The Artima Developer Community
Sponsored Link

.NET Buzz Forum
On Microsoft's new Security Bulletin release scheduling

0 replies on 1 page.

Welcome Guest
  Sign In

Go back to the topic listing  Back to Topic List Click to reply to this topic  Reply to this Topic Click to search messages in this forum  Search Forum Click for a threaded view of the topic  Threaded View   
Previous Topic   Next Topic
Flat View: This topic has 0 replies on 1 page
Frans Bouma

Posts: 265
Nickname: fbouma
Registered: Aug, 2003

Frans Bouma is a senior software engineer for Solutions Design
On Microsoft's new Security Bulletin release scheduling Posted: Oct 22, 2003 6:21 AM
Reply to this message Reply

This post originated from an RSS feed registered with .NET Buzz by Frans Bouma.
Original Post: On Microsoft's new Security Bulletin release scheduling
Feed Title: Frans Bouma's blog
Feed URL: http://www.asp.net/err404.htm?aspxerrorpath=/fbouma/Rss.aspx
Feed Description: Generator.CreateCoolTool();
Latest .NET Buzz Posts
Latest .NET Buzz Posts by Frans Bouma
Latest Posts From Frans Bouma's blog

Advertisement

I read The Inquirer every day through their RSS feed, and although its often amusing, they now have a very valid point: Microsoft's new release policy according to security fixes/bulletins is completely irresponsible.

Microsoft has now decided to release security bulletins and fixes only once a month, to make it more predictable when they are released and sysadmins can now plan upgrades easier. When I read that the first time, I thought: "WTF!? What are they thinking?". And it is still my opinion about the matter. This is serious stuff, people: when the Thursday after the security fixes are released a flaw is discovered and posted on the security focus forums, you have to wait at least another month before you get the fix, instead of the old situation where you could expect a fix perhaps within 2 days.

I simply don't see how a company that thinks security is its top priority, leaves customers in the dark by not handing out fixes when they are available, but waits until a scheduled release date is reached. How does that help security? It only helps crackers and scriptkiddies to enter our servers because we can't patch the software with a patch that is already done. It is easier for sysadmins because they can now schedule downtime and patch the systems with an easy one-exe-for-all-the-fixes-download but it comes with a cost: it leaves systems vulnerable while patches are done.

Sorry Mr. Ballmer, you can shout as hard as you can how much effort Microsoft is putting into security, there is still one thing that you don't understand after all these years: when you make security your top priority, it is then thus more important than usability, however up till today, usability seems to be more important than security. We're talking sysadmins here, for crying out loud. Monthly patches? Great idea, but at least offer the patches as separate downloads also for the people who want to patch their systems when the patch is released. Thank you.

Read: On Microsoft's new Security Bulletin release scheduling

Topic: Oracle 9i is already generations ahead and shows a .NET flaw. Previous Topic   Next Topic Topic: I will be on .NET Rocks Nov 4th!

Sponsored Links



Google
  Web Artima.com   

Copyright © 1996-2019 Artima, Inc. All Rights Reserved. - Privacy Policy - Terms of Use