NETWORK WORLD NEWSLETTER: GIBBS & BRADNER
10/26/04

Dear [EMAIL PROTECTED],

In this issue:

* Backspin columnist Mark Gibbs discusses an interesting yet 
��disturbing column  he read about Microsoft patches
* Links related to Gibbs & Bradner
* Featured reader resource
_______________________________________________________________
This newsletter is sponsored by Veritas 
IDC White Paper, Distributed Applications Performance Management 

Performance management of distributed applications continues to 
grow in complexity, keeping pace with this constantly changing 
environment is a challenge for IT and performance management 
software vendors alike.  Learn how the Veritas i3 Approach can 
be the foundation for your organization's Application 
Performance Management strategy.  Download this IDC White Paper 
now http://www.fattail.com/redir/redirect.asp?CID=85614
_______________________________________________________________
Announcing a Powerful New Resource for Small Businesses from NW 
Fusion and PC World! 

Find Small Business resources, tools, and advice on Security, 
Broadband, Networking, Hardware, Software and Wireless & Mobile 
Technology at:  
http://www.fattail.com/redir/redirect.asp?CID=85489
_______________________________________________________________

Today's focus:  Interestingly disturbing

By Mark Gibbs

I just read an interesting column in The New York Times by David 
Pogue about Microsoft's patches (see story at 
<http://www.nwfusion.com/nlgibrad754> ). I say "interesting" 
when I might more accurately write "disturbing."

Pogue expressed surprise over learning from a Microsoft product 
manager that hackers mostly exploit security problems after the 
patch is issued. The reason they do so is obvious: The time 
between the release of a patch and its installation on all 
vulnerable computers is at best several weeks and usually 
several months. This inevitable delay gives the miscreants 
plenty of time to examine the released patch, develop their 
attack plan and then go out hunting.

As Pogue points out, it was only recently that significant 
numbers of users switched on the Windows automatic update 
facility, which should significantly reduce the length of time 
between patch release and the population getting updated. The 
thing that made a significant number of end users enable 
automatic update was Windows XP Service Pack 2.

But here's the rub: Given that SP2 is a 266M-byte download, it 
is a big task for dial-up users to download it, spyware can make 
the installation of the patch fail, and there are plenty of 
other gotchas that can make installing SP2 less than a 
certainty. It is safe to assume the universal application of SP2 
is a considerable way off.

Worse still, Microsoft recognizes that IT shops are unwilling to 
just turn loose such a major patch without testing. To this end, 
Microsoft has decreed that, as of April 12, 2005, even if SP2 
hasn't been deployed, "Windows XP SP2 will automatically be 
delivered to all systems configured to receive updates 
automatically" (find this at 
<http://www.nwfusion.com/nlgibrad755> ). I'm betting that a 
significant number of IT shops will do their utmost to avoid the 
SP2 update anyway.

So the bottom line: Between now and April there will be a huge 
number of unprotected corporate systems. There also will be a 
staggering number of consumer systems and tens of thousands of 
medical systems that won't be patched then or possibly ever (see 
<http://www.nwfusion.com/columnists/2004/083004backspin.html> 
and <http://www.nwfusion.com/columnists/2004/082304backspin.htm> 
).

Now this is a bad enough situation, but Pogue, addressing the 
readership of The New York Times,suggests: "should Microsoft 
really be fixing these obscure holes at all? Think about it: the 
virus writers would never even have known about the hole if 
Microsoft hadn't patched it!"

This is the philosophy of security through obscurity - in other 
words, if you find a vulnerability don't tell anyone but the 
vendor and let them decide whether to take action. This policy 
was being pushed by the Microsoft spinmeisters some months ago, 
and it was, at least in the IT community, roundly disparaged as 
not only self-serving but ultimately the riskiest path of all.

The reason that security through obscurity is a bad idea is 
obvious. If a vendor is under no pressure to produce a fix for a 
given problem then it can drag its feet for as long as it 
pleases. Just consider that Microsoft dragged its feet for six 
months before releasing the patch that the Sasser worm 
exploited.

But in the time that the problem is assumed to be a secret what 
happens if it is independently discovered by the guys wearing 
black hats? They will potentially have months to exploit the 
problem.

This was what I found disturbing about Pogue's column: He 
pitched a bad idea to The New York Times readership who, in 
general, probably accept the concept because it was printed in 
The New York Times.

There is more than enough profound ignorance about computers in 
general without columnists in prominent newspapers making bad 
ideas sound good, especially in a field that is as critical to 
business continuity as security. The last thing we need is a 
bigger pool of potentially compromised PCs.

Tell me if you're disturbed at backspin@ gibbs.com.
_______________________________________________________________
To contact: Mark Gibbs

Mark Gibbs is a consultant, author, journalist, and columnist 
and he writes the weekly Backspin and Gearhead columns in 
Network World. We'll spare you the rest of the bio but if you 
want to know more, go to <http://www.gibbs.com/mgbio>. Contact 
him at <mailto:[EMAIL PROTECTED]> 
_______________________________________________________________
This newsletter is sponsored by Veritas 
IDC White Paper, Distributed Applications Performance Management 

Performance management of distributed applications continues to 
grow in complexity, keeping pace with this constantly changing 
environment is a challenge for IT and performance management 
software vendors alike.  Learn how the Veritas i3 Approach can 
be the foundation for your organization's Application 
Performance Management strategy.  Download this IDC White Paper 
now http://www.fattail.com/redir/redirect.asp?CID=85613
_______________________________________________________________
ARCHIVE LINKS

Gibbs archive:
http://www.nwfusion.com/columnists/gibbs.html

Bradner archive:
http://www.nwfusion.com/columnists/bradner.html
_______________________________________________________________
FEATURED READER RESOURCE
NW FUSION'S LIVING BUYER'S GUIDES

Updated constantly, NW Fusion's Buyer's Guides give you the 
latest information on product capabilities, features, 
requirements, pricing and more. Check out NW Fusion's Buyer's 
Guides on security, instant messaging, enterprise routers, 
anti-spam, NAS Appliances and more at:
<http://www.nwfusion.com/reviews/bg.html>
_______________________________________________________________
May We Send You a Free Print Subscription? 
You've got the technology snapshot of your choice delivered 
at your fingertips each day. Now, extend your knowledge by 
receiving 51 FREE issues to our print publication. Apply 
today at <http://www.subscribenw.com/nl2> 

International subscribers click here: 
<http://nww1.com/go/circ_promo.html>
_______________________________________________________________
SUBSCRIPTION SERVICES

To subscribe or unsubscribe to any Network World e-mail 
newsletters, go to: 
<http://www.nwwsubscribe.com/Changes.aspx> 

To unsubscribe from promotional e-mail go to: 
<http://www.nwwsubscribe.com/Preferences.aspx> 

To change your e-mail address, go to: 
<http://www.nwwsubscribe.com/ChangeMail.aspx> 

Subscription questions? Contact Customer Service by replying to 
this message.

This message was sent to: [EMAIL PROTECTED] 
Please use this address when modifying your subscription. 
_______________________________________________________________

Have editorial comments? Write Jeff Caruso, Newsletter Editor, 
at: <mailto:[EMAIL PROTECTED]> 

Inquiries to: NL Customer Service, Network World, Inc., 118 
Turnpike Road, Southborough, MA 01772

For advertising information, write Kevin Normandeau, V.P. of 
Online Development, at: <mailto:[EMAIL PROTECTED]> 

Copyright Network World, Inc., 2004

------------------------
This message was sent to:  [EMAIL PROTECTED]

Reply via email to