Announcement

Collapse
No announcement yet.

Yet another "critical" update from M$

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Yet another "critical" update from M$

    It's that time of month again:

    Originally posted by BBC
    Microsoft has warned that a "critical" flaw in the latest versions of its Windows operating system could leave computers vulnerable to hackers.
    The flaw affects systems running Windows NT, Windows 2000, Windows XP or Windows Server 2003 software.

    It has urged all home users and firms to download a software repairing patch free from its website to fix it.

    The flaw was found by a net security firm in July 2003. Microsoft announced it in its monthly security bulletin.

    'Extremely deep problem'

    Experts have warned that if home users and companies with these operating systems do not download the fix, hackers could, in theory, break into computers and take files, delete or steal valuable data, or snoop on what that user is doing.

    It could also leave systems open to worm and virus threats.

    "It does affect all [current] versions of Windows," said Stephen Toulouse, security program manager for Microsoft's Security Response Center

    He added the problem was "an extremely deep and pervasive technology in Windows" which affects the language standard that computers use to communicate with each other.

    Marc Maiffret of US company eEye Digital Security, who informed Microsoft of the vulnerability over six months ago, has criticised Microsoft for taking so long to come up with a patch to fix it.

    "This is one of the most serious Microsoft vulnerabilities ever released," said Mr Maiffret.

    "The breadth of systems affected is probably the largest ever." He added that, unusually, even the most secure Windows networks would be vulnerable.

    But Sal Viveros, security expert with McAfee Security, told BBC News Online this delay was standard practice within the industry.

    "Typically if someone identifies a flaw, they give the vendor a certain amount of time to fix it. If people don't know about it, virus writers are less likely to write something to take advantage of it."

    If Microsoft had announced the flaw without having a fix for it, the potential damage would have been much much worse, he added.

    Steven Philippsohn, who chairs a government fraud and cybercrime panel, said the delay could be a headache for Microsoft.

    "I have no doubt that if manufacturers in cases like this know about a flaw in their system and don't inform at earliest opportunity possible, they could be liable for losses," Mr Philippsohn told BBC News Online.

    "It has been made more serious by the fact Microsoft have accepted that they were told about the flaw months ago.

    "If a company can prove they suffered losses because of this, they have a good chance of making a claim," he said.

    Microsoft said it took months because it wanted to ensure a single patch solved any related problems.

    Open to worms

    According to security experts, many home users are not aware they should fix flaws and download patches when they are identified.

    This leaves computers vulnerable to attack from malicious software. Historically, Mr Viveros said, net security firms have seen an increase in mass-mailing worm and virus attacks which try to take advantage of unpatched systems after flaws are discovered.

    "There is no evidence that the recent worms [Mydoom and its variants] took advantage of this flaw," he said.

    "But historically, what we have seen is that computer users do not patch their systems, which is why we continue to see such worm attacks."

    He urged computer users to download the patch and to make sure they keep anti-virus software and firewalls up-to-date


    #2
    The flaw was found by a net security firm in July 2003. Microsoft announced it in its monthly security bulletin.
    That's so bad it's almost funny.
    They wait 3/4 of a year before they tell anybody?.
    How many people have been affected by this?

    And people ask why I prefer Macs...

    Comment


      #3
      Yup its pretty shameful that they took so long to fix it just in order "to get a single patch". I guess thats just the spin - what probably happened is it got lost amidst the red tape and forgotten about somehow.

      On the subject of "home users keeping upto date by downloading patches". I think what a lot of so called experts forget is:

      1) Most home users are just that: home users. Until they lose there data its just not going to be important to them.

      2) They've bought there software from whats percieved as a reputable firm. How often do consumers patch other types of product (anybody heard of a toaster update? - though once there networked I guess we'll be installing drivers for those too).

      3) Many people (the majority) are still on dial up. And at the rate patches, service packs, virus updates and updates are issued a dial up user could quite easily spend half there online life waiting for them to download. Couple that with a lot of home users still on pay as you go and it could become expensive too.

      In Microsoft's defence (I can't believe I just said that after spending my day swearing and cursing at the vs.net ide - my god thats atrocious) they probably have many more magnitude of hackers trying to break there systems than anybody else. I'm not claiming they produce the world's securest software but even if they did I suspect there would still be problems....

      Comment


        #4
        These flaws are inevitable.
        I'm not claiming macs don't have them (although none are any where near as severe).

        What I find incredible is the time delay.

        Comment


          #5
          Originally posted by Ish
          I can't believe I just said that after spending my day swearing and cursing at the vs.net ide - my god thats atrocious
          Oh good, I'm not ****ing insane then. I installed the latest version, booted it up and, ugh. What the heck? I'd had similar problems with the 2002 version. A menu option for Help on Help? Ok. Is this meant to be user interface? This is from MS, the company that makes intuitive UIs.

          I went back to Dev C++ shortly after that. Good thing it was free under the Uni site licence. I would have been annoyed to have paid for it.

          Comment


            #6
            Surely it's better to announce a fault once a fix was available than announce a fault six months ago when it wasn't? Although critical, this flaw was apparently another very obscure bug involving a buffer overflow and unlikely to be exploited unless made public. 100% bug free and unexploitable systems are a myth.

            Regards
            Marty

            Comment

            Working...
            X