John Gallant
by John Gallant

Latest scientific breakthrough from Xerox

Opinion
Dec 9, 20045 mins

Once again, we come to the holiday season, a deeply religious time that each of us observes, in his own way, by going to the mall of his choice.Dave Barry

Dear Vorticians,

Sometimes, no matter what my grand plan is for the week, critical news developments must take precedence. This is one of those weeks. I had a topic in mind, but it will have to wait for a moment until I tell you the news – and it’s good news for a change.

Are you ready? Scientists at Xerox have developed a way to copy pages from a bound book – without damaging the spine! Yes, it’s true. You’ll never have to crush down that encyclopedia (geography to hypothalamus) just to copy a photo of a hippopotamus for your science report. A scientist from Xerox’s Webster, N.Y., research facility broke the news to the scientific world at the 5th International Conference on Imaging Science and Hard Copy in Xi’an, China. According to Xerox, the cure for this literary scoliosis problem involves – and I quote directly from the press release – “a mathematical formula than can be incorporated into the software of common scanners.”

That’s a little more science talk than I can easily absorb, so I’ll go back to the topic I was going to cover this week. Unfortunately, it’ll sound so mundane compared to this book-copying stuff. It’s, well, it’s patching.

Yes, patching. The annoying job of keeping software shored up against security threats and to repair other flaws. It does sound mundane, doesn’t it?

But the sad reality is that patching costs businesses millions, maybe billions. That includes not only the time and resources required to actually do all the patching, as well as patching the patches, but also losses from attacks and problems caused by not patching. It’s dizzying, isn’t it?

On an event tour, I spent last week talking to IT executives about key issues for 2005 and patching was right up there at the head of the class. Yes, they are enthused about virtualization, mobility and services-oriented architectures. But there’s this little problem called patching….

Not only are they increasingly strapped by the amount of work involved in keeping up with patches from major vendors like Microsoft, they’re increasingly angry about this upward-leaping monkey.

What does that mean? In one management course I took years ago, I was warned against upward-leaping monkeys – meaning problems that employees shift from their backs to yours. The imagery is pretty good. Someone you manage walks in with a monkey (problem) on his back, you wade in to help him and – voila – next thing you know, the monkey’s on your back and your employee walks out smiling and monkey free.

That’s how customers feel about their software suppliers. Software makers build buggy, non-secure software and then they shift the ongoing repair of that lousy software over to customers. As one New Yorker said about King Kong: That’s a big

monkey!

Change the product and you quickly recognize how absurd this process is.

Let’s say you buy a brand new Mercedes coupe. A week or so later, you get a package from Mercedes that says: Hey, turns out the fuel line has a bunch of problems and it could cause your new coupe to burst into flames. We regret that, but we’ve included a new fuel line and some instructions for installing it. You better fix this thing before you go up in smoke!

Patching’s always been a sore point between customers and developers. But the problem is getting much worse. It’s increasingly difficult for enterprise shops to keep up with all the patches and to do the due diligence to ensure that the patch doesn’t create more problems than it was meant to fix. You’ve all encountered that on your own desktops. (Interestingly, it’s reported that even Microsoft can’t keep its own systems fully patched and, as a result, has suffered downtime due to Internet attacks.)

Want a real-world example of the extent of this patching problem? During my tour last week, I met with the top security officer at a major service provider. He told me the company spends $1 million a month on patching. I shook my head. No, that can’t be. One million bucks?

But he stuck to his guns. This service provider calculated staff time for studying the patches, testing them and rolling them out and concluded that it costs the company at least $1 million a month. Extrapolate that across just the rest of the telecom industry, which is struggling for profits, and you quickly see what a mess this is for the economy as a whole.

So, here’s my question to you, my Vortician friends, how do we change this? How can we shift the monkey back to the software makers? Software makers aren’t generally liable for the impact of flawed products – perhaps they ought to be. Or perhaps customers ought to rise up in revolt. Well, maybe that’s too much to hope for. What’s your answer?

Share your thoughts to mailto:jgallant@vortex.net.

I’m off to copy “Tropic of Cancer” for ‘a friend’. Finally!