Slashdot Mirror


Microsoft Taking Longer to Fix Flaws

An anonymous reader writes "A look back at the last three years of security patches from Microsoft shows Redmond is taking at least 25 percent longer to issue patches for "critical" vulnerabilities, now averaging around 135 days to issue a fix. The exception appears to be with "full disclosure" flaws, for which Redmond issued fixes in an average of 46 days last year."

45 of 192 comments (clear)

  1. And this is bad why? by saleenS281 · · Score: 2, Interesting

    So they're concentrating efforts on the full disclosure exploits... and this is bad why?

    1. Re:And this is bad why? by kg4gyt · · Score: 5, Insightful

      Focusing on the exploits or not, 46 days is a long time to wait for a critical fix.

    2. Re:And this is bad why? by saleenS281 · · Score: 5, Insightful

      when you're accountable to that many customers with so many "supported" configurations, it takes a while to test. They don't have the luxury of most linux distro's where if it breaks some obscure program they can go "whupps, well, tell the author to write a fix for his app".

    3. Re:And this is bad why? by Lifewish · · Score: 2, Insightful
      when you're accountable to that many customers with so many "supported" configurations, it takes a while to test. They don't have the luxury of most linux distro's where if it breaks some obscure program they can go "whupps, well, tell the author to write a fix for his app". And yet Debian manages to consistently not break stuff despite supporting more architectures than Microsoft could dream of.

      Apart from that time a while back when they had to transition between GCC versions, that could have been better managed. I hold out hope that one day GCC will come out with some specification to ensure binary compatibility.
      --
      For the love of God, please learn to spell "ridiculous"!!!
    4. Re:And this is bad why? by saleenS281 · · Score: 2, Informative

      architecture != software packages. And definitely != enterprise software packages. Veritas, oracle anyone?

      I won't even begin to go into how many times a redhat update has "broken" both of these.

    5. Re:And this is bad why? by freshman_a · · Score: 4, Insightful

      when you're accountable to that many customers

      When who's accountable? The disclaimer included with the last MS security update I downloaded read as follows:

      In no event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Microsoft Corporation or its suppliers have been advised of the possibility of such damages.

      Now, unless I misunderstood, it's telling me that if I install said security patch, and it breaks something, I can't hold MS accountable.
    6. Re:And this is bad why? by Lifewish · · Score: 3, Insightful
      Strictly from a customer-is-always-right point of view, what's their excuse? Not enough testors? Not enough programmers? Not enough managers?
      I'd go with "not enough clearly-defined interfaces". If software producers are forced to use undocumented APIs to get their product working fast/well enough, it seems obvious that any behind-the-scenes changes are going to break a whole load of products.
      --
      For the love of God, please learn to spell "ridiculous"!!!
    7. Re:And this is bad why? by Itchy+Rich · · Score: 4, Insightful

      Now, unless I misunderstood, it's telling me that if I install said security patch, and it breaks something, I can't hold MS accountable.

      You may or may not be able to hold them accountable in court, but third party adjudication is not the only form of accountability.

      If Microsoft didn't bother to test their patches carefully they'd risk upsetting their corporate customers, and hence their bottom line.

    8. Re:And this is bad why? by Fruit · · Score: 2, Insightful
      Let's say MS releases a patch that ends up causing major problems for mission critical systems at a nonzero number of Fortune 500 companies. The next time those companies are looking at major systems overhauls, do you think they're going to seriously consider MS products?
      Actually, yes. Just like they always have.
    9. Re:And this is bad why? by swillden · · Score: 2, Insightful

      Let's say MS releases a patch that ends up causing major problems for mission critical systems at a nonzero number of Fortune 500 companies. The next time those companies are looking at major systems overhauls, do you think they're going to seriously consider MS products?

      Good point. Similarly, Let's say MS releases a product that ends up causing major problems for mission critical systems at nearly every Fortune 500 company, a product that requires them to spend exorbitant amounts of money and resources on keeping the systems free of malware, which occasionally gets through anyway, wreaking havoc on productivity. The next time those companies are looking at major systems overhauls, do you think they're going to seriously consider MS products?

      Oh, wait...

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
    10. Re:And this is bad why? by pembo13 · · Score: 3, Insightful

      You mean they will upset the companies IT department. I hardly think that would trouble management that much.

      --
      "Thanks for all the money you paid to us. We've used it to buy off ISO among other things" -Microsoft
  2. Realities of patching. by Godeke · · Score: 5, Informative

    I was expecting to find a scathing review of the patch process, but instead found a fairly reasonable assessment of the realities of issuing security patches: disclosed vulnerabilities get patched faster in an attempt to cover the users from the most probable exploit vectors whereas undisclosed vulnerabilities give the breathing room to do more testing and attempt to repair related flaws that are discovered in the process.

    That doesn't make me happy with the current situation, but it does make sense to react quickly (even if it puts the reaction at risk of being a problem itself) when something is actively being exploited. More quality assurance can be placed on patches that are not actively exploited (although each day increases the chance it will be exploited) and even more quality assurance can be placed on patched for flaws that are unlikely vectors.

    Being responsible for very high reliability networks (our customer facing web and their support servers), high reliability networks (the corporate network, where I can apologize to someone's face if it blows up) and low reliability networks (my own internal network where I can fire anyone who complains) I have different thresholds for pain in the patching process depending on the network involved.

    I'm far more willing to just slap a patch on my internal network: after all, it is my testing ground and it affects me far more than anyone else if it dies. After I have assured myself it isn't total bunk, I will patch our corporate network. Finally, our high reliability network is patched only after the corporate network's servers and clients have given us confidence in the patch. Of course, that means our high reliability network has to be far more insulated (URL scanning proxies in another operating system, tightly controlled trust relationships, intrusion detection, etc) but it is worth the extra effort and cost to avoid a "bum" patch bringing down the show.

    Microsoft may not be reacting perfectly, but I think they are trying to balance corporate stability with the realities of exploitation. It sounds like they do need to throw some more resources to the departments involved to shorten the critical path, but with a system this complex, test cycles are going to be long and involved.

    --
    Sig under construction since 1998.
  3. in other news... by tont0r · · Score: 3, Funny

    a bear shits in the woods.

    1. Re:in other news... by Foofoobar · · Score: 3, Funny

      Steve Ballmer throws a chair

      --
      This is my sig. There are many like it but this one is mine.
    2. Re:in other news... by trandism · · Score: 3, Funny

      bug fixers. Bug Fixers!. Bug Fixers!!!. BUG FIXERS!!!!!!

      --
      www.lemonodor.com A mostly Lisp weblog
  4. Meh by Anonymous Coward · · Score: 4, Insightful

    Seems as though the reason stems from the fact that Microsoft actually has to make sure their patches are compatible with the rest of the things they support. As they support more and more hard and software, the total can only go up.

    1. Re:Meh by varmittang · · Score: 2, Insightful

      So Linux doesn't? I mean, it runs on more hardware, PPC, SPARC, blah blah put your chip in here. Linux also has multiple languages and lots of programs that need to share the same libraries. Sure you are more likely to have something break in Linux after a patch, but usually a few hours or a day later you have a patch for the program that got broken so it works properly again, although I haven't had a program break due to a security patch yet on Linux but I have on MS. And Linux vendors have their patches out quicker than MS. So, again, why does MS take so long?

      --
      -----BEGIN PGP SIGNATURE-----
      12345
      -----END PGP SIGNATURE-----
    2. Re:Meh by The+Angry+Mick · · Score: 3, Insightful
      So, again, why does MS take so long?

      The legal department?

      --

      I'm not tense. I'm just terribly, terribly, alert.

  5. Do expoits speed up the fixing? by chriss · · Score: 4, Insightful

    The most interesting result of Security Fix's study is that Microsoft took longer to fix a problem if the researcher waited to disclose the problem until after Microsoft published the patch.

    I'd like to know if the time to issue a fix also depends on existing exploits, i.e. is Microsoft faster if there is already an exploit out there. If yes, than it seems obvious that Microsoft does not really put as much afford into fixing bugs as they claim, they're "motivated" by public pressure.

    One explanation for additional delay in case of a not yet disclosed or not yet exploited problem may be more thorough testing, so it may not even be a bad thing. But I'm afraid that the delay is not really "in the best of the customers", more in the best of Microsoft. I have no prove, but it seems to be the general company policy.

    Chriss

    --
    memomo.net - brush up your German, French, Spanish or Italian - online and free

    1. Re:Do expoits speed up the fixing? by Z0mb1eman · · Score: 2, Interesting

      Or a simpler explanation might be that, given a certain budget for fixing bugs/security flaws, they have to prioritize, and since bugs that have an exploit out in the wild are much more likely to have a negative impact, they get pushed to the front of the queue... which makes sense to me.

      I don't think they set out to solve X bugs in Y months. I would assume they have a certain number of manhours devoted to fixing bugs, and fix however many they get around to. They can always increase the resources devoted to this, yes, but I doubt anyone over there says "oh, this one doesn't have an exploit in the wild, try to take as long as you can to fix it".

      --
      ClutterMe.com - easiest site creation on the Net. Just click and type.
    2. Re:Do expoits speed up the fixing? by innocent_white_lamb · · Score: 2, Insightful

      One explanation for additional delay in case of a not yet disclosed or not yet exploited problem may be more thorough testing, so it may not even be a bad thing.
       
      The problem with this is simply that you can never know that a given exploit is NOT being taken advantage of somewhere. "It's safe for now; nobody knows about it." Meanwhile someone is quietly carrying the goods out of the back door somewhere.
       
      Just because a flaw isn't being broadcast from the rooftops doesn't mean that it's not being quitely exploited.
       
      That's my concern with the concept of "responsible disclosure." If I have a vulnerable system I want to know about it even if there is no current fix available. I can always make physical or software changes to avoid problems if I know about them, right up to pulling the plug if I have to. If I know about the problem. Otherwise I can be merrily carrying out my normal routine while someone is getting ready to pull the rug out from under me.
       
      Tell me if there is a problem and I can deal with it or not as I choose. If I don't know about the problem, I don't have that choice.

      --
      If you're a zombie and you know it, bite your friend!
  6. Why is this a bad thing? by esac17 · · Score: 5, Insightful

    In the Linux world, the deployment of a bug fix and discovery of any potential bugs is part of the testing cycle. So you get a quick turn around time when a bug is reported.

    When Microsoft has to issue a bug fix (and all jokes aside about not testing), I am sure they have a team devoted to testing it, then it has to get sent to all internal Microsoft employees and tested, and then probably even has some initial customer testing with the bigger companies to make sure nothing breaks, and then finally gets released to the public.

    Hopefully 165 or 365 days .. whatever it takes to make sure it is tested is a GOOD thing. I don't want to be their beta tester :)

    1. Re:Why is this a bad thing? by randyflood · · Score: 4, Insightful


      You ask why it is a bad thing if the time between the discovery of a security vunerability and the time to relase a patch is increasing. You ackowlegde that in the Linux world, patches are fixed much faster due to their development model. So why is it a big deal if hackers can own your systems for longer without a patch being availiable? Isn't it obvious? HACKERS CAN OWN YOUR SYSTEM FOR LONGER BECAUSE A PATCH IS NOT AVAILIABLE. That is what the big deal is. They can use whatever development model they want. Releasing shoddy patches is only one solution that is available to them. The fact that they are able to cut the time it takes to release a patch in half if a working exploit has been publically released shows that it is more a matter of what resources they want to bring to bear on the problem rather than the minimum time to release a good patch. Or another way of stating this is, they are 25% less concerned with getting patches out in a timely manner than they used to be. So, the importance of security at Microsoft is decreasing.

      --
      Randy.Flood@RHCE2B.COM
    2. Re:Why is this a bad thing? by po8 · · Score: 2, Insightful

      It's a bad thing because Linux's process—which involves having thousands of alpha and beta testers of the patch with direct access to the source code and the knowledge to make that access useful deploy it on their boxes—turns out to produce better patches faster. You, as a user who "doesn't want to be their beta tester", don't have to be. In 5-10 days (not 46 or 135) your distro vendor will have enough evidence that the patch is harmless and effective that they will make it available to you, and you will have enough evidence that you can make a rational decision about whether you want it.

  7. Still too long, but you can take precautions. by gasmonso · · Score: 4, Interesting

    If you look at the data, you will notice that some critical flaws were patched in less than 3-4 weeks. While that may seem long, it is somewhat reasonable due to the amount of verification/validation necessary. People forget that 95% of the world runs on M$ so they have to really test a patch before releasing it.

    On the other hand... because so much of the world depends on M$, they have an obligation to its customers to provide a secure OS and timely patches. Personally, I feel they are doing an "ok" job and seem to be getting better. Alot of vulnerabilities can be avoided just by running your PC behind a router and/or by using a firewall application. Personally, I have NEVER had a virus at home on any of my computers because I take simple preventative measures like running Norton AV and AdAware. I also put all my pcs behind a router.

    http://religiousfreaks.com/
    1. Re:Still too long, but you can take precautions. by thePowerOfGrayskull · · Score: 2, Interesting

      Slightly OT, but a legitimate question..
      The background: I've never had a virus at home (well, not since DOS days). I don't run antivirus; I used to run antispyware, but it kept turning up nothing so I stopped. I run 3 windows xp PCs and several linux PCs. I don't use MS products for web browsing or e-mail (ever. period.) I do run windows firewall on my laptops (my wife uses hers at school, and I use mine at work and school, so it's safest), and I have a hardware firewall/router. I have open ports for a web server and a game server (both directed to linux machines).

      I /have/ heard that the hardware router/firewall combinations can be compromised, but has anyone ever had that actually happen? I've been running mine for 4 years with zero successful intrusions (and hundreds of attempts logged daily).

    2. Re:Still too long, but you can take precautions. by TheUser0x58 · · Score: 2, Informative
      People forget that 95% of the world runs on M$ so they have to really test a patch before releasing it.

      No, 95% of the desktop world runs on Microsoft. Microsoft certainly doesn't have that kind of marketshare in server systems.

      --
      -- listen to interesting music, support independent radio... WPRB
  8. Does Full Disclosure Increase Eventual Harm? by ThinkFr33ly · · Score: 3, Insightful

    While it is certainly interesting (if true) that Microsoft takes longer to release patches with no known exploits roaming around, I would find it far more interesting to see which causes more harm: the longer patch times or the full disclosure.

    Just because Microsoft releases a patch quicker when full disclosure is used doesn't mean this results in less harm to users. It might take Microsoft 200 days to release a patch, but if the only people who know about the bug are the researchers who discovered it and Microsoft, then the end result is that little harm was done to the users.

    If, however, an easily understandable exploit is posted before Microsoft has fixed the bug, those 45 days might be a lot more dangerous for those users than the 200 days in the previous example.

    Of course, it's very difficult to know if the security researchers who discovered the bug are the only ones with knowledge of that bug. Could other people know about it and be actively using it to compromise machines? Maybe. But I would really like to see some data on this.

    I suspect that the vast majority of major worms and viruses take advantage of well known exploits published on the Internet by usually well meaning security researchers. Certainly all of the major worms I can think of off the top of my head follow this pattern. (MYTOB, LOVGATE, NETSKY, SASSER, ZAFI, SOBER, BAGEL, etc.)

    If so, people really are safer when the exploit is not published before Microsoft releases a patch despite the significant lag time for those fixes.

    So I guess which approach you take depends on your goal. If your goal is the glory of a 0-day exploit, then post away. But if your goal is the security of the end user, maybe you should keep it to yourself for the time being.

    1. Re:Does Full Disclosure Increase Eventual Harm? by 99BottlesOfBeerInMyF · · Score: 2, Interesting

      So I guess which approach you take depends on your goal. If your goal is the glory of a 0-day exploit, then post away. But if your goal is the security of the end user, maybe you should keep it to yourself for the time being.

      You've made a number of incorrect assumptions and failed to consider several important concerns. First, is the vulnerability likely being exploited? Is the vulnerability able to be mitigated by users and if so, are there drawbacks to the fix? What systems would be made vulnerable?

      For example, suppose I find a trivial exploit in code I know blackhats have already reviewed. That means there is a good possibility that it is being quietly exploited. Or what if I am running a network that needs network access, but is top-secret and would be disastrous if compromised. I find a flaw that has a work-around that requires disabling a service. This will cost hundreds of thousands of dollars a day, but I can't risk exposure. Should I:

      • quietly disclose it to MS and wait for them to fix it, costing millions of dollars
      • disclose it publicly thus allowing other admins to disable it and spurring MS to fix it faster and thus saving myself millions of dollars

      Here's my general take on things. Windows machines will be compromised in huge numbers until MS gets their act together. Compromises to the average machine are not too important to me. Why do I care if 100,000 idiots turn into spam bots? Compromises to my system do concern me. The best way for me to keep my machine secure (and for other security conscious people who run important systems) is for me to be well informed about vulnerabilities. If there is a vulnerability in a particular service I want to know, so that I can disable it if need be, plan work arounds, migrate to a different service, and set up honey pots and IDSs to look for attacks or strange behavior.

      To put it bluntly, in some cases it is best for me to publicly disclose vulnerabilities and in others it is not. To imply, however, that it has something to do with trying to garner fame or a reputation is very mistaken. In some cases the security of end users if better served by full disclosure, while in other cases it is not. It all depends upon the vulnerability.

    2. Re:Does Full Disclosure Increase Eventual Harm? by PlusFiveTroll · · Score: 2, Interesting

      Of course, what we can't see here is the long tail effect. How many Windows boxes are being exploited by holes unknown to the public, but that Microsoft is aware of. There is not any way to tell easily.

      Heres a new benchmark that Microsoft would not like.

      T.C.C.M.

      Total Cost of Code Maintnence, how much does it cost to patch and test the base operating system source code per year? Microsoft vs Other commerical operating systems? Vs opensource operating systems.

      The T.C.O Microsoft does not talk about is on there end, That is the price of closed source code.

  9. Intrusion Prevention Systems (IPS) by Anonymous Coward · · Score: 4, Informative

    This is a great case for Intrusion Prevention Systems. I have seen many vendors providing "Virtual Software Patches" during the window from when a vulnerability is released to the time that it's actually patched. It's not the ideal solution, but it's definitely one of the best ways to take care of the problem today without waiting for m$ to get their stuff together.

    I'd say that in this week I've seen stuff from 3Com/TippingPoint, Secure Computing, Sonicwall, etc. all about securing WMF fairly quickly after the exploit had been announced.

  10. How much would it cost? by khasim · · Score: 4, Insightful
    when you're accountable to that many customers with so many "supported" configurations, it takes a while to test.
    What is this "a while"?

    Is it a day?
    Is it a week?
    Is it a month?

    Doesn't Microsoft have enough money to maintain images of different configurations just for such testing?

    Doesn't Microsoft have the people who could automate such testing?

    Is the problem that they don't have enough money? Or that they don't have people who are smart enough? Or that they just aren't doing it?
    1. Re:How much would it cost? by Anonymous Coward · · Score: 2, Insightful

      I think it's more along the line of how long does it take to build the binaries for the new components and run it through a battery of automated test scripts.

      The software that we write at my current employer is a complex vector editing system and image RIPing. Our regression test suite can take up to 3 days to run. Whoops, that last fix broke something in abc.dll that depended on some behavior coming from def.dll. That will take a day to fix, 4 hours to build and rerun the test suite. Rince repeat until no more errors. An average fix may take us up to 10 days to code, test and deploy for patching.

      The thought of regression testing on an entire OS gives me the sweats.

    2. Re:How much would it cost? by Austerity+Empowers · · Score: 2, Interesting

      It's more likely how long it takes to run that battery of test scripts on several hundred "typical" hardware configurations. It takes a while, we should not berate MS for testing, if indeed that is what is happening.

      In all likihood they are diverting resources from patching to Vista so they can ship it sooner. This is bad.

  11. No the flaw is in the user by SmallFurryCreature · · Score: 2, Funny
    No the flaw is in the user. Old saying, "Fool me once shame on your, fool me twice shame on me".

    Or to paraphrase, "sell me a bug ridden OS once shame on you, sell me a bug ridden OS twice shame on me".

    Cue everyone giving lousy examples of why they cannot live without windows.

    Proposal for a new moderation system, you can only mod people in OS discussions who are on the same OS as you.

    --

    MMO Quests are like orgasms:

    You may solo them, I prefer them in a group.

  12. Re:Not the WMF vulnerability by varmittang · · Score: 2, Informative

    Um, no. They said to download and notify before installing. MS just went right ahead and installed and rebooted the computer for them. http://www.emailbattles.com/archive/battles/vuln_a acfhddccc_de/

    --
    -----BEGIN PGP SIGNATURE-----
    12345
    -----END PGP SIGNATURE-----
  13. Doesn't seem too awful by XMilkProject · · Score: 3, Insightful

    The timeframe doesn't seem entirely unreasonable. When you think that they are releasing a patch which will be automatically downloaded and installed on literally tens of millions of computers, most of which without any system administrator to aid in the process.

    That is a daunting task, and I can imagine theres a very lengthy process a patch must go through.

    To Microsofts credit, I can hardly remember a time that a patch was released which cuased any major problems, which in itself is a great achievement given the amazing variety of hardware and software the users may have. There was of course alot of hype over compatibility issues in SP2, but to the best of my knowledge any actual issues were understood ahead of time and due to compromises that were made intentionally for one reason or another.

    --
    Big ones, small ones, some as big as yer 'ead!
    Give 'em a twist, a flick o' the wrist...
  14. Why MS takes so long to release patches by DoktorFuture · · Score: 5, Interesting
    I'm sure that the QA aspect of testing the patches takes the most time, because that is where Microsoft has the most to loose.

    Imagine if their patch accidentally disabled * * * TENS OF MILLIONS * * * of computers. If that happened, they'd loose so much consumer confidence -- essentially loosing whatever gains (if any) they have made in the last several years (and billions in spending).

    (okay, that did happen on a lot of sp2 systems, and MS is not loved for it)

    MS has to ensure that the patch works on a staggering and dizzying array of systems and architectures (lots of different mobos, pentiums, AMD's, dual core CPU's, XENON's, via chips), and for dozens upon dozens of applications. That's why you often find that they'll often release a patch on NT or more server based systems before they release it for consumer systems.

    Another reason is that, depending on the type of problem, will do a full tracability check, and also cross reference all their code that references the changed module, and evaluate (probably manually) if they put that dependency at risk. A huge, horrible job, suitable only for type-A micro-detail oriented folks. I wouldn't want to do it!

    If MS disabled TENS OF MILLIONS of computers, you would see a huge shift away from regular Patch Tuesday activities, towards one of 'install on a test bed' -- extremely tedious and manual that everyone would hate. Millions of people would be put out. Seriously bad Karma.

    So, they can:

    • Release a damaging patch -> like an A-Bomb wiping away consumer confidence
    • Release a patch late -> some systems might be infected, but often, threats can be mitigated on key systems (firewall rules, policies, use different software), or third party patches appear to fix the problem.
    • Ignore a problem -> Perhaps try to luer people to exploit it instead of finding new holes? :) Perhaps encouraging the industry to develop technologies like 'IPS' and 'worm crushers'?

    I'm sure at least someone is thinking "Heck: our flaws are the manure in which an entire security industry will grow in".

  15. On Full Disclosure by SHP · · Score: 2, Insightful

    A common argument of those who oppose full disclosure is that it does harm by allowing the development of worms, and provides infection vectors for Spyware. I personally think the widespread worms are a good thing. The act like wildfire clearing the underbrush of vulnerable machines.

    What really concerns me is not some 14 year kid in Bulgaria playing "my botnet is bigger than yours" games. I'm concerned about hostile governments, terrorist groups, and organized criminals who already have a stable of zero day holes to attack my company's systems. These are the threats that keep corporate and government security teams awake at night. All the piddly little public nuisances are just ploys to get funding.

    Yesterday, eEye released information about a Windows hole that they reported over 5 months ago. The WMF hole was known to Microsoft long ago, and has existed for YEARS! Does anyone really believe that the REAL bad guys don't have the knowledge to get inside any (at at least very nearly any) company in the world. The US military is getting hacked for God's sake.

    I say full disclosure now. It won't make us less secure, it will only appear to.

    -SHP

  16. Patch testing by Savage-Rabbit · · Score: 2

    Focusing on the exploits or not, 46 days is a long time to wait for a critical fix.

    Fixes like this have to be tested and re-tested which is not exactly something you do .... Yawn.... While you wait for the expresso machine to finish filling up that paper cup. I used to work for a *NIX vendor where the usual procedure was to offer a workaround to plug up the security hole. The patch was then developed and sent off for testing from where it would sometimes return for a rework because it caused unexpected problems in some other part of the OS. If Microsoft, Sun, IBM, Apple or any of the numerous enterprise quality Linux distros out there would sling these fixes out as soon as the developers finish them you would now be griping about how unstable these systems are because of badly tested patches. I will admit my former employer usually got better turnover times per pach than 6 weeks but for 3-4 weeks to pass from the time problem being reported and until the patch had been fully tested accross all major OS versions still in widespread use and approved for release was not unusual and we only had one Server OS to worry about. I can even remember a couple of errors that took over a year to track down because they were hard to reproduce and the culprit was difficult to isolate. Of course this was a few years ago and OS'es, at least in my experience, do not tend to get simpler as time passes.

    --
    Only to idiots, are orders laws.
    -- Henning von Tresckow
  17. This is perfectly reasonable. by Dorsai65 · · Score: 2, Funny

    I mean, when you consider how long it takes them to put the flaws in their products in the first place, it's only reasonable that it would take them longer to get the flaws back out again, right?

    --
    --- Asking inconvenient questions for over 30 years...
  18. MS is a very lucky company. by WhiteWolf666 · · Score: 2, Insightful

    Why? Because the black hat community is very, very nice to MS.

    I've never met a truly destructive worm or trojan. I don't mean one that disabled systems as a side effect of its operation. I mean one specifically designed to destroy data, and/or BIOS/CMOS/anything flashable.

    A 4 month patch cycle. I imagine that if North Korea, or whoever felt angry about the global economy, decided to try and do something devestating that they could easily prepare some kind of trojan payload that would install itself, replicate for a week or so, and then destroy the system in question. Blow away the BIOS (won't be determined until a reboot), blow away the partition table, and then start writing loads of garbage all over the disk.

    Such a worm would break MS. MS execs would be brought before a congressional hearing.

    That is, after banks, airlines, and major companies managed to rebuild some kind of IT infrastructure.

    MS is very luck that no black hats have decided to do such a thing. I guess its most likely because no one wants to bring THAT kind of heat down upon themselves.

    --
    WhiteWolf666 an exBush supporter. All you new-school,compassionate,save the children Republicans can rot in hell
  19. Re:Not the WMF vulnerability by jav1231 · · Score: 2, Insightful

    "I guess it all depends on how serious the flaw is."
    Or how much press they're getting for not having one.

  20. Kind of Applogetic... by EXTomar · · Score: 3, Insightful

    This would be akin to having the anology of cars without modern safety features. "Personally, I have NEVER had a serious injury while driving any car because I take simple preventative measures like buying seat belts, safety glass, and air bags." The question one should be asking is why does the user have to buy "seat belts, safety glass, and air bags" for their computer in the first place?? Shouldn't these things be standard features? Turning around responsiblity to the user is allowing MS off the hook. Users are using Windows as designed and getting sometimes serious malfunctions. It would be one thing if people were abusing their machines and breaking them. It is something else to be normally surfing the internet, reading email, or doing any other nominal activity and hitting a serious problem that leaves their system bare to the hackers. This is squarely Microsoft's problem not the users!!

    I'm tired of this kind of applogetic excusing for Microsoft. As much as people want to blame the users, its still all in MS's lap since many of the problems stem from software doing things that it should never be allowed to do in the first place. AV software, hardware and software firewalls, malware scanners...its all a hack to stop users from breaking their machines doing normal operations because MS won't or can't engineer a system that disallows it.

    Years of experience on other systems have shown that computers are complex machines with complex interactions all of which are prone to error and worst exploit if not carefully designed. On the other hand Microsoft sold most of the world on the promise that Windows is as easy to use as a VCR and requires just as much maintaince and look at where we are. We have to throw more and more money and time into work arounds while MS takes longer and longer to fix up things. Why aren't more people asking why does Windows work this way?

  21. The Microsoft Effect by SgtChaireBourne · · Score: 4, Insightful
    There's a lot of misdirection going on here. The day an exploit is made public is not the same as when the bug it uses is reported. Nor is that the same as when the bug is found, not is that the same as when MS acknowledges the bug.

    We're dealing with a number of different dates, some of which are often months or years apart:

    1. Date bug found by black hat
    2. Date bug found by white hat
    3. Date bug is reported
    4. Date bug is made public
    5. Date exploit is published
    6. Date exploit is found 'in the wild'
    7. Date MS acknowledges the bug
    8. Date MS announces a patch
    9. Date MS releases a patch
    10. Date MS releases a patch that fixes the bug / repairs damage from first patch

    Somehow, being a political movement / cult, MS becomes exempt from the rules of a normal business and from what customers expect. No other device or appliance has had even a fraction of the defects as MS' without going through a major product recall. Our dear Chairman Bill will go down in history as the man that made bad engineering acceptible aka the Microsoft Effect

    --
    Beta is broken and the link to classic doesn't work. Stop wasting our time or there won't be anybody left here.