RE: [Full-Disclosure] SP2 is killing me. Help?

From: Phillip R. Paradis (prp17_at_adelphia.net)
Date: 08/13/04

  • Next message: Will Image: "Re: [Full-Disclosure] lame bitching about xpsp2"
    To: "'xtrecate'" <xtrecate@spymac.com>
    Date: Thu, 12 Aug 2004 23:19:47 -0400
    
    

    > -----Original Message-----
    > From: full-disclosure-admin@lists.netsys.com
    > [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of xtrecate

    > Ultimately what difference to an end user does it make if the
    > applications
    > are broken by a service pack install or a virus?

    None at all. But the user has control over installing service packs. And the
    user should have read the warnings BEFORE installing it, not after they discover
    something is broken.

    > I think the update
    > provides some long needed changes to the fundamental
    > operation of Windows,
    > however if Microsoft knew of the potential problems via RC2
    > testing, I'd
    > have thought they'd do a little more to rectify those
    > problems than simply
    > releasing and disclaiming.

    Most of those problems are a result of a very simple problem. For certain
    security issues, it is possible to remain compatible with old, generally poorly
    written code, or to fix the security problem, but not both. There are some
    security issues that simply could not be fixed without creating compatibility
    issues. The data execution issue is one clear example; making blocks of memory
    allocated for data non-executable is a very effective way of preventing buffer
    overrun exploits from executing arbitrary code. The downside is that software
    (such as DivX) that intentionally tries to execute data won't work anymore.
    Given the choice between a secure system and a few badly written programs, I'd
    rather take the secure system and let the developers of those few programs that
    don't work due to lazy coding fix their products. Microsoft has in the past
    always taken the route of less security and more compatibility, and I, for one,
    think it's a good thing that their attitude has changed somewhat.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Will Image: "Re: [Full-Disclosure] lame bitching about xpsp2"

    Relevant Pages

    • Re: [Full-Disclosure] SP2 is killing me. Help?
      ... But the user has control over installing service packs. ... > written code, or to fix the security problem, but not both. ... The data execution issue is one clear example; ... > always taken the route of less security and more compatibility, and I, ...
      (Full-Disclosure)
    • Re: Some updates could not be installed ---to: PA Bear [MS MVP]
      ... There is no charge for support related to installing a Security Update. ... "When you call please let them know that this has to do with Security Bulletin MS09-062. ... "If they try to charge you, please let them know that there is free support for any issues with Security Updates." ... This service pack upgrades all Microsoft SQL Server 2005 Express Edition ...
      (microsoft.public.windowsupdate)
    • Re: sp2 service pack with i-e
      ... >> Hi there i downloaded the new service pack 2 great ... >> antivirus and norton personal firewall as well as xp ... > Also check out Norton's pages for advice with installing XP ... > Norton Internet Security. ...
      (microsoft.public.windowsxp.network_web)
    • Re: xp is fine - why should I install service pack 2?
      ... >> until the first patches for the Service Pack are issued. ... You are not forced or coerced into downloading and installing ... The fact that most, if not all, of the security applications provided in SP ... Computer Shopper Magazine have published numerous articles to that effect. ...
      (microsoft.public.windowsxp.basics)
    • Re: Unable to install updates
      ... Did you just reinstall Windows? ... => I would NOT recommend installing IE7 via Windows Update! ... MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002 ... Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 ...
      (microsoft.public.windowsupdate)