{"id":4155,"date":"2003-01-28T07:04:56","date_gmt":"2003-01-28T12:04:56","guid":{"rendered":"http:\/\/hill-kleerup.org\/blog\/wp\/?p=4155"},"modified":"2003-01-28T07:04:56","modified_gmt":"2003-01-28T12:04:56","slug":"patch_it_just_p","status":"publish","type":"post","link":"https:\/\/hill-kleerup.org\/blog\/2003\/01\/28\/patch_it_just_p.html","title":{"rendered":"Patch it!  Just patch it!  Whoo!"},"content":{"rendered":"<p>Micro$oft is more than happy to slam lax sysadmins who don&#8217;t keep their systems patched up-to-the-minute, and thus leave them vulnerable to things like the recent <a href=\"http:\/\/news.com.com\/2100-1001-982135.html\">Slammer\/Sapphire virus<\/a>.  &#8220;Just keep applying this endless set of security patches,&#8221; they say, &#8220;and all will be well, and all will be well.&#8221;<\/p>\n<p>Which no doubt explains why <a title=\"Microsoft fails Slammer's security test - Tech News - CNET.com\" href=\"http:\/\/news.com.com\/2100-1001-982305.html?tag=cd_mh\">Micro$oft&#8217;s own servers got hit so hard<\/a> by the virus attack.<\/p>\n<p class=\"block\">&#8220;All apps and services are potentially affected and performance is sporadic at best,&#8221; Mike Carlson, director of data center operations for Microsoft&#8217;s Information Technology Group, stated in an [internal] e-mail sent at 8:04 a.m. PST Saturday to other members of Microsoft&#8217;s operations groups. &#8220;The network is essentially flooded with traffic, making it difficult to gather details concerning the impact.&#8221; <\/p>\n<p>That&#8217;s right &#8212; even M$&#8217;s own sysadmins weren&#8217;t up to date with all the patches on their own internal systems.<\/p>\n<p class=\"block\">&#8220;This shows that the notion of patching doesn&#8217;t work,&#8221; said Bruce Schneier, chief technology officer for network protection firm Counterpane Internet Security. &#8220;Publicly, they are saying it&#8217;s not our fault, because you should have patched. But Microsoft&#8217;s own actions show that you can&#8217;t reasonably expect people to be able to keep up with patches.&#8221;<\/p>\n<p>And is it just because all those sysadmins are lazy?  No, they&#8217;re just worried that patches to fix some things will instead break others.<\/p>\n<p class=\"block\">\u201cSeems like every time I install a system patch, something else goes wrong with my system,\u201d said Frank Beier, president of Web design firm Dynamic Webs. The designer said many system administrators won\u2019t patch for many months, because they don\u2019t trust Microsoft to fix the problem without breaking some other function of the software. <br \/>\n\u201cIn most cases, I&#8217;m better off just playing Russian roulette with the hackers until our servers are broken into,\u201d he said. <\/p>\n<p><p><small>(also via <a href=\"http:\/\/boingboing.net\/2003_01_01_archive.html#90242950\">BoingBoing<\/a>)<\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Micro$oft is more than happy to slam lax sysadmins who don&#8217;t keep their systems patched up-to-the-minute, and thus leave them vulnerable to things like the recent Slammer\/Sapphire virus. &#8220;Just keep&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[20],"tags":[],"class_list":["post-4155","post","type-post","status-publish","format-standard","hentry","category-hi-tech"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":4365,"url":"https:\/\/hill-kleerup.org\/blog\/2003\/09\/17\/routing_around.html","url_meta":{"origin":4155,"position":0},"title":"Routing around the damage","author":"***Dave","date":"Wed 17-Sep-03 11:55am","format":false,"excerpt":"A few days ago, I came across a post from Seki about Veri$ign's latest Internet power-grab. V$, you see, not only has monopoly control of the .com and .net top...","rel":"","context":"In &quot;Blogging &amp; Internet&quot;","block_context":{"text":"Blogging &amp; Internet","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":5858,"url":"https:\/\/hill-kleerup.org\/blog\/2004\/07\/09\/security_is_a_c.html","url_meta":{"origin":4155,"position":1},"title":"Security is a &#8220;competitive advantage&#8221;","author":"***Dave","date":"Fri 9-Jul-04 9:44am","format":false,"excerpt":"Micro$oft is selling security as a \"competitive advantage\" that it has over the industry. Attendees at last year's event, in New Orleans, cheered when Microsoft Chief Executive Officer (CEO) Steve...","rel":"","context":"In &quot;Hi-Tech&quot;","block_context":{"text":"Hi-Tech","link":"https:\/\/hill-kleerup.org\/blog\/category\/hi-tech"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":10084,"url":"https:\/\/hill-kleerup.org\/blog\/2006\/09\/07\/patch_managemen.html","url_meta":{"origin":4155,"position":2},"title":"Patch Management and the bottom line","author":"***Dave","date":"Thu 7-Sep-06 9:18am","format":false,"excerpt":"Bruce Schneier asks (rhetorically) why is it that Micro$oft can only bring itself to issue patches once a month to clean up security holes in its operating system, browser, and...","rel":"","context":"In &quot;Big Business&quot;","block_context":{"text":"Big Business","link":"https:\/\/hill-kleerup.org\/blog\/category\/big-business"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":9387,"url":"https:\/\/hill-kleerup.org\/blog\/2006\/07\/18\/broken_controls.html","url_meta":{"origin":4155,"position":3},"title":"Broken controls","author":"***Dave","date":"Tue 18-Jul-06 6:43am","format":false,"excerpt":"My company is finally rolling out the critical, and increasingly inescapable Micro$oft Security Patch MS06-021.\u00a0 This cumulative patch includes lawsuit-required code to break (or at least bend) ActiveX controls.\u00a0 Rather...","rel":"","context":"In &quot;Hi-Tech&quot;","block_context":{"text":"Hi-Tech","link":"https:\/\/hill-kleerup.org\/blog\/category\/hi-tech"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":869,"url":"https:\/\/hill-kleerup.org\/blog\/2001\/11\/08\/so_this_is_how.html","url_meta":{"origin":4155,"position":4},"title":"So this is how you crack down on a monopolist","author":"***Dave","date":"Thu 8-Nov-01 11:25am","format":false,"excerpt":"The Register has a number of articles on the Micro$oft\/Dept. of Justice \"settlement.\" The bottom line? Micro$oft is now in a stronger position than it was before, because it has...","rel":"","context":"In &quot;Big Business&quot;","block_context":{"text":"Big Business","link":"https:\/\/hill-kleerup.org\/blog\/category\/big-business"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":893,"url":"https:\/\/hill-kleerup.org\/blog\/2001\/11\/04\/what_do_you_hav.html","url_meta":{"origin":4155,"position":5},"title":"What do you have in your wallet?","author":"***Dave","date":"Sun 4-Nov-01 1:41pm","format":false,"excerpt":"An open-source programmer spent about a half-hour combining a couple of known web site vulnerabilities to come up with a mechanism to let someone exploit the Microsoft Passport scheme and...","rel":"","context":"In &quot;Hi-Tech&quot;","block_context":{"text":"Hi-Tech","link":"https:\/\/hill-kleerup.org\/blog\/category\/hi-tech"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts\/4155","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/comments?post=4155"}],"version-history":[{"count":0,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts\/4155\/revisions"}],"wp:attachment":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/media?parent=4155"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/categories?post=4155"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/tags?post=4155"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}