Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Apple patches a pile of flaws
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates 23 Mar 2008 »
« Infected file  
AuthorAll Replies

SUMware
Premium
join:2002-05-21


2 edits
reply to daveinpoway
Re: Apple patches a pile of flaws

said by daveinpoway See Profile :

If you depend on Microsoft for your patches, then you do not get them when they are ready (except in rare instances); you have to wait for the 2nd Tuesday of the month.
Sorry, should have been more specific. Was referring to Linux where patches/updates can become available within minutes of actual code fix, 24/7.

daveinpoway
Premium
join:2006-07-03
Poway, CA

The memory fades with time, but I can still recall a situation (prior to around 2002, if I am correct) when Microsoft always released patches when they were ready. Then, supposedly due to pressure from corporate IT folks, they switched to the "Patch Tuesday" model.

SUMware
Premium
join:2002-05-21


1 edit
According to Wikipedia:
quote:
The Windows Update system suffered from two problems, affecting opposite ends of the users scale. On the one hand, less experienced users were not aware of it, and did not run it. Microsoft's solution was to introduce the concept of "Automatic Update", which would pro-actively inform the user that an update was available for their system.

The second problem affected large deployments of Windows, such as can be found at large companies. Such large deployments found it increasingly difficult to make sure all systems across the company were all up to date. The problem was made worse by the fact that, occasionally, a patch issued by Microsoft would break existing functionality, and would have to be uninstalled.

In order to reduce the costs related to the deployment of patches, Microsoft introduced the concept of Patch Tuesday. The idea is that security patches are accumulated over a period of one month, and then dispatched all at once on an anticipated date which system administrators can prepare for. This date was set not too close to the beginning of the week, and yet far enough from the end of the week to allow any problems that may arise to be resolved before the weekend. System administrators can mark the second Tuesday of the month as the "day in which machines are updated", and plan accordingly. The name "Patch Tuesday" has been in use since the third quarter of 2004. It is becoming synonymous for the day any software vendor issues a vulnerability patch. Some editors/analysts talk about "Exploit Wednesday" as the day after, or even "Day Zero" immediately following the update, when hackers can launch attacks against the newly announced vulnerabilities.
[emphasis added]

daveinpoway
Premium
join:2006-07-03
Poway, CA

Referring to the last sentence in the article, a more significant problem (at least to me, although they didn't talk about it) is that hackers can release malware targeting vulnerabilities which haven't been announced (or patched) yet on the day after Patch Tuesday, knowing that they will have a full month before Microsoft will do anything to close the door (unless it is such an extreme problem that MS will release an "out-of-cycle" patch).

SUMware
Premium
join:2002-05-21

said by daveinpoway See Profile :

Referring to the last sentence in the article, a more significant problem (at least to me, although they didn't talk about it) is that hackers can release malware targeting vulnerabilities which haven't been announced (or patched) yet on the day after Patch Tuesday, knowing that they will have a full month before Microsoft will do anything to close the door (unless it is such an extreme problem that MS will release an "out-of-cycle" patch).
Actually, this situation is described in the article. I just didn't post it above. But since you bring it up...
quote:
Security implications of Patch Tuesday

The most obvious security implication is that security problems that have a solution are withheld from the public for a period of up to a month. Implicitly, this policy assumes that most attacks use information reverse engineered from the security patches that fix the vulnerability, rather than true "Zero day attack" exploits. It is unknown to what extent this assumption is true.

In the past, there were some cases where either vulnerability information or actual worms were released to the public a day or two before patch Tuesday. This does not leave Microsoft enough time to incorporate a fix for said vulnerabilities, and thus, theoretically, leave a one month window for attackers or the worm to exploit the hole, before a patch is available to formally fix it. This phenomenon is unrelated to Exploit Wednesday.

Exploit Wednesday

Many exploits are seen shortly after the release of a patch. By analyzing the patch, exploit developers can more easily figure out how to exploit the underlying vulnerability. Therefore the term "Exploit Wednesday" was coined. Also, starting to abuse an exploit on this day gives malicious code writers the longest period of time before a fix is supplied to users. Malware authors can sit on a new exploit until after a given patch Tuesday, knowing that there will be an entire month before Microsoft releases any patch to fix it.

Other consequences

Immediately following Patch Tuesday, millions of computers are rebooted within a short period of time. This causes an exceptional strain on other internet companies. For example, in August 2007, Skype experienced a two-day outage following Patch Tuesday.

daveinpoway
Premium
join:2006-07-03
Poway, CA

Issues like this have caused me to wonder whether the security problems with "Patch Tuesday" outweigh the convenience to the corporate IT people. Apparently, the convenience aspect has won out, since I see no signs that Microsoft is going to change their patching model anytime soon.
Forums » Up and Running » Security » SecuritySecurity Software Updates 23 Mar 2008 »
« Infected file  


Saturday, 28-Nov 10:24:13 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [122] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [72] TiVo Sees Record Customer Losses
· [69] In-Flight Internet Headed For Bumpy Landing?
· [69] Verizon CEO: Hulu Will Be Dead Soon
· [62] Thanksgiving Open Thread
· [54] Weekend Open Thread
· [40] EFF Wages War On Fine Print
Most people now reading
· Motion Sickness Solutions? [General Questions]
· Windows 7 boot manager editing questions [Microsoft Help]
· Using AirMax to provide triple play services? [Wireless Service Providers]
· Why does it take so long? Mail question [General Questions]
· Hosts file attributes set to system and hidden [Security]
· Not strictly "Home" related - but WOW anyways... [Home Repair & Improvement]
· [Newsgroups] Newzleech down? [Filesharing Software]
· What to use while demonoid is down? [Filesharing Software]
· [Vista] Why is HD So Full? [Microsoft Help]
· Is Gear Score now the new requirement to get pug invite? [World of Warcraft]