution Services) API (application programming interface) is a public API that lets developers add attachment security to their e-mail client and browser applications.

In Outlook Express, file types known to be dangerous will be blocked and an explanation given to the user. The user will be given a choice of whether to open suspicious but less-dangerous file types.

Developers of other software, such as Qualcomm's Eudora e-mail software, may decide to block different file types, or to block none but prompt users with a warning for each.

Outlook Express will also no longer download graphics and other external content in HTML by default as these can be used to validate e-mail addresses.

"If the sender is not in the user's contact list, it will be treated as potentially unsafe," and will not be displayed, Burkhardt said.

Many of the security aspects now being released have been included in XP ever since it was first launched, but were turned off by default. "The climate was different then; there were fewer attacks, and fewer people had broadband," he said.

Users often make halfhearted attempts to ensure security, but do not follow through, Burkhardt said.

Many users download updates automatically, but not to automatically install them.

To try to solve this, users will see a new prompt when setting up their PC that will explain the benefits of automatic downloads and installation to encourage them to use it, he added.

The background download service has also been adapted to help users on slower connections.

The download speed will be scaled to suit what the user is doing, speeding up and using the available bandwidth when the user is doing something like reading e-mail, and slowing down when they are more actively using the bandwidth, such as when they surf the Internet, Burkhardt said.

Windows Firewall will now be turned on by default, and Windows Messenger will be turned off.

Gillian Law writes for IDG News Service

Read more on IT risk management