On TV.com: NARUTO SHIPPUDEN latest episode
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 44 of 44:
« Previous
To MS: secure your patches
To Microsoft: This shows that creating patches after a flaw has been discovered is not enough, if the patch itself is a way to explain to hackers where precisely the flaw occured.
Using a Authenticode signature for patches and secured servers for its distribution is not enough: the patch itself must use a strong encryption and a code obfuscation system to block reverse engineering of this patch, and some way for the patch installer to block and disable completely any debugger from running.
The patch installer is not a simple installer, and before doing anything to the system, it must be sure that it will run safely without being "eyed" by hackers...
The difficulty is that the patch installer normally runs in the background, letting other applications running. However, there could be a security environment in Windows 2000/XP, where a private administrative user account is created, whose protections are all enabled againts other users....
Posted by: PhilippeV   Posted on: 07/30/04 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Classic!  Linux User 147560 | 07/28/04
catch-22 there in your logic  acaluya | 07/28/04
you are correct, but....  Monkey_MCSE | 07/28/04
Vunerability-Discovery-Patch-AV lifecycle  The King's Servant | 07/29/04
catch-23 in yours wink  michael-t | 07/28/04
A tad ridiculous  Jeff Spicoli | 07/28/04
You have a valid point but as a counter...  Linux User 147560 | 07/28/04
illogical  Jeff Spicoli | 07/28/04
I agree with Jeff. There, I've said it.  seosamh_z | 07/28/04
Why isp's won't do this:  CobraA1 | 07/28/04
What about trasparent proxing ?  ZXSpectrum | 07/31/04
2 Nits  tim__az | 07/28/04
You are correct  Linux User 147560 | 07/28/04
Too harsh  mjzalewski@... | 07/28/04
Speeding is allowed because of taxes  voska | 07/28/04
Funny, I know an ISP that does that  voska | 07/28/04
The Real Problems  JimSatterfieldW | 07/29/04
This places the blame  RedNek | 08/02/04
Yes!  bluescreen_z | 07/30/04
Forest for the trees  Bluesman Deluxe | 08/18/04
The ONLY way MicroSoft will EVER....  kd5auq | 07/28/04
You are probably right  uno@... | 07/29/04
Nice idea...But....  sma7769 | 07/29/04
And people just accept this?  Chad_z | 07/28/04
Apparently  seosamh_z | 07/28/04
sigh  M_c | 07/28/04
Why should users care?  OldeTimeGeek | 07/28/04
What is a PC  voska | 07/28/04
Outstanding!  wimbo_z | 07/28/04
HEY!!!!!  PA-ITGuy | 07/28/04
It's not that simple  mcunningham | 07/28/04
Why should users care?  DJnRF | 07/28/04
Yea?  wimbo_z | 07/28/04
Why They Accept It  TomGab | 07/28/04
True  uno@... | 07/29/04
Not true  The King's Servant | 07/29/04
XP SP2  jim-cacy@... | 07/28/04
Re: XP SP2  alterego_z | 07/28/04
How does business get done?  wimbo_z | 07/28/04
Everybody  michael-t | 07/28/04
Ok BallmerGates whatcha gonna do for the legacy ware  Squawkbox | 07/28/04
Linux - Because a 386 is a terrible thing to waste.  The King's Servant | 07/29/04
Windows OR Linux ???? that is the question  vbp1 | 07/29/04
To MS: secure your patches  PhilippeV | 07/30/04

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement