Microsoft Patches 19 Flaws, 6 in Vista
Cheesy Balogna writes "Microsoft has just released seven advisories — all rated critical — with patches for at least 19 vulnerabilities affecting the Windows operating system, the widely deployed Office productivity suite and the dominant Internet Explorer browser. Six of the 19 vulnerabilities affect Windows Vista. 'There are patches for 7 different vulnerabilities that could lead to code execution attacks against Word, Excel and Office. Users of Microsoft Exchange are also urged to pay attention to one of the critical bulletins, which cover 4 different flaws. A cumulative IE update addresses six potentially dangerous bugs. There are the six that apply to IE 7 on Windows Vista. The last bulletin in this month's batch apples to CAPICOM (Cryptographic API Component Object Model) and could also put users at risk of complete system hijack attacks.'"
When are we going to start seeing regular Slashdot postings outlining Linux or other free software security patch releases in the same accusatory tone that the monthly Microsoft security bulletin releases bring? No, I'm not trolling, but I'm getting sick of the clear bias Slashdot editors (and most readers) have when it comes to matters of Microsoft.
(I can feel my karma slipping away, but I couldn't take it anymore).
MS throws out a bunch of patches every month, and have been at it for years. It must be a regular event by now, right?
Ok, here's what's bugging me: 6 out of 19 holes are still present in Vista. That means that, in developing Vista, they removed at least 13 holes. My question: was that an accident? If those 13 holes were identified as critical vulnerabilities during Vista development and fixed, then they should have been patched in XP too. If they were accidentally fixed by more broad changes in Vista, then I guess you can see that as good, but it still calls into question MS's ability to audit code.
On the other hand, if the rewritten portions of Vista removed 70% of the critical holes, that's pretty good. They might have been working on the right modules.
Is there any reason someone with Chilisoft ASP couldn't implement the same functionality?
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
I'm calling bullshit. Microsoft has been saying for 10 years that IE is INSEPARABLE from Windows. Any flaw in IE is a flaw in Windows. Because either you believe Microsoft or you stop your cheerleading and admit that Bill Gates and all the other execs at Microsoft are liars and that the feds should have broken the company up into a hundred little Microsofts.
The Farewell Tour II
During the OS install, you are specifically asked to configure automatic updates. Some of the service pack installs also ask you to do this. [...] If the user decides to just click away the dialog asking you to configure automatic updates (which many OEMs will leave for you) then that's their damage.
Hmmm.. like most people, windows was preinstalled on my machine. If enabling a feature can lose the vital work of the user, it should not be a default. Also, a clear warning of the consequences should be made. In actual fact, I intentionally enabled the automatic update and I still didn't know what I was letting myself in for. My bad, I guess, but I never thought for one moment that enabling it like this might just cause my machine to lose my work while I was sitting in front of it, never mind if I popped out for a coffee! It fails the principle of least surprise.
I think that for most people, computers are tools, not objects of intrinsic interest in themselves. Any boring software (ie - stuff that should just work and not get in the user's way unless absolutely necessary) should do just that: just work. If can't just work, at the very least it should not endanger the user's work if at all possible.
Funnily enough, the argument that linux is harder to configure than windows is often made, but in my recent experience, I have to tinker less with linux than I ever did with windows, and I feel much safer!