Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
One Patch to Rule Them All
Tim Mullen, 2002-09-30

A recent XP security hole begs the question, do we really want Microsoft to release individual fixes for every bug?

Comments Mode:
One Patch to Rule Them All 2002-09-30
Anonymous (1 replies)
One Patch to Rule Them All 2002-10-08
Anonymous
Security patchs are diffrent 2002-09-30
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous (1 replies)
One Patch to Rule Them All 2002-10-02
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous
RE: One Patch to Rule Them All 2002-10-01
Piroufreek
One Patch to Rule Them All 2002-10-01
Anonymous (1 replies)
One Patch to Rule Them All 2002-10-04
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous
One Patch to Rule Them All 2002-10-01
Todd Knarr
One Patch to Rule Them All 2002-10-01
mjc
Included in the recently released XP SP1 where patches and fixes for flaws that were discovered shortly after the retail release of XP, Microsoft released fixes for those flaws and vulnerabilities earlier. If they hadn't, but instead waited until the SP was released some of them would have been left "open" for nearly a year! That approach would be entirely intolerable.

Waiting until enough patches are gathered together to form a "Service Pack" just plays into the hands of those who would exploit those defects. Patching each hole or flaw as they are discovered is a saner approach. You don't wait until your roof is missing most of the shingles to start a repair. You repair the damaged shingles now, and maybe 6 months later, you might have to still put on a new roof, but at least the damage to the rest of your hose was kept to a minimum.

An earlier poster referred to Microsoft as treating security fixes as a PR problem. They do, because almost every one discovered is first met with denial by MS, then by "Oh, it isn't really all THAT bad...", and finally some sort of response, be it a patch or "Well, that version wasn't really meant to be secure, so you will have to upgrade to get the peace of mind you are seeking." All of which is a PR department's standard method of damage control...the problem does not exist, it isn't really a major one, shift the blame to someone/something else and finally do something (albeit half-heartedly) about it.



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/112/16660#16660
One Patch to Rule Them All 2002-10-02
security@NOdsia.SPAM.com
One Patch to Rule Them All 2002-10-03
Darkphyber
One Patch to Rule Them All 2002-10-03
iDENTiTY
One Patch to Rule Them All 2002-10-04
Anonymous
He should have called this article "Flame Bait"... 2002-10-09
Anonymouse (1 replies)
"Flame Bait" 2002-10-09
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus