Full Disclosure mailing list archives

Re: RE: Computer Sabotage by Microsoft


From: Michael D Schleif <mds () helices org>
Date: Thu, 11 Sep 2003 23:19:18 -0500

Thor Larholm <thor () pivx com> [2003:09:11:15:28:33-0700] scribed:
<snip />

One thing is sure, we will see a greater level of automation for patch
management in the future. I can reasonably imagine the default
installation of Longhorn to automatically download and install
critical
security updates, and given an agreement like we already have with
most
AV software I see no problems in that.

And when that happens, m$oft will lose a very profitable bit of
business, especially regarding HIPAA governed medical facilities,
research labs, high security government applications, &c.

The fact is, it can take many months and tens of thousands of dollars to
get a single piece of medical equipment certified at a fixed and static
configuration, any change from which automatically nullifies said
certification.  These types of enterprises cannot allow anybody to just
up and change software -- patches or not -- or risk losing income, or --
worse -- going out of business.

Unfortunately, automatic updates are not quite the slam dunk some might
think them to be . . .

-- 
Best Regards,

mds
mds resource
877.596.8237
-
Dare to fix things before they break . . .
-
Our capacity for understanding is inversely proportional to how much
we think we know.  The more I know, the more I know I don't know . . .
--

Attachment: _bin
Description:


Current thread: