Micro$oft is more than happy to slam lax sysadmins who don’t keep their systems patched up-to-the-minute, and thus leave them vulnerable to things like the recent Slammer/Sapphire virus. “Just keep applying this endless set of security patches,” they say, “and all will be well, and all will be well.”
Which no doubt explains why Micro$oft’s own servers got hit so hard by the virus attack.
“All apps and services are potentially affected and performance is sporadic at best,” Mike Carlson, director of data center operations for Microsoft’s Information Technology Group, stated in an [internal] e-mail sent at 8:04 a.m. PST Saturday to other members of Microsoft’s operations groups. “The network is essentially flooded with traffic, making it difficult to gather details concerning the impact.”
That’s right — even M$’s own sysadmins weren’t up to date with all the patches on their own internal systems.
“This shows that the notion of patching doesn’t work,” said Bruce Schneier, chief technology officer for network protection firm Counterpane Internet Security. “Publicly, they are saying it’s not our fault, because you should have patched. But Microsoft’s own actions show that you can’t reasonably expect people to be able to keep up with patches.”
And is it just because all those sysadmins are lazy? No, they’re just worried that patches to fix some things will instead break others.
“Seems like every time I install a system patch, something else goes wrong with my system,” said Frank Beier, president of Web design firm Dynamic Webs. The designer said many system administrators won’t patch for many months, because they don’t trust Microsoft to fix the problem without breaking some other function of the software.
“In most cases, I’m better off just playing Russian roulette with the hackers until our servers are broken into,” he said.
(also via BoingBoing)
“Seems like every time I install a system patch, something else goes wrong with my system,”
Yep. I’ve noticed that, too. Funny. Hah.
Microsoft rarely patches SQL. It tells you to apply “hotfixes,” which tend to cause more problems than they’re worth.
However, our patched SQL Server and our NetScreen firewall stopped us from being infected. whoo!