Microsoft Announces Four "Critical" Patches

Miscellaneous Forums/General Discussion/Microsoft Announces Four "Critical" Patches

http://www.tomshardware.co.uk/Microsoft-patches-updates-bugs,news-29108.html

Microsoft has announced that next week will see the company release updates targeted at four vulnerabilities with Windows.

All four are vulnerabilities are branded critical, and if exploited allow for remote code execution. While it may look like the number of updates is relatively small because affected programs are listed as Windows Media Player, Microsoft Encoder and Microsoft Office, it’s the fourth bulletin that just claims to affect Windows that has us worried.


Don't use M$ programs? problem solved.

Don't use computer? problem solved.

Don't use Windows? ;)

This is Critical! And we have the fixes!
...But they won't be served up until next Tuesday. (Maybe poke around our web site for a few hours if you really need them).

I think I have been spoiled by the Debian update infrastructure , with that openssl debacle a few months ago being a wonderful example of instant update distribution. Problem was detected -- albeit a bit late -- fixed and successfully sent downstream to users of Debian and all Debian-based distros like Ubuntu within the same day.

Yeah, and both Debian and Linux need to be rebooted or at least temporarily taken offline for any changes to take effect - causing downtime, causing overtime, causing night shifts, causing costs. I don't see a difference between the two, only that it is hip to hate and bash Microsoft for providing the same kind of service for which Linux distributions are being hyped without a special reason. (And no, Linux is not for free, unless your work and time do not cost anything.)

I've been running Windows Servers in a corporate environment for years - safely behind good firewalls where they belong - and cannot complain about the reliability of Microsoft's Windows Server products. Knowing the prices of the Enterprise Agreement that we had with Microsoft, even the license costs were ridiculously cheap (Red Hat or Novell Enterprise Linux actually would have cost us more per server).

The actual solution for most security problems would be to not use non-managed programming languages like C or C++ that create all those nice buffer overflow and other memory allocation errors which in turn create those security holes. You won't use your manhood if you use a garbage collected language, but your users will have less security problems to fight with. That approach won't solve all issues, but a huge amount of them.

Yeah, and both Debian and Linux need to be rebooted or at least temporarily taken offline for any changes to take effect - causing downtime, causing overtime, causing night shifts, causing costs.
You must have "Linux" confused with "Windows". When exactly do you *need* to reboot Linux?

You must have "Linux" confused with "Windows". When exactly do you *need* to reboot Linux?

The most obvious one is after any changes/updates to the kernel. Otherwise it's plain sailing.

actually you dont -HAVE- to reboot.

For the kernel update to take effect you do, but thats usually the only time. Theres not a desparate rush to do it because the security problems are not usually as scary. Almost all other non-kernelific updates can be performed simply by restarting the service. This applies to almost everything else like networking stuff, servers, the gui & Xserver, device drivers etc.

In short you occasionally need to reboot but no where near as often as windows. Windows usually needs a 'clearout' reboot after simply RUNNING non stop for a couple of weeks, let alone updates.

Welcome to another round of geek hair splitting.


Which part of


at least temporarily taken offline for any changes to take effect



do I need to rephrase to make it easier to understand?

You might not need to reboot the world's greatest invention since sliced bread (TM), but it certainly won't run through an update without having to babysit it or without a minimal downtime; and downtime, for a user, is when the system is not available to him. It does not necessarily mean downtime as in rebooting. For the customer, temporarily unavailable is temporarily unavailable.

Or to put it more bluntly: Nobody except for a few geeks gives a crap whether only a few services/daemons need to restart or the entire system goes through a five to ten minute boot process.

You have to announce a maintenance time window for either system, and you have to pay your staff to be there.

Besides, when do I *need* to reboot Windows? I can run my servers and workstations safely behind a hardware firewall until kingdom come and never need to install an update. In fact, there are many environments where it is strictly forbidden to install updates without a ton of accompanying QA.

Windows Server 2003 has never failed me, and I'm sure you guys will tell me the same about your Linux boxes.

/EOL

When exactly do you *need* to reboot Linux?
When you have to work?

What about a hardware firewall is going to protect your servers from bugs in remotely accessible services? Let alone workstations which have the additional issue of somebody behind the keyboard exacerbating the whole problem.

I don't think you've ever done an update on a Linux system either. There's zero comparison between a system restart at a minimum of 5 minutes on a Windows system (usually at least 10 with major updates) and a few seconds or even zero on a restart of a service.

Hell, I can update SSH on my Linux boxes while connected to SSH without a disconnect. There's no downtime to announce.

Added to that, I can update Linux systems knowing full well exactly which pieces of the system are getting updated, meaning there's much less QA work required. Most Windows updates patch numerous libraries all over the place. Add to that how many people are testing various distributions on a regular basis as opposed to Microsoft's typically closed shop approach.

There's no comparison between the two. If it wasn't for the huge popularity of Microsoft's programming languages, they wouldn't much exist in the server market anymore.

When you have to work?
Impressive! :P

On the thought of updates, though, you don't even need to reboot for Linux kernel updates anymore. (If you have enough time on your hands / the right distribution).
http://tech.slashdot.org/article.pl?sid=08/04/24/1334234


Anyhow, back to the topic at hand. Security updates are good?

When you have to work?

I dont get it :/

Neither do I :)

omg fredborg, that was hilarious!

Please though, not another M$ vs Linux debate......

"Don't use Windows? ;)"

Don't make money. ;)

Maybe they're banking on whats going on at CERN to save them having to release the critical patches.



IPete2.

Maybe they're banking on whats going on at CERN to save them having to release the critical patches.


and they would have gotten away with it too if not for those damn kids and a dog named scooby doo

Don't make money. ;)

I make money..
..I like money.

Neither do I :)
No, i mean i really dont get it (considering i only really use 'the other' for games that i cant run otherwise) :P

..i dun like money..I just need it..

yah true.

lol !

IPete2.