Microsoft's Security Disclosures Come Under Fire
Old Banana writes "Is Microsoft silently fixing security vulnerabilities and deliberately obfuscating details about patches in its monthly security bulletins? Matthew Murphy, a security researcher who has worked closely with the MSRC (Microsoft Security Response Center) in the past, is accusing the software maker of 'misleading' customers by not clearly spelling out exactly what is being patched in the MS06-015 bulletin released on April 11."
As long as Microsoft are fixing them I'm not too bothered about this, but it would be nice to know what exactly they are fixing.
"Oh boy"
For Business users, they might actually want to know what might break if they do the update - especially since many cannot be "un-done".
This issue is a bit more complicated than you think.
This brings up the age old debate which I will not revive. However, my spin is that if you are patching a vulnerability you should disclose that. Otherwise the end user might not apply the patch. This very same situation happened with Cisco at Blackhat and ended up in the Courts and Cisco ended up with a public black-eye. Based upon the IT reaction to that I would venture the assumption that we want to know.
Quality Hosting e3 Servers
The guy making all the noise is just shooting his mouth off until he's actually tested the patch.
Yes, he has a valid gripe that the wording is unclear, but the crux of his complaint balances on the fact that MS allegedly patched something without coming out and saying so.
It's incredibly stupid to put yourself out on the line like that. One day it'll come back and bite him when he's wrong.
[Fuck Beta]
o0t!
If you explain exactly what is being patched, then you give the hackers a pretty clear roadmap of what they need to do to exploit all of the unpatched systems, don't you?
You do that already by providing a patch. The bad guys will simply look at the differences of the binaries and find out what has been patched. So instead of helping the good guys, Microsoft gives an information advantage to the bad guys.
OS Reviews: Free and Open Source Software
I would think that corporate "Software Assurance" customers who are paying for continual updates and support, and have to support MANY legacy applications that may be affected by such flaws or patches would be (and ARE) demanding such notifications. Joe Bob Home User does't really care, but Fortune 100 Fred in IT sure does, especially when his job (which is to keep the companies infrastructure up and running) is on the line.
I like what you've said and agree. , I work in the aviation industry and aircraft manufacturers release similar 'patches'. One operator of a certain aircraft (say B747) discovers a crack in a certain part of the wing, or a control cable that is jamming. They report this to Boeing, who then release a service buletin to all the users with all the details, inluding the approprite timeframe with which the inspection / modification must take place and steps required for the repair.
It may be to inspect a part, it may be to ground the fleet and inspect for a major crack or replace a rudder control cable before next flight. ALL the details are provided which allows operators to have enough knowledge to make an educated decision on how many resources to put into fulfilling the service buletin, and if they cant fulfill it in the timeframe, what the risks are.
Without the vendor providing all the information, the end user does not know the risks they are opening themselves up to, and thus the ability to assess if its worth committing (valuable) resources to immeadiatly. An airplane may well require full testing of systems after the repair, perhaps even a test flight to ensure full functionality from before the repair.
In an ideal world, MS would provide all the information required, and IT departments would have unlimited resources to test the patch the second its released before deploying on their 'fleet'. Its not an ideal world, and IT departments dont have those kind of resources. The least MS can do is provide GOOD information to allow IT management to make an assessment of the risk they are exposing themselves and their company to. If MS dont want to give out that infomation, the least the can do is re-grade their criticality of updates. If the can gain the trust of the IT world that a critical patch is critical, and not over use it, that would go someway to providing the IT world with the ability to manage the resources to deploy these updates.
While the analagy to aircraft is not everybodys way of thinking. Know that more and more safety critical systems are using MS products. Would you fly on an 'unpatched' 747? Would you ride on an 'unpatched' subway? Would you like it if the computer that monitors your credit and banking information at the local financial institution is unpatched? What if each case, the patch was not fully explained, deployed in a hurry and the system not fully tested, or not deployed at all? Crash, Crash, Crash. Game over.
How to find out? MD5 sum your /windows folder including the sub-directories (don't forget the hidden ones) before the patch. MD5 Sum again after the patch and compare the results. bdiff the questionable file differences and dis-assemble. At least thats what I used to do as a prior legitimate Windows license(s) owner (but before being called a thief by Microsoft).
Like I said earlier today, you either own a Microsoft appliance or a personal computer, these days you can't have both. Switch to something else or stay with Windows.
Enjoy,
It's just the normal noises in here.
The bad guys don't need to spend time with compatibility or regression testing for their software.
They can download the patch the day it is released and have an exploit ready that same day. You'll still be meeting to discuss the test plan for your servers.
Attempting to hide information doesn't help anyone except the vendor and the bad guys.
At least if you have the information, you can determine your own level of exposure and decide what mitigating actions you want to take based upon your environment.
That's all well and good, right up until the point that the syphilis cure also causes a fatal allergic reaction in a small but significant percentage of the population.
Patches can break things. This is why disclosure of what it's touching is important, so you can properly test that everything it touched still works after the patch.
I'll say it once, and say it again; it isn't Microsofts responsibility to provide backwards compatibility to people
I'd disagree, partially, with this. Yes, it isn't Microsoft's responsibility to provide backwards compatibility to people who have used undocumented behaviour - but where they have changed the API so that it no longer operates as documented, then it is their responsibility.
What would Lemmy do?