republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Apple patches a pile of flaws
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates 23 Mar 2008 »
« Infected file  
AuthorAll Replies

daveinpoway
Premium
join:2006-07-03
Poway, CA
reply to SUMware
Re: Apple patches a pile of flaws

If you depend on Microsoft for your patches, then you do not get them when they are ready (except in rare instances); you have to wait for the 2nd Tuesday of the month.

SUMware
Premium
join:2002-05-21


2 edits
said by daveinpoway See Profile :

If you depend on Microsoft for your patches, then you do not get them when they are ready (except in rare instances); you have to wait for the 2nd Tuesday of the month.
Sorry, should have been more specific. Was referring to Linux where patches/updates can become available within minutes of actual code fix, 24/7.

daveinpoway
Premium
join:2006-07-03
Poway, CA

The memory fades with time, but I can still recall a situation (prior to around 2002, if I am correct) when Microsoft always released patches when they were ready. Then, supposedly due to pressure from corporate IT folks, they switched to the "Patch Tuesday" model.

SUMware
Premium
join:2002-05-21


1 edit
According to Wikipedia:
quote:
The Windows Update system suffered from two problems, affecting opposite ends of the users scale. On the one hand, less experienced users were not aware of it, and did not run it. Microsoft's solution was to introduce the concept of "Automatic Update", which would pro-actively inform the user that an update was available for their system.

The second problem affected large deployments of Windows, such as can be found at large companies. Such large deployments found it increasingly difficult to make sure all systems across the company were all up to date. The problem was made worse by the fact that, occasionally, a patch issued by Microsoft would break existing functionality, and would have to be uninstalled.

In order to reduce the costs related to the deployment of patches, Microsoft introduced the concept of Patch Tuesday. The idea is that security patches are accumulated over a period of one month, and then dispatched all at once on an anticipated date which system administrators can prepare for. This date was set not too close to the beginning of the week, and yet far enough from the end of the week to allow any problems that may arise to be resolved before the weekend. System administrators can mark the second Tuesday of the month as the "day in which machines are updated", and plan accordingly. The name "Patch Tuesday" has been in use since the third quarter of 2004. It is becoming synonymous for the day any software vendor issues a vulnerability patch. Some editors/analysts talk about "Exploit Wednesday" as the day after, or even "Day Zero" immediately following the update, when hackers can launch attacks against the newly announced vulnerabilities.
[emphasis added]

daveinpoway
Premium
join:2006-07-03
Poway, CA

Referring to the last sentence in the article, a more significant problem (at least to me, although they didn't talk about it) is that hackers can release malware targeting vulnerabilities which haven't been announced (or patched) yet on the day after Patch Tuesday, knowing that they will have a full month before Microsoft will do anything to close the door (unless it is such an extreme problem that MS will release an "out-of-cycle" patch).

SUMware
Premium
join:2002-05-21

said by daveinpoway See Profile :

Referring to the last sentence in the article, a more significant problem (at least to me, although they didn't talk about it) is that hackers can release malware targeting vulnerabilities which haven't been announced (or patched) yet on the day after Patch Tuesday, knowing that they will have a full month before Microsoft will do anything to close the door (unless it is such an extreme problem that MS will release an "out-of-cycle" patch).
Actually, this situation is described in the article. I just didn't post it above. But since you bring it up...
quote:
Security implications of Patch Tuesday

The most obvious security implication is that security problems that have a solution are withheld from the public for a period of up to a month. Implicitly, this policy assumes that most attacks use information reverse engineered from the security patches that fix the vulnerability, rather than true "Zero day attack" exploits. It is unknown to what extent this assumption is true.

In the past, there were some cases where either vulnerability information or actual worms were released to the public a day or two before patch Tuesday. This does not leave Microsoft enough time to incorporate a fix for said vulnerabilities, and thus, theoretically, leave a one month window for attackers or the worm to exploit the hole, before a patch is available to formally fix it. This phenomenon is unrelated to Exploit Wednesday.

Exploit Wednesday

Many exploits are seen shortly after the release of a patch. By analyzing the patch, exploit developers can more easily figure out how to exploit the underlying vulnerability. Therefore the term "Exploit Wednesday" was coined. Also, starting to abuse an exploit on this day gives malicious code writers the longest period of time before a fix is supplied to users. Malware authors can sit on a new exploit until after a given patch Tuesday, knowing that there will be an entire month before Microsoft releases any patch to fix it.

Other consequences

Immediately following Patch Tuesday, millions of computers are rebooted within a short period of time. This causes an exceptional strain on other internet companies. For example, in August 2007, Skype experienced a two-day outage following Patch Tuesday.

daveinpoway
Premium
join:2006-07-03
Poway, CA

Issues like this have caused me to wonder whether the security problems with "Patch Tuesday" outweigh the convenience to the corporate IT people. Apparently, the convenience aspect has won out, since I see no signs that Microsoft is going to change their patching model anytime soon.
Forums » Up and Running » Security » SecuritySecurity Software Updates 23 Mar 2008 »
« Infected file  


Saturday, 05-Dec 23:51:40 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [128] Comcast Makes NBC Universal Acquisition Official
· [122] The Bandwidth Hog Does Not Exist
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [80] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· False positive in Avast! or is it real? [Security]
· How fast is your upstream internet connection? [General Questions]
· First commercial tool to crack BitLocker arrives (Updated) [Security]
· Windows 7 boot manager editing questions [Microsoft Help]
· What is this thing for? [Home Repair & Improvement]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· [northeast] Well it's done... [Verizon Fiber Optics]
· HVAC - Leaving a bedroom window open? [Home Repair & Improvement]
· A reminder [Mediacom]