Re: Releasing patches is bad for security

From: Clint Bodungen (clint_at_secureconsulting.com)
Date: 02/26/04

  • Next message: Curt Purdy: "RE: Releasing patches is bad for security"
    To: <incidents@securityfocus.com>
    Date: Thu, 26 Feb 2004 13:47:28 -0600
    
    

    Chris Brenton wrote Thursday, February 26, 2004 12:31 PM:

    > This is just such a hoot I had to share:
    > http://news.bbc.co.uk/1/hi/technology/3485972.stm
    >
    > The story quotes David Aucsmith, who is in charge of technology at
    > Microsoft's security business and technology unit as stating:
    >
    > "We have never had vulnerabilities exploited before the patch was
    > known,"
    >
    > The story then goes on to talk about how vulnerabilities are always
    > reverse engineered from patches. It really sounds to me like he's saying
    > that patches are *the* problem and if only Microsoft would stop
    > releasing patches, then all the security issues would just go away.
    >

    It seems the author just didn't express what he was trying to say very well.
    I think what he was trying to say was disclosure of the patch / patch
    details was the culprit... not the actual release of the patch. But yes,
    there is still some blatant ignorance in that article.

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Curt Purdy: "RE: Releasing patches is bad for security"

    Relevant Pages

    • [summary] patch install fails - checkinstall cannot open file
      ... > When installing a patch, ... Technology One's entire liability will be limited to resupplying the material enclosed. ... No other warranties are provided ... Although this e-mail has been checked for the presence of computer viruses, the Environmental Protection Agency provides no warranty that all possible viruses have been detected and cleaned. ...
      (SunManagers)
    • AMD PowerNow! Technology and Win2000
      ... I have a big problem with my new notebook. ... Technology. ... The problem is that the PowerNow! ... the servicepack for XP but I guess there is no patch ...
      (microsoft.public.win2000.hardware)
    • Re: [TCPIP V5.3 ECO4] For VMS V7.3-2 ?
      ... This does not make sense as the fail safe IP is 5.4 not 5.3. ... Would you not being applying a patch of older technology. ... Muggeridge" writes: ...
      (comp.os.vms)