Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
One Patch to Rule Them All
Tim Mullen, 2002-09-30

A recent XP security hole begs the question, do we really want Microsoft to release individual fixes for every bug?

Comments Mode:
One Patch to Rule Them All 2002-09-30
Anonymous (1 replies)
One Patch to Rule Them All 2002-10-08
Anonymous
Security patchs are diffrent 2002-09-30
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous (1 replies)
One Patch to Rule Them All 2002-10-02
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous
RE: One Patch to Rule Them All 2002-10-01
Piroufreek
One Patch to Rule Them All 2002-10-01
Anonymous (1 replies)
One Patch to Rule Them All 2002-10-04
Anonymous
One Patch to Rule Them All 2002-10-01
Anonymous
One Patch to Rule Them All 2002-10-01
Todd Knarr
One Patch to Rule Them All 2002-10-02
security@NOdsia.SPAM.com
One Patch to Rule Them All 2002-10-03
Darkphyber
I don't agree with your argument at all. The current MS strategy of delaying the release of fixes until they can be bundled into a roll-up, or SP leaves can leave the end-user vulnerable for weeks, months or even years. There is certainly an advantage to bunlding all of your security updates for a particular product at regular intervals. However, that should not replace the incremental/individual fixes even if they aren't considered to be critical at the time. Another important issue that you mentioned in your article is that people don't want to wait to download large monolithic security patches, especially those on slower links. Incremental patches can help in this area as they download quicker. These smaller updates can also be queued and downloaded in the background while users go about their business. Windows XP does this nicely, and can be configured to install automatically, or to prompt the user for confirmation before installation. It's not a perfect solution, but it will certainly help to catch those users who would otherwise be less likely to download those fixes.

-=darkphyber=-

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/112/16675#16675
One Patch to Rule Them All 2002-10-03
iDENTiTY
One Patch to Rule Them All 2002-10-04
Anonymous
He should have called this article "Flame Bait"... 2002-10-09
Anonymouse (1 replies)
"Flame Bait" 2002-10-09
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus