NETWORK WORLD NEWSLETTER: GIBBS & BRADNER 10/26/04 Dear [EMAIL PROTECTED],
In this issue: * Backspin columnist Mark Gibbs discusses an interesting yet ��disturbing column he read about Microsoft patches * Links related to Gibbs & Bradner * Featured reader resource _______________________________________________________________ This newsletter is sponsored by Veritas IDC White Paper, Distributed Applications Performance Management Performance management of distributed applications continues to grow in complexity, keeping pace with this constantly changing environment is a challenge for IT and performance management software vendors alike. Learn how the Veritas i3 Approach can be the foundation for your organization's Application Performance Management strategy. Download this IDC White Paper now http://www.fattail.com/redir/redirect.asp?CID=85614 _______________________________________________________________ Announcing a Powerful New Resource for Small Businesses from NW Fusion and PC World! Find Small Business resources, tools, and advice on Security, Broadband, Networking, Hardware, Software and Wireless & Mobile Technology at: http://www.fattail.com/redir/redirect.asp?CID=85489 _______________________________________________________________ Today's focus: Interestingly disturbing By Mark Gibbs I just read an interesting column in The New York Times by David Pogue about Microsoft's patches (see story at <http://www.nwfusion.com/nlgibrad754> ). I say "interesting" when I might more accurately write "disturbing." Pogue expressed surprise over learning from a Microsoft product manager that hackers mostly exploit security problems after the patch is issued. The reason they do so is obvious: The time between the release of a patch and its installation on all vulnerable computers is at best several weeks and usually several months. This inevitable delay gives the miscreants plenty of time to examine the released patch, develop their attack plan and then go out hunting. As Pogue points out, it was only recently that significant numbers of users switched on the Windows automatic update facility, which should significantly reduce the length of time between patch release and the population getting updated. The thing that made a significant number of end users enable automatic update was Windows XP Service Pack 2. But here's the rub: Given that SP2 is a 266M-byte download, it is a big task for dial-up users to download it, spyware can make the installation of the patch fail, and there are plenty of other gotchas that can make installing SP2 less than a certainty. It is safe to assume the universal application of SP2 is a considerable way off. Worse still, Microsoft recognizes that IT shops are unwilling to just turn loose such a major patch without testing. To this end, Microsoft has decreed that, as of April 12, 2005, even if SP2 hasn't been deployed, "Windows XP SP2 will automatically be delivered to all systems configured to receive updates automatically" (find this at <http://www.nwfusion.com/nlgibrad755> ). I'm betting that a significant number of IT shops will do their utmost to avoid the SP2 update anyway. So the bottom line: Between now and April there will be a huge number of unprotected corporate systems. There also will be a staggering number of consumer systems and tens of thousands of medical systems that won't be patched then or possibly ever (see <http://www.nwfusion.com/columnists/2004/083004backspin.html> and <http://www.nwfusion.com/columnists/2004/082304backspin.htm> ). Now this is a bad enough situation, but Pogue, addressing the readership of The New York Times,suggests: "should Microsoft really be fixing these obscure holes at all? Think about it: the virus writers would never even have known about the hole if Microsoft hadn't patched it!" This is the philosophy of security through obscurity - in other words, if you find a vulnerability don't tell anyone but the vendor and let them decide whether to take action. This policy was being pushed by the Microsoft spinmeisters some months ago, and it was, at least in the IT community, roundly disparaged as not only self-serving but ultimately the riskiest path of all. The reason that security through obscurity is a bad idea is obvious. If a vendor is under no pressure to produce a fix for a given problem then it can drag its feet for as long as it pleases. Just consider that Microsoft dragged its feet for six months before releasing the patch that the Sasser worm exploited. But in the time that the problem is assumed to be a secret what happens if it is independently discovered by the guys wearing black hats? They will potentially have months to exploit the problem. This was what I found disturbing about Pogue's column: He pitched a bad idea to The New York Times readership who, in general, probably accept the concept because it was printed in The New York Times. There is more than enough profound ignorance about computers in general without columnists in prominent newspapers making bad ideas sound good, especially in a field that is as critical to business continuity as security. The last thing we need is a bigger pool of potentially compromised PCs. Tell me if you're disturbed at backspin@ gibbs.com. _______________________________________________________________ To contact: Mark Gibbs Mark Gibbs is a consultant, author, journalist, and columnist and he writes the weekly Backspin and Gearhead columns in Network World. We'll spare you the rest of the bio but if you want to know more, go to <http://www.gibbs.com/mgbio>. Contact him at <mailto:[EMAIL PROTECTED]> _______________________________________________________________ This newsletter is sponsored by Veritas IDC White Paper, Distributed Applications Performance Management Performance management of distributed applications continues to grow in complexity, keeping pace with this constantly changing environment is a challenge for IT and performance management software vendors alike. Learn how the Veritas i3 Approach can be the foundation for your organization's Application Performance Management strategy. Download this IDC White Paper now http://www.fattail.com/redir/redirect.asp?CID=85613 _______________________________________________________________ ARCHIVE LINKS Gibbs archive: http://www.nwfusion.com/columnists/gibbs.html Bradner archive: http://www.nwfusion.com/columnists/bradner.html _______________________________________________________________ FEATURED READER RESOURCE NW FUSION'S LIVING BUYER'S GUIDES Updated constantly, NW Fusion's Buyer's Guides give you the latest information on product capabilities, features, requirements, pricing and more. Check out NW Fusion's Buyer's Guides on security, instant messaging, enterprise routers, anti-spam, NAS Appliances and more at: <http://www.nwfusion.com/reviews/bg.html> _______________________________________________________________ May We Send You a Free Print Subscription? You've got the technology snapshot of your choice delivered at your fingertips each day. Now, extend your knowledge by receiving 51 FREE issues to our print publication. Apply today at <http://www.subscribenw.com/nl2> International subscribers click here: <http://nww1.com/go/circ_promo.html> _______________________________________________________________ SUBSCRIPTION SERVICES To subscribe or unsubscribe to any Network World e-mail newsletters, go to: <http://www.nwwsubscribe.com/Changes.aspx> To unsubscribe from promotional e-mail go to: <http://www.nwwsubscribe.com/Preferences.aspx> To change your e-mail address, go to: <http://www.nwwsubscribe.com/ChangeMail.aspx> Subscription questions? Contact Customer Service by replying to this message. This message was sent to: [EMAIL PROTECTED] Please use this address when modifying your subscription. _______________________________________________________________ Have editorial comments? Write Jeff Caruso, Newsletter Editor, at: <mailto:[EMAIL PROTECTED]> Inquiries to: NL Customer Service, Network World, Inc., 118 Turnpike Road, Southborough, MA 01772 For advertising information, write Kevin Normandeau, V.P. of Online Development, at: <mailto:[EMAIL PROTECTED]> Copyright Network World, Inc., 2004 ------------------------ This message was sent to: [EMAIL PROTECTED]
