Advertisement
Promo

Security threats Toolkit

Microsoft patches win industry trust

Munir Kotadia ZDNet.co.uk

Published: 01 Apr 2004 13:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security professionals say Microsoft's Trustworthy Computing initiative may finally be improving their lives because the latest patches and fixes being distributed by Redmond rarely break other applications.

Just over two years ago, Bill Gates fundamentally changed the way Microsoft approached software development by making security the highest priority. The company has spent millions of dollars to train staff in privacy concerns and secure programming, while building new tools and processes to help create reliable software. Although even Microsoft executives admit there is a long way to go, the investment seems to be paying off.

Security professionals attending a security event organised by non-profit organisation ISSA UK, which was held at Microsoft's headquarters in Reading on Wednesday, said that although Microsoft still has a lot of work to do before its patching system even meets basic requirements, the patches themselves have improved.

David Merry, senior network engineer at UK consultancy Polar Computer communications, said the change in Microsoft's policy is working well, so far: "We see that Microsoft's patches do tend to be more reliable and cause less interference with our client's machines than they did in the past. We are all seeing that security is a bigger issue -- in Windows 95, accessibility was the key but there is more focus now," he said.

A senior consultant from a major financial institution, who asked to remain anonymous, said that over the past nine months Microsoft patches have not caused any problems with existing applications: "Historically, in my department the view is that you don't trust Microsoft patches, but over the past eight or nine months, we haven't had any integration problems at all. Yes, I'd say there is a definite improvement there," he said.

Graham Titterington, principal analyst at Ovum, said he had heard of "very few" reports where patches were breaking systems because Microsoft's testing procedures has improved. However, he warned companies to not get complacent with their own internal testing: "This is quite an achievement when you think that they are being applied to systems with varying levels of previous patching. However, good system management practice says that you shouldn't make any changes to a working system without testing the system in its new form, and every large organisation has a system that is to some extent unique -- so a risk remains," he said.

However, there are still problems. In February Microsoft released a patch for Internet Explorer outside of its monthly cycle to stop the company's browser from being used to fix a URL spoofing flaw. But the update also stopped certain URLs from being used to access password-protected Internet resources, which was a relatively common practice.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
86 out of 147 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters