Microsoft Silently Patches..

Posted by jericho Tue, 25 Apr 2006 09:37:29 GMT

Sure, the news that Microsoft silently patches vulnerabilities made the rounds. But honestly, who was surprised in the least? We’ve all known it is a common practice among many vendors, not just Microsoft. As you may have guessed, the reasoning behind this practice is a commonly heard justification:

“We want to make sure we don’t give attackers any [additional] information that could be used against our customers. There is a balance between providing information to assess risk and giving out information that aids attackers,” Mike Reavey said.

Ok, we can buy that up to a certain point. So how about just saying “This patch also fixed X internally discovered vulnerabilities during internal audits.” At least give us an idea just how big the patch really is and help us figure out just how many vulnerabilities are being patched. That doesn’t give the bad guys enough information to act on.

Posted in  | 1 comment

Comments

  1. sandro gauci said about 3 hours later:

    i don’t know how effective this is considering that the bad guys usually have enough information when they look at the patch itself.

    some reference can be found on this blog itself: http://osvdb.org/blog/?p=20

    I guess that defeats the commonly heard justification ;-)

(leave url/email »)

   Comment Markup Help Preview comment