Microsoft's patch and pray model

Fran Foo, ZDNet Australia commentary Imagine, for a moment, if Microsoft were a hospital.

You're wheeled in for hip replacement surgery but end up with one leg amputated. Shattered, you're told not to worry ... the commonly available (and cheap) vitamin C will help control any pain. But that's not the point ... what about the leg?

You can imagine the multitude of malpractice suits in such cases.

Unfortunately, the reality is such that Microsoft will not compensate customers who use its flawed products. It's 'buyer beware' all the way.

Reading about the latest Windows patch -- which incidentally was problematic -- made me thank my lucky stars Microsoft wasn't directly involved in healthcare (I know some of you might be sniggering right now what with the state of our public hospitals).

The latest patch, released in Microsoft Security Bulletin MS05-051 on October 11, was meant to fix critical security flaws in:

  • Windows 2000 Service Pack 4
  • Windows XP Service Pack 1 and Service Pack 2
  • Windows XP Professional x64 Edition
  • Windows Server 2003 and Windows Server 2003 Service Pack 1
  • Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
  • Windows Server 2003 x64 Edition

"An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

"We recommend that Windows 2000 and Windows XP Service Pack 1 customers apply the update immediately. We recommend that customers using other operating system versions apply the update at the earliest opportunity," Microsoft said in the bulletin.

So sys admins around the world swung into action and started applying the fix. Installing the patch would hopefully ensure that vulnerabilities could not be remotely exploited, among other issues.

Unbeknownst to them, it seemed the solution to the problems had, well, problems of its own. A few days later, Microsoft publicly recanted the security alert.

"On a computer that is running Microsoft Windows XP, Windows 2000 Server, or Server 2003, one or more problems may occur after you install the critical update that is discussed in Microsoft Security Bulletin MS05-051," the company said in an advisory.

Microsoft admitted that users who installed the patch could face myriad issues such as the inability to log on, Windows Firewall and Windows Installer refusing to start, emptying of the Network Connections folder, and many more.

Was it wrong for the company to release the patch in the first place?

Fortunately for Microsoft, most customers seem to have taken the developments in their stride (lucky they still have their legs). Enterprise software is a complex animal and trying to fix a maze of code is no mean feat -- this is something customers understand. But the complexity also makes it harder to drill down to the source of the problem.

With no proper answer in sight, using Microsoft's products is increasingly costing an arm and a leg.

I've always said that an organisation's greatest enemy is internal forces, and not the competition. Microsoft's self-inflicted wounds in this whole saga is a great example.

Do you think Microsoft's latest security blunder will drive enterprise customers to investigate alternative operating systems or are Windows users generally happy with the company's products? E-mail us at edit@zdnet.com.au or talkback below.

Fran Foo is ZDNet Australia managing editor.

Advertisement

Talkback 3 comments

    microslop fred dag -- 30/10/05 (in reply to #120122583)

    The answer is simple move to Linux

    They don't care Anonymous -- 03/11/05

    I think evidence by now shows that the overwhelming majority of windows users are either clueless, or stubbornly unwilling to realize that windows is, and will most probably always be, mediocre compared to unix'es including linux.

    Issues with patching any OS Anonymous -- 04/11/05

    Please don't get into a slanging match of Windows vs Linus as it won't help anyone. And I can imagine a time where a Linux patch might cause as much trouble as some Windows patches do.
    If you have mission critical systems, then I think that the best thing to do - whatever OS you use - is to have a test server set up in the same manner as your production servers, and test patches on that *first*. That way you can see potential issues before they get to your production environment. Some folks will say that it is too much $$ to do this, but if it truly "mission critical" then you can't afford *not* to do this.

Add your opinion

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue Can not-so-smart meters help the NBN?
    It was interesting to witness Conroy's recent enthusiasm to spruik the NBN's role in supporting the Smart Grid, Smart City initiative. What a pity that Conroy hadn't yet seen the damning report from the Victorian auditor-general about that state's smart-meter roll-out.
  • Array Can the Telco Reform Act be win-win?
    In the second of our two programs looking at the Senate Inquiry into the Telecommunications Legislation Amendment Bill, we hear from shareholders, bureaucrats and industry groups.
  • Array Has New Zealand's smiling assassin delivered?
    One year into its tenure, how has the new New Zealand Government performed on issues of technology and telecommunications?
  • More blogs »

Tags

Back to top

Featured