Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Patches That Patch

    Written by

    Brian Livingston
    Published November 17, 2003
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The “Patch-A-Month Club” was to have made life simpler for Microsoft customers. Instead, its life as before—which leaves much to be desired. In moving to a monthly schedule for routine patches, Microsoft intended to make it easier for customers to maintain stable and secure systems. But in the weeks the program has been in effect, the company has had to violate the monthly timetable by issuing more frequent patches—and even patching the patches that it issued.

      “Even though theyve changed to monthly, theyve already made some changes off the schedule,” said an IT professional at Time, who asked not to be named. “So theyve officially changed—but not really.”

      Microsofts policy of batching patches began Oct. 15. On that date, the company released five Windows security bulletins, four of them rated “critical,” plus two bulletins specifically for Exchange Server. The next batch wasnt due until Nov. 11. The new schedule is potentially a great idea that can protect your enterprise against script kiddies if you roll out needed vulnerability fixes as soon as theyre available.

      But on Oct. 22, Microsoft released a new version of one of the Windows patches and, on Oct. 24, a new version of one of the Exchange patches. On Oct. 29, three of the Windows patches were modified and reissued—including one for the revised Windows patch that had been issued just one week earlier. The latest round of revisions, Microsoft acknowledges, keeps the three initial Windows patches from hanging machines in certain cases when theyre installed (see www.bri.li/3461).

      No one would argue that Microsoft shouldnt have issued fixed patches when it learned of significant problems. Software isnt perfect and never will be. But Microsoft customers deserve to feel safe relying on Microsofts megapatches every month. Most people wont feel safe if they keep getting patches with unadvertised side effects that disrupt their work. More important, their systems wont be fully secure.

      These issues trouble even big believers in the new monthly patch policy. For example, Roger Wilding, senior technical engineer for CNF, a global supply chain service company, supports the new schedule, saying, “It actually makes it easier for us to understand. As long as there isnt a critical vulnerability thats going around the Net right now, we can wait until the second Tuesday of the month.” Wilding uses the Software Update Services Feature Pack of Microsofts Systems Management Server to administer patches to more than 2,000 machines.

      Last months Windows upgrades, however, caused him grief. “One of the patches broke one of our applications, so Microsoft is discussing with us whether or not the patch should have a shim or something.” Microsoft said the patch in question changes the way Windows handles text input and that other developers should change their code to avoid any problems.

      Windows is such a complex organism now that its hopeless to expect Microsofts patches to ever play nicely with all possible software. Thats why enterprises are heavily invested in patch management tools—Microsofts and others—to apply patches and patches to patches. Russ Cooper, editor of the NTBugtraq security mailing list, recently surveyed his 31,000 subscribers and found theyre collectively using 29 fee-based patch management solutions and 18 free ones. Whew!

      The new monthly patch schedule leaves companies with no excuse for not updating regularly. Michael Howard, Microsofts senior program manager for security engineering and communications, told me customers demanded it: “The overwhelming feedback we had from customers is that this would be much more predictable. It allows you to do it in one fell swoop.”

      Having committed to sending out a broad batch of updates the second Tuesday of every month, Microsoft also has no excuse if it doesnt improve its testing during the extra weeks it now has between releases. We all have a big stake in everyone getting this right.

      Brian Livingston is editor of BriansBuzz.com. His column appears every other week in eWEEK. Send your comments to eWEEK @ziffdavis.com.

      Brian Livingston
      Brian Livingston

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.