Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Security Patches by Modem? Forget it!
Scott Granneman, 2004-03-24

Let's face it - there is no way for dial-up users on any major operating system to keep their computers up-to-date and patched. OK, maybe "no way" is an exaggeration. How about, "a difficult, burdensome, time-consuming, very prone to failure way?"

Comments Mode:
CVSUP works via modem 2004-03-24
Anonymous
Security Patches by Modem? Forget it! 2004-03-24
Ed Habal (1 replies)
Security Patches by Modem? Forget it! 2004-03-25
Gerhard Rickert (1 replies)
Security Patches by Modem? Forget it! 2004-03-25
rarchimedes
This is possibly the simplest, best exposition of this problem that I have seen. As a consultant, I despair of finding ways to keep my dial-up customers current. Most of them just give up, repeatedly, despite my best efforts to encourage or terrify them. Six months old security updates are completely inadequate. Such CD's should be cumulative and updated at least once a month even if they are only shipped quarterly. The huge sump of unprotected users out there are affecting all of the internet, and this includes broadband users.

Now, I do have one further problem with MS on this front. They casually include function updates along with critical updates. Those should be in a completely separate process on a separate CD, requiring clear, short summaries of EULA changes or things like DRM that are included in new products. For example, I will not allow my customers to install any WMP functional updates, because of the DRM implications of recent versions. On the other hand, I do want them to have security updates, always. DRM is not a security issue, period, exclamation point. MS use of it's update function to stealthily extend it's reach and control should be actionable under any number of laws.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/230/25575#25575
Easing the burden 2004-03-25
InvisiBill
Funny, I did this on Saturday... 2004-03-25
Anonymous
Microsoft's CD 2004-03-27
Anonymous
550mb of patches/upgrades? 2004-03-28
Anonymous
Slipstream 2004-03-29
Anonymous







 

Privacy Statement
Copyright 2009, SecurityFocus