, SecurityFocus 2004-06-28
SYDNEY, Australia--Microsoft chairman Bill Gates defended the company's handling of security patches Monday following widespread attacks on the Internet by suspected Russian organized crime gangs.
Expand all |
Post comment
Gates Lies
2004-06-29
Daniel Convissor (3 replies)
Daniel Convissor (3 replies)
Anti-Microsoft FanBoys
2004-06-30
Just Some guy (11 replies)
Just Some guy (11 replies)
Point of Clarification: Gates Defends Microsoft Patch Efforts
2004-07-01
http-equiv (at) excite (dot) com [email concealed]
http-equiv (at) excite (dot) com [email concealed]
Gates Defends Microsoft Patch Efforts
2004-07-05
PanzerPsycho (at) yahoo (dot) com [email concealed]
PanzerPsycho (at) yahoo (dot) com [email concealed]

Yes, two months really isn't too bad for a closed source vendor, and certainly has come down from the bad old days. But it's 30 times worse than BG claims, and of course his *average* has to take into account things like the shatter attack, which MS took something like 5 years to address!
And strictly speaking averages aren't the useful figure here. Worst case is what worries admins, since the crackers only need one exploit. However, worst case might be too severely skewed by things like the shatter attack. Maybe 99th percentile? (i.e. "99% of our vulnerabilities are fixed in less than six months", or whatever.)
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/9004/27241#27241