Microsoft stands by Patch Tuesday for Vista

Software giant Microsoft is set to continue releasing security patches and other updates on the first Tuesday of every month despite admitting that malicious software authors have started exploiting the predictability of its updates.

"It's very difficult because on the one side we have businesses saying give us a set date when [the patches] are coming out and on the other hand we have the people instigating this saying, 'now you are being more predictable, I am going to build my processes around that.'.

"Two years ago how many [out of cycle] fixes did we release? Very few. Recent times we have done a lot of that to combat the zero day exploits," Peter Watson, Microsoft Australia chief security advisor, told ZDNet Australia.

Around three years ago, Microsoft started releasing security patches and software updates only on the first Tuesday of every month -- unless the patch was designed to fix a dangerous vulnerability that was actively being exploited.

Watson said that despite "Exploit Wednesday" becoming a regular occurrence, Microsoft has no plans to change its patching schedules for Windows Vista, which was officially released this morning.

However, Watson claimed that Vista is more secure by design and contains several security controls that will help reduce the operating system's vulnerabilities compared with previous versions of Windows.

One security feature he highlighted was Universal Access Control (UAC), which addresses one of the biggest criticisms of previous Windows versions. Before UAC, the majority of Windows users were logged in as administrators, which means applications -- legitimate or otherwise -- could be installed with little or no interaction by the user.

With UAC activated, applications cannot be installed unless the user gives permission -- usually by entering a password.

"UAC provides the ability for [Windows] to say 'did you know you are downloading something and did you really want to do it?'," said Watson.

Advertisement

Talkback 0 comments


Latest Videos

ZDNet's CIO Vision Series

Department of Defence | Greg Farr, CIO (part two)

In the second part of his interview, Defence CIO Greg Farr talks about outsourcing, the skills crisis and reveals his most urgent IT priority.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Angus Kidman I'm a celebrity, don't back me up
    Celebrity comes with its perks — free alcohol, better-looking partners, lots of holiday time — and disadvantages — constant media intrusions, being forced to appear in films with Eddie Murphy for the long-term good of your career, and having to do mindless radio interviews with angry men who've been awake since 4am.
  • Array Lies, damned lies and telco stupidity
    Earlier this month, Telstra put out a press release trumpeting that it's come up with a new phone coaching service to help people who are "bamboozled" by their mobiles. Another excellent example of wrongheaded thinking from the mobile industry.
  • Array Dear carriers: More walking, less talking
    Sometimes, a well-placed and well-timed letter can make all the difference. Other times, it can make no difference at all — and even hurt your case. This week's missive by the Competitive Carriers' Coalition, I would suggest, falls into the latter category.
  • More blogs »

Tags

Back to top

Featured