Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Latest News

      Patching: We Merit Better

      Written by

      eWEEK Editorial Board
      Published May 16, 2005
      Share
      Facebook
      Twitter
      Linkedin

        While Microsoft is still a leader among software manufacturers in the dubious category of product vulnerability to attack, recent studies show that the software vendor has gotten better at plugging security holes.

        The SANS Institute partially credits Microsofts Automatic Update feature in Windows, which automatically downloads and installs security patches, but the institute also warns that a side effect has been to divert attackers energies to third-party applications lacking such streamlined support.

        Microsoft has shown commitment to securing its products and has made significant progress toward that goal. Disruptions such as those associated with Windows XP SP2 say more about third-party developers bad habits than about any failings on Microsofts part.

        We resist, though, the assumption that a broader use of automatic patching is the proper focus of improvement. Its not mainly the failure to respond to new threats thats the problem; its that vendors fail to ship high-quality products in the first place.

        /zimages/4/28571.gifClick here to read about Microsofts new security service intended to provide advisories between month bulletins.

        Automated patching is a decidedly mixed blessing. Systems cant be left vulnerable and unpatched, to be sure, and few IT departments can manually cope with the deluge of security patches.

        Microsoft alone inundates its customers with a set of security patches and fixes on the second Tuesday of every month.

        The automation of updates and patches alleviates to some extent the burden of user site management, but it also tends to ratify the assumption that its OK to ship poor-quality products.

        The volatility introduced into the enterprise code base by constant updating of executables, not to mention the consumption of network bandwidth, amounts to a significant subsidy of commercial software providers by their customers.

        As if that werent bad enough, the time lag of any patch cycle—automated or otherwise—is getting to be unacceptably long compared with the shortening time between the discovery and exploit of vulnerability. It took more than three months for Apple to issue a patch for a security hole made public in January that left the mRouter tool in iSync vulnerable to a buffer-overflow attack.

        IT pros who are doing their jobs right know that they must test patches before installing them in production systems. This IT best practice ought not to be sacrificed for vendors convenience.

        It would also be desirable, though, for Microsoft to build a framework within Windows that provides for flexible, unified updates of both Windows system components and individual applications; we would then urge participation from the independent development community in that initiative.

        We also believe that software vendors can and must do better and that their enterprise IT customers deserve better. Reducing the need for patches—not merely streamlining the process—must remain a critical priority for all software vendors.

        Tell us what you think at [email protected].

        /zimages/4/28571.gifCheck out eWEEK.coms for Microsoft and Windows news, views and analysis.

        eWEEK Editorial Board
        eWEEK Editorial Board

        Get the Free Newsletter!

        Subscribe to Daily Tech Insider for top news, trends & analysis

        Get the Free Newsletter!

        Subscribe to Daily Tech Insider for top news, trends & analysis

        MOST POPULAR ARTICLES

        Artificial Intelligence

        9 Best AI 3D Generators You Need...

        Sam Rinko - June 25, 2024 0
        AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
        Read more
        Cloud

        RingCentral Expands Its Collaboration Platform

        Zeus Kerravala - November 22, 2023 0
        RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
        Read more
        Artificial Intelligence

        8 Best AI Data Analytics Software &...

        Aminu Abdullahi - January 18, 2024 0
        Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
        Read more
        Latest News

        Zeus Kerravala on Networking: Multicloud, 5G, and...

        James Maguire - December 16, 2022 0
        I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
        Read more
        Video

        Datadog President Amit Agarwal on Trends in...

        James Maguire - November 11, 2022 0
        I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
        Read more
        Logo

        eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

        Facebook
        Linkedin
        RSS
        Twitter
        Youtube

        Advertisers

        Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

        Advertise with Us

        Menu

        • About eWeek
        • Subscribe to our Newsletter
        • Latest News

        Our Brands

        • Privacy Policy
        • Terms
        • About
        • Contact
        • Advertise
        • Sitemap
        • California – Do Not Sell My Information

        Property of TechnologyAdvice.
        © 2024 TechnologyAdvice. All Rights Reserved

        Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.