Re: [SC-L] Computerworld op/ed on vulnerability patch cycle

2004-04-14 Thread Kenneth R. van Wyk
Alexander Antonov wrote: I believe the issue of automatic updates was already discussed on other security-related lists. Yes, I agree, but that's not what I was commenting on specifically. Certainly, we've seen automatic patches for a few years now. (And for many systems, e.g., desktop users, I

RE: [SC-L] Computerworld op/ed on vulnerability patch cycle

2004-04-14 Thread Alexander Antonov
Ken, I believe the issue of automatic updates was already discussed on other security-related lists. There are two main problems: - everybody who has subscribed is at a complete mercy of the software manufacturer, if a new bug is introduced in a new release, then everybody becomes vulnerable be

[SC-L] Computerworld op/ed on vulnerability patch cycle

2004-04-13 Thread Kenneth R. van Wyk
FYI, I just saw an opinion piece on Computerworld written by Bill Addington called "Slow down the security patch cycle". (See http://www.computerworld.com/printthis/2004/0,4814,92037,00.html for full story.) In the article, the author discusses some possible solutions for improving the distri