Windows 8.1 security: what's been improved

Windows 8.1 promises security that goes beyond just scanning potential malware
Windows 8.1 promises security that goes beyond just scanning potential malware

In all the fuss about the Start screen, it's easy to miss that Windows 8 had major improvements to security; that was the culmination of ten years of work on defending the operating system, senior product manager Chris Hallum told us.

"Windows 7 is six times more likely to get infected than Windows 8 and Windows XP is 21 times more likely to be exploited."

But that was still all defensive reactions; for Windows 8.1, he said, Microsoft is going on the offensive with better malware protection, new ways of checking the security certificates web sites rely on - and with a plan to add encryption and biometric security to every PC.

The built-in anti-malware tool Defender will protect against more threats in the browser, including from plugins and ActiveX controls. "In Windows 8.1 we will scan those payloads before they're executed," Hallum told us.

Protecting against stolen certificates

Microsoft will also be more active about protecting the browser against stolen certificates; because the browser trusts those certificates to identify popular web sites that you log into, hackers have started targeting them (and the authorities who issue them) as a way to break into your accounts.

"Public certificates have already been hacked," Hallum points out; in a number of cases certificates for well-known companies like Yahoo and Google have been compromised and used on fake web sites to steal credentials."

Windows 8 vs Windows RT: what's the difference?

For Windows 8.1, Microsoft will operate a service tracking certificates for the top million web sites. "If we see a certificate being used fraudulently or showing up on a server where it shouldn't be, we will work with the certificate authorities," Hallum said, noting that this will protect other versions of Windows and indeed other platforms too.

Windows 8.1 encryption and BitLocker

With Windows 8.1, encryption isn't just for business users any more, although Microsoft is improving BitLocker performance for business systems (up to 30 times faster than in Windows 8, Hallum claims). "We need it not just to protect your data but also the system itself; we don't want people to be able to tamper with Windows system files," he explained.

That's why all versions of Windows will now include encryption; BitLocker in the business editions and the same device encryption that's already in Windows RT and Windows Phone 8 in the home editions. "We expect encryption to be pervasive," he predicted.

If you're putting confidential information on a Windows 8.1 tablet, encryption and biometrics will keep it more secure

If you're putting confidential information on a Windows 8.1 tablet, encryption and biometrics will keep it more secure

There are some hardware restrictions on this; you need a PC that is capable of Connected Standby with Windows 8 or 8.1. That means the PC has a UEFI BIOS and either a separate Trusted Platform Module (TPM), ARM's Trusted Zone or Intel's Platform Trust Technology for storing information securely.

It also means there is are no Direct Memory Access connections, which includes both FireWire and the Thunderbolt technology Intel developed with Apple; Hallum says Microsoft is talking to Intel about ways of making Thunderbolt more secure but DMA connections can transfer code directly into memory, bypassing system security.

Windows 8.1 Provable PC

Microsoft will also use the information about the PC stored in the TPM to 'harden' Windows with a cloud service that's provisionally called Provable PC Health (expect the name to change, Hallow says). This will use the record of secure boot stored in the TPM to verify that your PC isn't infected. "We can remotely analyse the security state of the device and the integrity of the device." Hallum says, claiming that this will detect even sophisticated malware like Flame.

"We will inform the user if there is a problem and if there is an infection Windows can put them back in a safe state. If there is an infection that can steal their credentials we will inform them, and we will help them remediate their Microsoft account."

TOPICS
Contributor

Mary (Twitter, Google+, website) started her career at Future Publishing, saw the AOL meltdown first hand the first time around when she ran the AOL UK computing channel, and she's been a freelance tech writer for over a decade. She's used every version of Windows and Office released, and every smartphone too, but she's still looking for the perfect tablet. Yes, she really does have USB earrings.

Latest in Security
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
How to prevent cyberattacks
NTT admits hackers accessed details of almost 18,000 corporate customers in cyberattack
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
Latest in News
Q Acoustics Q SUB80, QSUB100 and QSUB120 subwoofers
Q Acoustics wants to bring the bass to your post-Oscars movie catch-up
Hospital
Major Oracle outage hits US Federal health record systems
Samsung Galaxy A56 display
Samsung’s new budget handsets are getting One UI 7 before the Galaxy S24 Ultra, and I’m as confused as you are
iPad Pro 13-inch 2024 on a table
The OLED iPad Pro is reportedly less popular than expected – and that could mean these changes to Apple's OLED iPad plans
Sam Porter cradles a baby
Death Stranding 2: On the Beach trailer confirms June release date and an even more harrowing post-apocalyptic world
The Ray-Ban Meta Coperni smart glasses
The new Ray-Ban Meta smart glasses design is an expensive disappointment