On mySimon: Pride and Prejudice and Zombies
BNET Business Network:
BNET
TechRepublic
ZDNet

By Patrick Gray
Posted on ZDNet News: Nov 11, 2003 1:10:00 PM

Microsoft plans to make available a series of security patches Tuesday in line with its new policy of releasing patches on a monthly basis.

The company announced its shift to a monthly patching cycle as a part of a new security initiative unveiled at its Worldwide Partner Conference in New Orleans last month. Microsoft said it was introducing the new schedule to ease the burden on systems administrators struggling with the frequency of security updates. Industry sources anticipate the disclosure of multiple vulnerabilities in the Windows operating system.

However, security professionals have avoided giving Microsoft's policy shift the thumbs-up, saying the effect is likely to be neutral. Greg Shipley, co-founder and chief technology officer of U.S.-based security company Neohapsis, said the new policy will actually make some things harder.

"The measuring stick is the volume of patches, not the release times," he said by phone from Chicago. "It's difficult because now we have to regression-test all these patches in one lump sum."

On the surface, the policy is a good one, Shipley said, because system administrators have to schedule only one service outage window a month. "But now you apply a bunch of patches, and (if) something 'breaks,' which one do you back up on?"

Shipley says the policy needs to be flexible in order for Microsoft to appropriately affect its customers. "If a hole is found in the wild...they should respond in a timely manner regardless of their patch cycle," he said. "But if they're doing controlled releases, then I'm not sure if it matters that much."

Security professional and former chief security officer of InterNIC Richard Forno also highlights the large time between updates as a potential source of risk.

"Perhaps it makes it easier for the system administrators to do one major fix-it patch instead of several each month, but that means there's a greater window of opportunity for a bad guy to cause damage between patch cycles," he said. "Watch for the next major Windows exploits to occur within a week of a monthly patch being released by Microsoft."

"If I was a bad guy, that's when I'd release my malicious exploits," he added.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 68 Talkback(s)
Major Security Problem
I am currently taking my Computer Network Technition Certificate and after finding out more about hacking and such I feel that this is not a good move. I will allow someone up to one month to access ... (Read the rest)
Posted by: jasonrodgers Posted on: 11/20/03 You are currently: a Guest | | Terms of Use
the only patch is Linux!  screaming silence | 11/11/03
Not So Fast!  ShadeTree | 11/11/03
Way, way off !  Spoon Jabber | 11/11/03
Your the one that is clueless.  ShadeTree | 11/11/03
It's fun, failing to apostrophise, when calling someone cluesless isn't it?  dw@... | 11/11/03
Wrong Assumption  ShadeTree | 11/11/03
Well thats nice saying I use RedHat but........  Some_one | 11/11/03
ASS U ME  ryusen | 11/12/03
Your argument is patchy at best  chrichton99 | 11/11/03
A little one sided?  Spoon Jabber | 11/11/03
Links?  chrichton99 | 11/11/03
Errata Listing  ShadeTree | 11/11/03
Ask "shadetree" he came up with 485  Spoon Jabber | 11/11/03
Service Packs  Some_one | 11/11/03
This is a dumb question, really dumb  NoB$ | 11/11/03
Waitasec...  chrichton99 | 11/11/03
Here's what.  libertyaikido | 11/11/03
Will M$ shills ever understand the motives?  NoB$ | 11/11/03
(NT) No they won't ; Blind leading the blind?  Spoon Jabber | 11/11/03
70% of Web Servers ???  ShadeTree | 11/11/03
70% is about right  chrichton99 | 11/11/03
And your point is?  NoB$ | 11/11/03
All the above  ShadeTree | 11/11/03
Wouldn't ms target linux with virii....  Spoon Jabber | 11/11/03
Please don't feed the trolls. (n/t)  Damon K | 11/11/03
Please don't feed the trolls  NoB$ | 11/11/03
Because it encourages them!  Damon K | 11/11/03
what i fear  ryusen | 11/12/03
Because it encourages them!  SC-man | 11/12/03
Man, your posts are getting....  BitTwiddler | 11/11/03
Screaming silence, please review the Terms Of Use.  GraysonPeddie | 11/11/03
It's the unscheduled outages that is the problem  issthatso | 11/11/03
Good idea, great OS  Mike Cox | 11/11/03
Isn't that what they promised with Server 2003  doctormoriarty | 11/11/03
Have faith, you have potential  Mike Cox | 11/11/03
I've met some of Microsoft's programmers and I'm sure you're right.  dw@... | 11/11/03
Exactly  Mike Cox | 11/11/03
Re: Exactly  dw@... | 11/11/03
eXPerience???  jasonp@... | 11/11/03
Don't knock it, he's spent years in BiCaPiTaLiSaTiOn school!  dw@... | 11/11/03
RE: what u said  Enton Eller | 11/11/03
What is the problem?  jellyclock | 11/11/03
Passion and Hatred ....  IS Girl | 11/11/03
Much like irrational hatred of all things Apple  MacCanuck | 11/11/03
More Choice?  MalumRegnat | 11/11/03
question about apple  lmaxwell | 11/11/03
Subjective but a better experience...  MacCanuck | 11/12/03
Depends on what your defintion of choice is..  Rick_K | 11/13/03
Passion and Hatred ....  NoB$ | 11/11/03
I think you're seeing...  Damon K | 11/11/03
Why the passion and hatred?  Anton Philidor | 11/11/03
Resentment???  slopoke | 11/12/03
Once a month is a PR move  Chad_z | 11/11/03
You get what you pay for..  IS Girl | 11/11/03
Once a month is a PR move  SC-man | 11/12/03
Only up to 30 days  FirstNLastN | 11/11/03
Learn to read.  acomtois@... | 11/12/03
Microsoft Patch Day  rgriffith64@... | 11/11/03
What will ZDNet fill in the other 3 Thursdays a week with  Knorthern Knight | 11/11/03
They should do both,  JoeMama_z | 11/11/03
just because  lmaxwell | 11/11/03
Get off the Microsoft bandwagon  ka5vcq | 11/11/03
You're right, but...  Spoon Jabber | 11/11/03
Huh?  Rick_K | 11/13/03
Questionable Practices  michael-t | 11/11/03
I don't see a problem...  acomtois@... | 11/12/03
So, in other words...  Spoon Jabber | 11/12/03
Major Security Problem  jasonrodgers | 11/20/03

What do you think?

advertisement

White Papers, Webcasts, and Downloads