, SecurityFocus 2006-08-22
UPDATE: Microsoft continued to work on Tuesday to create a fix for an exploitable flaw introduced by the company's latest security update to Internet Explorer.
Expand all |
Post comment
Microsoft patch opens users to attack
2006-08-23
TJ (1 replies)
TJ (1 replies)
Re: Microsoft patch opens users to attack
2006-08-24
Matthew Murphy (2 replies)
Matthew Murphy (2 replies)

I'm choosing NOT to give Microsoft "credit" for their blog postings, because they:
a) made the blog postings only after eEye announced the vulnerability.
b) claimed publicly in prior blogs on the same sites that the issue was a simple crash, when the authors knew otherwise.
c) chose to attack eEye and continue to insist that deceiving customers was in the public interest.
Not only was the patch broken, but Microsoft's public statements are blatantly false up to the point where they are publicly corrected. It is my belief that those statements violated multiple federal laws on false and misleading marketing claims.
Accordingly, Microsoft deserves a thorough scolding for how they handled this incident, not "credit", as you seem intent on showering them with. Microsoft is the only vendor in the software business able to get away with such conduct and not face a substantial penalty in the marketplace, and is only so because its technology is a proprietary monopoly.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/11408/34030#34030