Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity

    Does Vendors Fix Philosophies Match Yours?

    Written by

    Jim Rapoza
    Published April 4, 2005
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Finally the long winter is over, and our thoughts turn to warm-weather pursuits. Some people will plan beach vacations, while others will turn to hiking, fishing and other outdoor activities.

      Me? Im planning that truly American experience of going to a big amusement park. But which one? The quality of rides and the cost are important considerations, but probably the biggest factor is the safety record of the park.

      Ive narrowed it down to two choices: the world-famous Jim World and the ubiquitous Great Rapoza Experience. Both parks have had about the same number of potential problems that require equipment maintenance, repairs or even outright redesigns. But both handle these problems differently.

      The Great Rapoza Experience typically announces every major or minor problem that it finds and rushes to fix it almost immediately. This has earned the park lots of good will in the hard-core ride enthusiast community. However, it also tends to lead to negative coverage in the press, which harps on the problems rather than on the fact that they were quickly fixed.

      Jim World, on the other hand, keeps as quiet as possible about most problems and fixes to problems. When there is a major issue, Jim World usually fixes it in good time, but the park also sits on many smaller problems and then quietly fixes them in quarterly park redesigns.

      Now that I think about it, these same factors can be found in the software world, and software buyers need to make similar decisions when purchasing applications.

      In last weeks column, I argued that software vendors should work with researchers who look for software vulnerabilities and that vendors should be open about the discovered problems. But when one looks at the many commercial and open-source software vendors out there, it is easy to see that there are many levels and definitions of openness.

      Some choose to address every single problem as it comes to light, an approach that is typical of—but not found solely in—open-source products. Others fix critical problems immediately but sit on smaller problems and fix them in big updates or service packs.

      Much of the discussion about these approaches tends to focus on the political issues. Vendor A might say that Vendor Bs products are insecure because Vendor B issues multiple fixes. Vendor B might then turn around and say that the single service pack Vendor A issued actually fixed 50 problems that people were exposed to in the months prior to the service packs release.

      But theres really no right answer when it comes to issuing software fixes. Open-source organizations often sit on smaller bugs for months and address them in a .0x release that is essentially a service pack. And commercial vendors will sometimes quickly address less-critical bugs that are affecting many users.

      For IT administrators, the political back and forth is much less important than which patching approach best fits their organizations security practices and system management procedures.

      With the “fix everything quickly” approach, the administrator benefits from knowing about a problem right away and promptly getting a fix. On the other hand, being put in a position of constantly having to decide which fixes need to be tested and deployed can add a sometimes-unmanageable load onto administrators backs.

      With the “fix most small problems in a big service pack” approach, administrators need only test a single big patch once, which can make deployment a lot easier. However, administrators may also have wasted months dealing with a problem whose fix was being saved for a service pack.

      So when looking at security as a deciding factor in choosing an application, you may want to focus less on the raw numbers and more on how the vendor or developer approaches bug and security fixes.

      As for my amusement park choice, all the data is pretty close, so Im going to have to go with what is by far the most influential factor for most people (and businesses): Im going to go with the amusement park that offers the biggest discount coupons.

      Labs Director Jim Rapoza can be reached at jim_rapoza@ziffdavis.com.

      To read more Jim Rapoza, subscribe to eWEEK magazine.

      Check out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Jim Rapoza
      Jim Rapoza
      Jim Rapoza, Chief Technology Analyst, eWEEK.For nearly fifteen years, Jim Rapoza has evaluated products and technologies in almost every technology category for eWEEK. Mr Rapoza's current technology focus is on all categories of emerging information technology though he continues to focus on core technology areas that include: content management systems, portal applications, Web publishing tools and security. Mr. Rapoza has coordinated several evaluations at enterprise organizations, including USA Today and The Prudential, to measure the capability of products and services under real-world conditions and against real-world criteria. Jim Rapoza's award-winning weekly column, Tech Directions, delves into all areas of technologies and the challenges of managing and deploying technology today.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×