Advertisement
Promo

Security threats Toolkit

Microsoft patches win industry trust

Munir Kotadia ZDNet.co.uk

Published: 01 Apr 2004 13:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security professionals say Microsoft's Trustworthy Computing initiative may finally be improving their lives because the latest patches and fixes being distributed by Redmond rarely break other applications.

Just over two years ago, Bill Gates fundamentally changed the way Microsoft approached software development by making security the highest priority. The company has spent millions of dollars to train staff in privacy concerns and secure programming, while building new tools and processes to help create reliable software. Although even Microsoft executives admit there is a long way to go, the investment seems to be paying off.

Security professionals attending a security event organised by non-profit organisation ISSA UK, which was held at Microsoft's headquarters in Reading on Wednesday, said that although Microsoft still has a lot of work to do before its patching system even meets basic requirements, the patches themselves have improved.

David Merry, senior network engineer at UK consultancy Polar Computer communications, said the change in Microsoft's policy is working well, so far: "We see that Microsoft's patches do tend to be more reliable and cause less interference with our client's machines than they did in the past. We are all seeing that security is a bigger issue -- in Windows 95, accessibility was the key but there is more focus now," he said.

A senior consultant from a major financial institution, who asked to remain anonymous, said that over the past nine months Microsoft patches have not caused any problems with existing applications: "Historically, in my department the view is that you don't trust Microsoft patches, but over the past eight or nine months, we haven't had any integration problems at all. Yes, I'd say there is a definite improvement there," he said.

Graham Titterington, principal analyst at Ovum, said he had heard of "very few" reports where patches were breaking systems because Microsoft's testing procedures has improved. However, he warned companies to not get complacent with their own internal testing: "This is quite an achievement when you think that they are being applied to systems with varying levels of previous patching. However, good system management practice says that you shouldn't make any changes to a working system without testing the system in its new form, and every large organisation has a system that is to some extent unique -- so a risk remains," he said.

However, there are still problems. In February Microsoft released a patch for Internet Explorer outside of its monthly cycle to stop the company's browser from being used to fix a URL spoofing flaw. But the update also stopped certain URLs from being used to access password-protected Internet resources, which was a relatively common practice.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
86 out of 145 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:







Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters