Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Apple patches a pile of flaws
Search Topic:
Uniqs:
535
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates 23 Mar 2008 »
« Infected file  
AuthorAll Replies

C DM

join:2002-12-31

reply to Tommyastro
Re: Apple patches a pile of flaws

said by Tommyastro See Profile :

They do it MUCH faster then Microsoft does. MUCH faster.
Seems to be roughly on the same schedule, at least from frequency point of view.

Tommyastro

join:2004-01-18
Poughkeepsie, NY
reply to SUMware
They do it MUCH faster then Microsoft does. MUCH faster.

daveinpoway
Premium
join:2006-07-03
Poway, CA

reply to SUMware
Issues like this have caused me to wonder whether the security problems with "Patch Tuesday" outweigh the convenience to the corporate IT people. Apparently, the convenience aspect has won out, since I see no signs that Microsoft is going to change their patching model anytime soon.

SUMware
Premium
join:2002-05-21

reply to daveinpoway
said by daveinpoway See Profile :

Referring to the last sentence in the article, a more significant problem (at least to me, although they didn't talk about it) is that hackers can release malware targeting vulnerabilities which haven't been announced (or patched) yet on the day after Patch Tuesday, knowing that they will have a full month before Microsoft will do anything to close the door (unless it is such an extreme problem that MS will release an "out-of-cycle" patch).
Actually, this situation is described in the article. I just didn't post it above. But since you bring it up...
quote:
Security implications of Patch Tuesday

The most obvious security implication is that security problems that have a solution are withheld from the public for a period of up to a month. Implicitly, this policy assumes that most attacks use information reverse engineered from the security patches that fix the vulnerability, rather than true "Zero day attack" exploits. It is unknown to what extent this assumption is true.

In the past, there were some cases where either vulnerability information or actual worms were released to the public a day or two before patch Tuesday. This does not leave Microsoft enough time to incorporate a fix for said vulnerabilities, and thus, theoretically, leave a one month window for attackers or the worm to exploit the hole, before a patch is available to formally fix it. This phenomenon is unrelated to Exploit Wednesday.

Exploit Wednesday

Many exploits are seen shortly after the release of a patch. By analyzing the patch, exploit developers can more easily figure out how to exploit the underlying vulnerability. Therefore the term "Exploit Wednesday" was coined. Also, starting to abuse an exploit on this day gives malicious code writers the longest period of time before a fix is supplied to users. Malware authors can sit on a new exploit until after a given patch Tuesday, knowing that there will be an entire month before Microsoft releases any patch to fix it.

Other consequences

Immediately following Patch Tuesday, millions of computers are rebooted within a short period of time. This causes an exceptional strain on other internet companies. For example, in August 2007, Skype experienced a two-day outage following Patch Tuesday.

daveinpoway
Premium
join:2006-07-03
Poway, CA

reply to SUMware
Referring to the last sentence in the article, a more significant problem (at least to me, although they didn't talk about it) is that hackers can release malware targeting vulnerabilities which haven't been announced (or patched) yet on the day after Patch Tuesday, knowing that they will have a full month before Microsoft will do anything to close the door (unless it is such an extreme problem that MS will release an "out-of-cycle" patch).

SUMware
Premium
join:2002-05-21


1 edit
reply to daveinpoway
According to Wikipedia:
quote:
The Windows Update system suffered from two problems, affecting opposite ends of the users scale. On the one hand, less experienced users were not aware of it, and did not run it. Microsoft's solution was to introduce the concept of "Automatic Update", which would pro-actively inform the user that an update was available for their system.

The second problem affected large deployments of Windows, such as can be found at large companies. Such large deployments found it increasingly difficult to make sure all systems across the company were all up to date. The problem was made worse by the fact that, occasionally, a patch issued by Microsoft would break existing functionality, and would have to be uninstalled.

In order to reduce the costs related to the deployment of patches, Microsoft introduced the concept of Patch Tuesday. The idea is that security patches are accumulated over a period of one month, and then dispatched all at once on an anticipated date which system administrators can prepare for. This date was set not too close to the beginning of the week, and yet far enough from the end of the week to allow any problems that may arise to be resolved before the weekend. System administrators can mark the second Tuesday of the month as the "day in which machines are updated", and plan accordingly. The name "Patch Tuesday" has been in use since the third quarter of 2004. It is becoming synonymous for the day any software vendor issues a vulnerability patch. Some editors/analysts talk about "Exploit Wednesday" as the day after, or even "Day Zero" immediately following the update, when hackers can launch attacks against the newly announced vulnerabilities.
[emphasis added]

daveinpoway
Premium
join:2006-07-03
Poway, CA

reply to SUMware
The memory fades with time, but I can still recall a situation (prior to around 2002, if I am correct) when Microsoft always released patches when they were ready. Then, supposedly due to pressure from corporate IT folks, they switched to the "Patch Tuesday" model.

SUMware
Premium
join:2002-05-21


2 edits
reply to daveinpoway
said by daveinpoway See Profile :

If you depend on Microsoft for your patches, then you do not get them when they are ready (except in rare instances); you have to wait for the 2nd Tuesday of the month.
Sorry, should have been more specific. Was referring to Linux where patches/updates can become available within minutes of actual code fix, 24/7.


Greg_Z
Premium
join:2001-08-08
Springfield, IL
reply to SUMware
It is a safer platform, then Microsoft's. Keep in mind that the components that are being patched, are the same ones that get patched in Linux distro's.

daveinpoway
Premium
join:2006-07-03
Poway, CA
reply to SUMware
If you depend on Microsoft for your patches, then you do not get them when they are ready (except in rare instances); you have to wait for the 2nd Tuesday of the month.


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

reply to SUMware
Yup..can understand that..no one likes to feel vulnerable if they know there is a bad boy 'in the wild' that is targeting the flaw.
But I am just amazed sometimes at peoples reaction when a developer patches a product to improve it over time and we don't thank them for looking after our investment.
--
Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kids »www.missingkids.com/

SUMware
Premium
join:2002-05-21
reply to Name Game
Guess I'm just spoiled by getting my patches/fixes/updates as soon as available.


Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

reply to SUMware
said by SUMware See Profile :

Too bad that Apple doesn't provide patches as soon as OSS fixes become available. They do their users a great disservice by not providing a safe platform ASAP.
I think from a security point of view they also assess the risk factor in the numbers game.
»news.softpedia.com/newsImage/Win···ux-3.png

But if they can release those patches and have them fully tested before release so they do not whacked other stuff when installed or require even another patch only days later to correct some flaws. Then the users still are happy campers.
--
Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kids »www.missingkids.com/

SUMware
Premium
join:2002-05-21
reply to Cudni
Too bad that Apple doesn't provide patches as soon as OSS fixes become available. They do their users a great disservice by not providing a safe platform ASAP.


Cudni
La Merma - Vigilado
Premium,MVM
join:2003-12-20
Someshire

from
»www.securityfocus.com/brief/706
"...
Consumer technology company Apple released two updates on Tuesday to fix more than a hundred flaws in its Mac OS X operating system, the OS's open-source components and the company's Safari Web browser.
..."

Cudni
--
"Mercifully, he hit him with the soft end of the pistol."
Help yourself so God can help you.
Microsoft MVP, 2006-2007
Forums » Up and Running » Security » SecuritySecurity Software Updates 23 Mar 2008 »
« Infected file  


Thursday, 10-Dec 14:36:28 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [131] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [82] AT&T Hints At Usage-Based iPhone Data Pricing
· [72] Mediacom Unveils 105 Mbps Pricing
· [69] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [66] Sprint Poised For A Turnaround?
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [47] Average American Consumes 34 Gigabytes Daily
Most people now reading
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· [WIN7] Well, I was dumb, but do I have recourse? [Microsoft Help]
· New Mediacom Email [Mediacom]
· Will Gearscore die now? [World of Warcraft]
· Windows 7 boot manager editing questions [Microsoft Help]
· malware has been found hidden inside an Ubuntu screensaver [Security]
· Cross Server Dungeon Experience [World of Warcraft]
· 60GB would only last us two days! [TekSavvy]
· Icecrown 5-man strats [World of Warcraft]
· Adobe Flash Player version 10.0.42.34 [Security]