Re: IE vulnerabilities...

From: andy smart (anonymus_at_discussions.microsoft.com)
Date: 05/18/05


Date: Wed, 18 May 2005 08:07:26 +0100

Imhotep wrote:
> Mark Randall wrote:
>
>
>>I think the 40 day testing is simply this... unlike open source, if you
>>distribute a patch to a billion computers and then find out there is a
>>bug, you have 1 billion very unhappy customers.
>>
>
>
>
> ..and if you do not patch two critical security holes in a timely manner and
> a million customers get "infected" you get what?
>
> -Im
They are less likely to go to court.

My guess is that if you don't patch your security holes and people get
infected then you have the 'defence' of saying that you were working on
the patch and because the data loss was caused by the malware which
exploited your security weakness then it's not your fault - if you
release a patch which is somehow flawed and results in data loss then
you are liable for that data loss because it is your fault. Open source
need not care about this because the level of individual responsibilty
is low and there is no level of collective responsibility as there is no
"company".

The other point is that the only duty any company really has is to its
shareholders to make a profit; that's how capitalism works. As long as
the product sells and makes a profit the company is doing that for which
it exists.



Relevant Pages

  • Re: Mozilla and Firefox vulnerable to shell attacks
    ... It is not bugs and security holes that are the issue, it is the response time, ... This particular patch doesn't apply to non-MS users. ... > constant user diligence. ...
    (microsoft.public.security.virus)
  • Re: Two questions....
    ... Say you apply the patch, yet the patch breaks things, producing a headache ... > this accessment should be done. ... Is there a list of security holes which have been patched with each ... > closed by installed SP5 or SP6? ...
    (Security-Basics)
  • RE: Two questions....
    ... Say you apply the patch, yet the patch breaks things, producing a headache ... > this accessment should be done. ... Is there a list of security holes which have been patched with each ... > closed by installed SP5 or SP6? ...
    (Security-Basics)
  • Re: Apple release patch for massive security holes....
    ... Security holes are security holes. ... > patch security problems in a timely manner, ... >> something I was told by the Mac Jihad that simply DOES NOT HAPPEN EVER on ... >> Does these MASSIVE OSX SECURITY BREACHES affect your Mac using ...
    (comp.sys.mac.advocacy)
  • RE: Two questions....
    ... Use server not in production to test the patch. ... Follow basic rule before apply patch: ... Is there a list of security holes which have been patched with each ...
    (Security-Basics)

Loading