SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Security Products, Practices and Infrastructure

Getting it right when it comes to IT security

Getting it right when it comes to IT security

By:  Frank Hayes  On: 02 Feb 2006 For: IT World Canada Creator

Just when we think Microsoft finally understands the importance of security, we get this WMF fiasco. Here was a situation with all the makings of a catastrophe: a zero-day attack based on a long-standing design flaw, discovered at a time when everyone’s on vacation, exploited using something as innocuous as a picture on a Web site.

Just when we think Microsoft finally understands the importance of security, we get this WMF fiasco. Here was a situation with all the makings of a catastrophe: a zero-day attack based on a long-standing design flaw, discovered at a time when everyone’s on vacation, exploited using something as innocuous as a picture on a Web site.

Microsoft’s response? A crash holiday effort that produced a working, effective patch within days. Followed by a decision to not release the fix until the next monthly patch dump, and a public announcement of that decision so that every bad guy could declare open season on Windows PCs until Jan. 10. Followed, at last, by a decision to release the patch ahead of schedule after all.

That, finally, was the right decision. But why did Microsoft’s management strain so mightily in the wrong direction before doing the right thing? Microsoft programmers did their job. We know that because Microsoft’s WMF patch showed up briefly on a security Web site a week before its scheduled release (“inadvertently,” Microsoft said). Security gurus who examined it said it worked and didn’t conflict with a non-Microsoft patch that was already available.

But Microsoft didn’t release its patch then. Why not? The official answer: It wasn’t thoroughly tested and available in all languages and for all versions of Windows. The scuttlebutt: Microsoft bigwigs didn’t want “Microsoft Issues Emergency Fix” headlines and viewed the WMF threat as overblown — although, fortunately, someone in Redmond thought it was dangerous enough to build an emergency fix during the holiday break.

Let’s be clear about this: Microsoft was right to reverse course. Those bigwigs who wanted to hold the patch were right to listen to customers and release it ahead of schedule. Yeah, the flip-flop looks embarrassing, and they’ll take some flak for that. But they deserve thanks, not grief.

Getting that patch out the door four days early is going to make a difference. We’re all better off with the right decision than with a foolish consistency. But, that said, why the heck did they get it so wrong in the first place?

They had options. They could have released a patch early and warned customers that it wasn’t fully tested. They could have even called it a beta and asked customers for feedback, since no IT shop was going to put it into production without testing it.

Instead, amid growing concerns from security experts and hundreds of new WMF exploits and tools for bad guys, Microsoft kept saying customers should just tweak the Windows registry and wait for the next patch cycle.

Microsoft’s decision-makers apparently got two things wrong. First, they underestimated the seriousness of the WMF threat. And second, they assumed that their estimate was the one that mattered.

They were wrong. Security decisions belong to IT shops. That’s where the buck stops. That’s where risk can be assessed. To patch or not, when to patch, what to patch...corporate IT has to make those choices.


Sign up for our Newsletters
Tags: Windows












Print |  Views: 595   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Frank Hayes Frank Hayes is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Microsoft's new OS extends life of old PCs
Microsoft's new OS extends life of old PCsMicrosoft Corp. released a new version of its operating system for businesses this week that extends the life of older PCs by effectively turning them into thin-client computers.
Windows fix conflicts with HP software
Windows fix conflicts with HP softwareIf you've been having severe problems over the past week with Internet Explorer and Office applications, it could likely trace back to a major conflict between a recently distributed critical Microsoft security patch and Hewlett-Packard software shipped with numerous HP products.
Microsoft fixes Vista OS flaw
Microsoft fixes Vista OS flawMicrosoft Corp. has issued a patch for a preliminary version of its Vista OS for the same graphics-rendering problem that raised concerns about current versions of the Windows OS earlier this month.
The Conficker conflaguration
three months is a pathetic response time for pretty much every business issue, but it’s particularly pathetic when you’re talking about an issue that could cripple your employee’s ability to work at all. and yet, as the conficker/downadup worm continues to wreak havoc across enterprise it networks, security researchers are saying that many firms still haven’t deployed the patch microsof
blog comments powered by Disqus