Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums

Go Back   Vista Forums > Vista technology newsgroups > WinFS

Data access security in WinFS - Re: Spyware

Reply
 
Thread Tools Display Modes
Old 03-05-2006   #1
Mario Goebbels [489782]
Guest
 
Posts: n/a

Data access security in WinFS - Re: Spyware

I've read the blog entry "WinFS Mailbox II", which cuts a bit into the topic
of item security. However how will this be exposed by the UI?

In my ideal world, items in the store would be assigned to
application/system contexts. Each application can access its own context
without restrictions. While other applications could search the files
residing in other contexts, accessing them however would spawn a system
dialog asking if you want to grant the application access to the single
file, the whole context of the other application or plain out deny the
access. Add a checkbox to make the decision permanent. This would put the
data security in the hands of the user and notify him immediately when an
application tries funny business. This would give for instance secure
sensitive data of your Money version on WinFS the protection it needs while
giving other applications the ability to access them under the control of
the user.

There should also be a system context, where the system files would reside,
which are accessible by everyone under the control of the system, and a root
context for global things that you want to be accessible without
restrictions. That'd be contacts, mails and other insensitive items.

Regards.

-mg


  Reply With Quote

Old 03-22-2006   #2
Simon Skaria [MSFT]
Guest
 
Posts: n/a

Re: Data access security in WinFS - Re: Spyware

Applicaton isolation has been widely investigated as a security feature for
Vista. However, it has not been fully implemented - MIC provides a level of
isolation in Vista. True App identity is postponed to subsequent OS
releases. WinFS aligns its security model with NT and leverages security
mechanisms availabe in the OS for its authentication, authorizaiton,
auditing and administration to improve better inter-operability with other
components in the ecosystem. Until App isolation becomes a native mechanism
in the OS, WinFS recommends the classic namespace based isolation (for
isntance, Infopath uses the following folder for storing content specific to
Infopath - c:\Documents and Settings\simonsk\Application
Data\Microsoft\InfoPath).



--
Simon Skaria [MSFT]

simonsk@microsoft.com
This posting is provided "AS IS" with no warranties, and confers no rights




"Mario Goebbels [489782]" <fa001478@skynet.be.MAPS> wrote in message
news:eAy9F%23EQGHA.3872@TK2MSFTNGP15.phx.gbl...
> I've read the blog entry "WinFS Mailbox II", which cuts a bit into the
> topic of item security. However how will this be exposed by the UI?
>
> In my ideal world, items in the store would be assigned to
> application/system contexts. Each application can access its own context
> without restrictions. While other applications could search the files
> residing in other contexts, accessing them however would spawn a system
> dialog asking if you want to grant the application access to the single
> file, the whole context of the other application or plain out deny the
> access. Add a checkbox to make the decision permanent. This would put the
> data security in the hands of the user and notify him immediately when an
> application tries funny business. This would give for instance secure
> sensitive data of your Money version on WinFS the protection it needs
> while giving other applications the ability to access them under the
> control of the user.
>
> There should also be a system context, where the system files would
> reside, which are accessible by everyone under the control of the system,
> and a root context for global things that you want to be accessible
> without restrictions. That'd be contacts, mails and other insensitive
> items.
>
> Regards.
>
> -mg
>



  Reply With Quote
 
Reply

Thread Tools
Display Modes









Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Vistax64.com 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48