Enabled by default, Windows 8's SmartScreen feature aims to protect unwitting users from nasty malware and other unsavory files. Even if this is the first time you've heard of it though, it may still sound strikingly familiar. That's because the technology was originally introduced with Internet Explorer 8 as an extension of IE7's phishing filter. In IE9, SmartScreen gained Application Reputation, a set of algorithms used to analyze the trustworthiness of downloads via digital signatures, heuristics and information collected by Microsoft. This appears to be the foundation of Windows 8's implementation.
In order for SmartScreen to work, the technology relies on Microsoft's proprietary, centralized database of software trustworthiness. That's where security and privacy advocates become a little uneasy -- Microsoft collects information about user-driven download activities which in turn, are used to power this database.
Kobeissi believes the data sent by Windows 8 includes the application's hash value, it's obfuscated file name and the computer's IP address. Although the data is encrypted, Kobeissi voices his concern that SSLv2 is relatively insecure, potentially leaving installation data and identities of users open to hackers.
Ultimately though, SmartScreen has proven itself to be fairly effective in protecting users from malicious sites and files. A cost-benefit analysis of the technology is unlikely to weigh on the minds of most users, but for the average consumer, SmartScreen may actually prove to be a worthwhile addition to Windows 8. Skeptics and cynics though, will likely want to leave SmartScreen disabled.
No comments:
Post a Comment