Reflections on ‘first Tuesday’

Opinion
Oct 18, 20042 mins

* Pros and cons of Microsoft’s ‘first Tuesday’ approach to patching

There was a time when “first Tuesday” usually referred to Election Day in November. Now it’s the eagerly awaited day, each month, when Microsoft releases a flurry of patches for its operating systems, applications and services.

The first Tuesday in October was both typical and atypical – typical in that the now usual release of patches occurred, and atypical in that Microsoft set a new record for activity in a single month. Altogether, 10 security bulletins were issued, seven of them called “critical.” The related patches fixed 22 identified security vulnerabilities. 22!

It’s been almost three years since Bill Gates issued his now infamous “Trustworthy Computing” memo to all Microsoft employees in January 2002. I applauded the move at that time, and I still applaud any move on Microsoft’s part to make computing more reliable and secure.

The first-Tuesday patch bundles have only been issued since February of this year. While I questioned the logic of holding off a patch that could be released until a particular day (which could mean waiting four weeks for something you really need), that hasn’t happened yet. By focusing the attention of the press and users on a “First Tuesday” release, Microsoft has increased the amount of attention that the security bulletins receive – even in those months where there are none released. I’ve got to applaud that.

The scary thing I’ve just realized, though, is that this sort of “patchwork patching” is never going to go away. For the rest of our lives, it seems, we’ll be downloading security patches the first week of every month. That’s a really depressing thought. No matter how many security patches we apply, it seems, there are always new vulnerabilities being uncovered. 

Most security discussions focus on Microsoft, its practices and the culture in Redmond where “user friendliness” was always the paramount priority as the source of the security problems. The Trustworthy Computing Initiative was supposed to overcome these perceived shortcomings. But is the focus in the right place?

Were these new vulnerabilities always there, and we’re just noticing? Is the very fact of patching one vulnerability uncovering another one? Or is there a bigger, more endemic problem which has to do with programmers, programming methods and programming environments? We’ll look at that in the next issue. Stay tuned.