Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
The Reality of Perception
Tim Mullen, 2003-04-07

A new poll finds that seventy-seven percent of security professionals believe Microsoft products are insecure. But a closer look at the survey tells a far more interesting story.

Comments Mode:
The Reality of Perception 2003-04-07
Anonymous (6 replies)
The Reality of Perception 2003-04-07
Bill Hey <bill.hey@nospam.dsia.com>
The Reality of Perception 2003-04-07
Peter
The Reality of Perception 2003-04-08
R Mortimer
It's not just market share 2003-04-08
Anonymous
Re: AnonymousPeon 2003-04-08
Just a point
Sorry, that's crap 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-07
AnonymousPeon (2 replies)
The Reality of Perception 2003-04-07
Anonymous
The Reality of Perception - heh 2003-04-07
Anonymous (1 replies)
The Reality of Perception - 2003-04-08
AnonymousPeon (1 replies)
The Reality of Perception - 2003-04-09
Anonymous (1 replies)
The Reality of Perception 2003-04-07
ralf
The Reality of Perception 2003-04-07
Bill Hey <bill.hey@nospam.dsia.com> (1 replies)
The Reality of Perception 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-09
anonybori
The Reality of Perception 2003-04-07
Scott Sorrentino (1 replies)
Your references to Code Red and Nimda are fair; admins who still get bit by them deserve it for being slow (glacial)to apply patches.

However, I know *many* Windows admins who don't bother patching right away because Microsoft has a history of releasing patches that solve one problem and create others. Sometimes to the point that the OS becomes unusable. To fault these folks for not jumping immediately on the patch bandwagon is unfair. They're slow to react because they've been burned before.

It's not enough for a company to simply release a patch. Despite the pressure to post a fix ASAP, it's also equally important to ensure the fix (a) solves the problem and (b) does not cause any others.

Of course, none of this addresses the larger issue of "we don't trust it but we actively deploy it". Perhaps it's market factors (customer who *have* to have Microsoft for their server platform) or organizational ("so-and-so says we can only do it with Microsoft products"). I guess we won't know why until someone orders that survey ;)

Scott Sorrentino
scott@kill-hup.com
http://www.kill-hup.com/

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/152/19194#19194
Stupid unstable patches 2003-04-08
Anonymous
The Reality of Perception 2003-04-07
Anonymous
The Reality of Perception 2003-04-07
Penguinisto (1 replies)
The Reality of Perception 2003-04-08
Anonymous
The reality of your techs 2003-04-07
Andy Wood
The Reality of Perception 2003-04-07
Anonymous (2 replies)
The Reality of Perception 2003-04-08
Anonymous
The Reality of Perception 2003-04-07
Anonymous
The Reality of Perception 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-09
Anonymous
The Reality of Perception 2003-04-08
Anonymous (1 replies)
The Reality of Perception 2003-04-09
Gary Fisher
The Reality of Perception 2003-04-08
Anonymous
My look on things 2003-04-08
DC0 (1 replies)
My look on things 2003-04-10
Anonymous
It's easy Tim - listen up! 2003-04-08
Anonymous
The Reality of Perception 2003-04-08
Wisconsin (1 replies)
The Reality of Perception 2003-04-10
blacklight
dont blame MS-blame these stupid poeple 2003-04-10
ab_s0248@yahoo.com
The Reality of Perception 2003-04-10
Anonymous
Patch Management 2003-04-11
mesmer
The Reality of Perception 2003-04-11
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus