Interestingly disturbing

Opinion
Oct 25, 20044 mins

I just read an interesting column in The New York Times by David Pogue about Microsoft’s patches. I say “interesting” when I might more accurately write “disturbing.”

Pogue expressed surprise over learning from a Microsoft product manager that hackers mostly exploit security problems after the patch is issued. The reason they do so is obvious: The time between the release of a patch and its installation on all vulnerable computers is at best several weeks and usually several months. This inevitable delay gives the miscreants plenty of time to examine the released patch, develop their attack plan and then go out hunting.

As Pogue points out, it was only recently that significant numbers of users switched on the Windows automatic update facility, which should significantly reduce the length of time between patch release and the population getting updated. The thing that made a significant number of end users enable automatic update was Windows XP Service Pack 2.

But here’s the rub: Given that SP2 is a 266M-byte download, it is a big task for dial-up users to download it, spyware can make the installation of the patch fail, and there are plenty of other gotchas that can make installing SP2 less than a certainty. It is safe to assume the universal application of SP2 is a considerable way off.

Worse still, Microsoft recognizes that IT shops are unwilling to just turn loose such a major patch without testing. To this end, Microsoft has decreed that, as of April 12, 2005, even if SP2 hasn’t been deployed, “Windows XP SP2 will automatically be delivered to all systems configured to receive updates automatically” (read it here). I’m betting that a significant number of IT shops will do their utmost to avoid the SP2 update anyway.

So the bottom line: Between now and April there will be a huge number of unprotected corporate systems. There also will be a staggering number of consumer systems and tens of thousands of medical systems that won’t be patched then or possibly ever

Now this is a bad enough situation, but Pogue, addressing the readership of The New York Times, suggests: “should Microsoft really be fixing these obscure holes at all? Think about it: the virus writers would never even have known about the hole if Microsoft hadn’t patched it!”

This is the philosophy of security through obscurity – in other words, if you find a vulnerability don’t tell anyone but the vendor and let them decide whether to take action. This policy was being pushed by the Microsoft spinmeisters some months ago, and it was, at least in the IT community, roundly disparaged as not only self-serving but ultimately the riskiest path of all.

The reason that security through obscurity is a bad idea is obvious. If a vendor is under no pressure to produce a fix for a given problem then it can drag its feet for as long as it pleases. Just consider that Microsoft dragged its feet for six months before releasing the patch that the Sasser worm exploited.

But in the time that the problem is assumed to be a secret what happens if it is independently discovered by the guys wearing black hats? They will potentially have months to exploit the problem.

This was what I found disturbing about Pogue’s column: He pitched a bad idea to The New York Times readership who, in general, probably accept the concept because it was printed in The New York Times.

There is more than enough profound ignorance about computers in general without columnists in prominent newspapers making bad ideas sound good, especially in a field that is as critical to business continuity as security. The last thing we need is a bigger pool of potentially compromised PCs.

Tell me if you’re disturbed at backspin@gibbs.com.