BugTraq
RE: Windows Update: A single point of failure for the world's economy? Aug 19 2003 06:01PM
Russ (Russ Cooper rc on ca) (1 replies)
Re: Windows Update: A single point of failure for the world's economy? Aug 31 2003 07:01PM
Stefano Zanero (stefano zanero ieee org) (3 replies)
Re: Windows Update: A single point of failure for the world's economy? Sep 03 2003 03:56PM
Paul Schmehl (pauls utdallas edu) (4 replies)
Re: Windows Update: A single point of failure for the world's economy? Sep 04 2003 02:57PM
Barry Fitzgerald (bkfsec sdf lonestar org)
Re: Windows Update: A single point of failure for the world's economy? Sep 04 2003 08:45AM
Stefano Zanero (stefano zanero ieee org)
Re: Windows Update: A single point of failure for the world's economy? Sep 03 2003 10:11PM
Jeremy C. Reed (reed reedmedia net)
Re: Windows Update: A single point of failure for the world's economy? Sep 03 2003 10:02PM
Kurt Seifried (bt seifried org)
Re: Windows Update: A single point of failure for the world's economy? Sep 03 2003 03:12PM
Andrew Gideon (jk28j381jdl30 gideon org)
Re: Windows Update: A single point of failure for the world'seconomy? Sep 03 2003 12:16PM
Lawrence MacIntyre (lpz ornl gov)
Stefano:

I rebuilt my Windows 2000 system from scratch this spring because of an
update. I can't remember the patch number anymore, but I remember that
it was a critical security update. I also remember reading about it the
day after it happened to me. Supposedly it was related to another patch
that had been previously applied and it only happened to W2K Pro. The
symptom was that the machine blue-screened during startup. Safe Mode
didn't help.

Now I don't let Windows Update touch my machine until the patch has been
there for about 2 weeks and I haven't heard anything bad about it.

On Sun, 2003-08-31 at 15:01, Stefano Zanero wrote:
> > I know of no patch which caused all systems to shutdown, or refuse to
> reboot.
>
> Ahem, Russ, this is something of a bold claim, unless you stress the ALL :)
> There have been some deeply troubling patches in the past, I hope you're not
> trying to dismiss that.
>
> And about mis-signatures, may I remind you of the fact that a Microsoft
> certificate was wrongly released and signed by Verisign a number of months
> ago ?
>
> Enabling a world-wide auto-update feature does indeed seem much of a
> security risk to me.
>
> Regards,
> Stefano
>
>

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus