 |
No security patches for December? Is that good news or bad?
SECURITY.ITWORLD.COM --- 12/16/2003
Brent Huston
I have to admit that I am a bit dismayed at Microsoft on this one. A few
months ago they decided to change their "hotfix" release policy to
schedule patch releases for the second Tuesday of each month. So, with
bated breath, the entire computing community waited for the December
release date. When "Patch Tuesday" came, we continued to wait. Around
the middle of the afternoon the site was updated with a curt "Microsoft
has no security bulletins to release as part of the monthly release
cycle for December."
Now, that simple sentence leaves us wondering about a few issues. First,
does this mean that no new security issues were identified during the
past four weeks, or does this mean that though issues were found,
Microsoft has no patches for the problems yet? As if the entire release
cycle issue did not leave clients feeling vulnerable enough, the vague
posted entry on the Microsoft site leaves them with more to worry about.
Next, if the simple one line posts are all the information about the
status of security at Microsoft we are going to get, we must ask
ourselves how comfortable the new policy makes us. Microsoft, please
provide us with a little more information! Something like; "Microsoft
has no new patches to release at this time. All known security issues
have been addressed." Or even, "Microsoft has no new patches at this
time, but we are currently investigation several issues that have been
brought to our attention." At least let us know if there is something or
anything going on!
So, sit back and enjoy the holidays. At least for now the patch race is
at a lull. You can sip some eggnog and play some reindeer games. Just
make sure you're ready come the second Tuesday in January, because you
just never know what waits for you.
Brent Huston is president and CEO of MicroSolved Inc., a systems and
network security-consulting service for Fortune 500 companies and
government facilities. He has 12 years of professional experience in
cyber security testing, network monitoring, scanning protocols,
firewalls, viruses and virus prevention formats, incident response,
forensic computing and hacker techniques. He is an accomplished
computer and information security speaker, and has published numerous
white papers on security-related topics. He also served as co-author
and technical editor of "Hack Proofing Your E-Commerce Site" from
Syngress Publishing. Write him at mailto:brent.huston@itworld.com.
|
|
|
|
|
Advertisement | |
|  |
Sponsored links |
 |
HP Wireless Solutions for business. Proven technology. Superior service.
|
 |
How do you maximize return on your IT investments? Learn more now.
|
 |
Setting the pace of PC technology. HP Compaq Desktops, starting at $367.
|
 |
By networking your storage, you can reduce costs, protect your information--and simplify management.
|
 |
SMBs: Specialized News, Webcasts, white papers, and newsletters. Go NOW!
|
 |
Achieve Maximum Effectiveness and Productivity for Remote Workers
|
 |
Organizations need adaptable, intelligent networks to meet the need for security, mobility and converged voice, video, and data.
|
 |
The latest advancements in secure remote access right at your fingertips.
|
 |
Find the Right Balance Between Useful Wireless Networks and Security
|
|