The potential dangers of Microsoft's secret patches

Page 1 of 2 12 LastLast

    The potential dangers of Microsoft's secret patches


    Posted: 07 May 2010
    Microsoft's security patches sometimes fix more problems than their descriptions let on. This is not a new problem, nor is it unique to Redmond. As much as anything else, it is a consequence of the way patches are produced: when a vendor is analyzing and fixing one flaw, they might well discover other flaws in the same piece of code, and their patch will fix the whole set.

    However, research by one security company, Core Security Technologies, suggests that in so doing, Microsoft may be underplaying the significance of various patches, which may lead companies to be less aggressive in rolling out patches for critical flaws.

    In particular, the company believes that secret fixes in two of last month's patches make the patches more important than Microsoft's bulletins suggest. It has issued its own bulletins to discuss the additional fixed flaws.

    Core Security Technologies analyzes patches to produce attacks for use with its penetration software; it uses real exploits to detect network vulnerabilities. Attackers do the same: comparing patched files to unpatched files to learn exactly what was patched is a common technique, which is one of the reasons that accurate assessments and timely deployment are so important.
    Source -
    The potential dangers of Microsoft's secret patches
    Posted By: JMH
    07 May 2010



  1. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #1

    Good read. I can understand Microsoft's reluctance to publicize particular vulnerabilities; but there is another side of this coin. Microsoft seems to rely on the fact that a majority of users have automatic updates turned on; therefore, MS does not have to be specific. Some of us, however, screen, pick, and choose our updates. Accurate information would be helpful. INMO this update should have been labeled critical instead of important.
      My Computer


  2. NoN
    Posts : 4,166
    Windows 7 Professional SP1 - x64 [Non-UEFI Boot]
       #2

    Sometimes better being cheat around to be better protected...I do trust entirely MS because i'm an end-user afterall...I doing the same trying to see if someone could possibly hack my computer.

    The chase!
    I'm playing dumbiest one and hope the hackers doing dumb aswell thinking that i'm the smartiest one playing the dumbiest one.
      My Computer


  3. Posts : 1,487
    Windows 7 x64 / Same
       #3

    CarlTR6 said:
    Good read. I can understand Microsoft's reluctance to publicize particular vulnerabilities; but there is another side of this coin. Microsoft seems to rely on the fact that a majority of users have automatic updates turned on; therefore, MS does not have to be specific. Some of us, however, screen, pick, and choose our updates. Accurate information would be helpful. INMO this update should have been labeled critical instead of important.
    I agree, there should be more transparency. I too like to choose every update I receive. Not everyone wants MSN Games updates or Outlook updates.
      My Computer


  4. Posts : 7,538
    Windows 10 64bit/Windows 10 64bit/Windows 10 64bit
       #4

    They don't seem to class them critical now, they are either Recommended or Optional.
      My Computer


  5. NoN
    Posts : 4,166
    Windows 7 Professional SP1 - x64 [Non-UEFI Boot]
       #5

    The probs that those are dig in download center and people are not always aware or does not takes the time to read MS bulletins...but it is a good point to let people choose, if they do know what's going on.
      My Computer


  6. Posts : 2,127
    Windows XP - Now Windows 7 Home Premium (64-bit).
       #6

    Same here. I've said before and I'll say again: I use my discretion and my judgment as to which updates to install. It does take a little bit more time to read the update info provided but it's time well spent IMO.
    Thanks for the link JMH.
      My Computer


  7. Posts : 11,990
    Windows 7 Ultimate 32 bit
       #7

    manhunter2826 said:
    Same here. I've said before and I'll say again: I use my discretion and my judgment as to which updates to install. It does take a little bit more time to read the update info provided but it's time well spent IMO.
    Thanks for the link JMH.
    Well said!
      My Computer


  8. Posts : 87
    Windows 7 Home Prem x32
       #8

    manhunter2826 said:
    Same here. I've said before and I'll say again: I use my discretion and my judgment as to which updates to install. It does take a little bit more time to read the update info provided but it's time well spent IMO.
    Thanks for the link JMH.

    Ditto.
      My Computer


  9. Posts : 7,878
    Windows 7 Ultimate x64
       #9

    manhunter2826 said:
    Same here. I've said before and I'll say again: I use my discretion and my judgment as to which updates to install. It does take a little bit more time to read the update info provided but it's time well spent IMO.
    Thanks for the link JMH.
    That's a fine approach. I take the completely opposite approach and just leave automatic updates turned on and all things have been just fine for me over the years.
      My Computer


 
Page 1 of 2 12 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 06:24.
Find Us