Showing posts with label microsoft. Show all posts
Showing posts with label microsoft. Show all posts

Monday, September 17, 2007

Microsoft Forces Stealth Updates Even without Automatic Updates On

Here is another one from the "Microsoft is smarter than you are" file.

Microsoft was recently exposed for pushing out updates to your computer even if you don't have Automatic Updates turned on. Their position is that they need to continue to update the Windows Update Service components in order to notify you of updates and "maintain the quality of the service".

This presents a huge trust issue for many, especially IT support personnel, myself included. The reasons that Microsoft has announced on this issue are somewhat valid, but still cause a trust issue. If they are doing this unilaterally with some components, what keeps them from updating other components that they choose to update at will? The fact that Microsoft tried to do this behind the scenes is quite alarming.

Partnering with BIG BROTHER

There are many that are totally outraged by this Microsoft trust issue. My take on it is that you knew what you were getting into when purchasing and choosing to run Microsoft products, so deal with it. If you don't trust Microsoft to write your OS and write patches for your OS, then go play with someone else's OS. Granted, there are not many choices that most corporate average desktop users can deal with and with that, many IT support personnel are stuck with Microsoft desktops. If Microsoft screws this up and some compromised code gets pushed out to your desktops, yes, it will hurt and screw you up for a few days, but think about the pain you would endure to attempt to convert those desktop users to Ubuntu, or any other Unix like environment. Ultimately, Microsoft would be at fault for leaving the back door open.

For more detail on the MS stealth updates:

http://blogs.technet.com/mu/archive/2007/09/13/how-windows-update-keeps-itself-up-to-date.aspx

http://windowssecrets.com/comp/070913/#story1

Tuesday, July 10, 2007

M$ Patch Tuesday Overview Report

SANS released a very useful "July 'Black Tuesday' overview" report. I don't know if they do this for every patch release Tuesday, but it is a nice report and I suggest you check it out at:
http://isc.sans.org/diary.html?storyid=3120&rss

They have columns for level of importance for Servers and Desktops (ISC rating) which is a nice feature. I like getting the second opinion from SANS!

Wednesday, June 27, 2007

Beware of Fake Microsoft Patch

The spam will have a subject of:
Microsoft Security Bulletin MS07-0065 - Critical Update

The body claims to have a patch for a zero day vulnerability, but contains
malware.

For more detail, please see this SANS alert:
http://isc.sans.org/diary.html?storyid=3054&rss


A real, legitimate Microsoft Security Bulletin will be a PGP Signed text message.




Friday, June 1, 2007

Knowledge Base Alertz Notification

For those of you that need to keep up on Microsoft bug fixes (read security issues!) the task can be a real pain in your backside... to say the least.

To help ease the pain there is a service by Scott Cate at www.kbalertz.com
This free service will send you daily email alerts when a new KB article is posted for each KB area that you select.
Check it out, and Thank You Scott for creating this service!