On The Insider: Dr. Conrad Murray Returns to Work
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 15 of 26:
Next »
« Previous
You "30 day grace" apologists should ...
... reread a couple items here:

"In some cases, administrators using patch management have to move so fast to install a fix that they aren't able to test it beforehand."

and:

"People often feel squeezed. Sometimes there are cases where they can't patch quickly enough. There may be an exploit out there before you can get your systems patched."

and this one is good, too:

"That's despite the fact that patches have frequently caused additional problems within corporate networks by turning off needed functions, or because the fixes themselves have had flaws."

This is what really frosts me with saying we should let rich software developers have 30 days to fix their vulnerable products, while the poor SysAdmins dance the dance of trepidation waiting for the Black Hats to hose their systems.

But the line I REALLY like in this article is THIS one:

"Rice said the best solution for resolving security vulnerabilities lies with software makers, which should fix code before it's put on sale."

I don't if can be accomplished 100%, but it CERTAINLY could be done a lot better than it is being done NOW. Like I said elsewhere on ZDNet: Let's give 'em a target of 30 HOURS, and let THEM do the Apprehension Boogie for a little bit and maybe they'll get a little bit more serious about securing things and fixing bugs.
Posted by: Judas I.   Posted on: 01/28/05 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

How about NOT putting all your eggs in one basket?  Laff | 01/28/05
Explain that to managers  crocd | 01/28/05
Easy  frgough@... | 01/28/05
Not necesarily  crocd | 01/28/05
Be careful of what you ask for.  Anton Philidor | 01/28/05
True  crocd | 01/28/05
Bad example to use...  htotten | 01/28/05
I still have NT4 running  crocd | 01/28/05
My condolences  seosamh_z | 01/28/05
Bad example to use...  Loverock Davidson | 01/28/05
AD groan!  crocd | 01/28/05
all of your problems should have never happend....  JoeMama_z | 01/28/05
we do and guess what  crocd | 01/28/05
legacy is something managment does not understand  xshakes | 01/28/05
You "30 day grace" apologists should ...  Judas I. | 01/28/05
Dancing "the dance of trepidation"  Anton Philidor | 01/28/05
Yeah, 'course, the people who can waltz ...  Judas I. | 01/28/05
Personaly I'd much rather head bang than waltz myself  Laff | 01/28/05
Metallica RULEZZZ !!!  Judas I. | 01/28/05
I'll bring my ibuprofen.  Anton Philidor | 01/28/05
Doc says that that stuff is bad for my kidneys, ...  Judas I. | 01/28/05
First they find stuff that works...  Anton Philidor | 01/28/05
Outstanding, Anton!  Judas I. | 01/28/05
Even W2K is way behind the curve.  davidb@... | 01/28/05
This article is about Windoze  Roger Ramjet | 01/31/05
firefox  Baptistt | 01/31/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

SmartPlanet

Click Here