Microsoft has, in the past, had a reputation for not taking security seriously. It had previously run the company on the idea that users want features and that is where the development costs went. Security was put only in where it couldn't be avoided.
Things changed and security became a feature. Microsoft woke up and have done an amazing job of establishing a patching schedule (Patch Tuesday) and supplying tools like WSUS and MBSA to make sure that patches are rolled out with minimal issues.
Thats great for larger organisations but while my PC at work is always up-to-date and secure, my PC at home has been lagging. I feel rather safe because it is not connected to the Internet 24/7 and is firewalled when it does dial up. Yes, dial up. With a modem. I don't process any funny documents on the box so it is really in a safe world of its own.
But being a security professional I feel that I should take some time to patch the box just to be sure.
So...lets get back to that modem thing. My modem does not run at 100% and the connection is pretty faulty. In South Africa local calls are charged for so it could get quite pricey to patch my machine not to mention the amount of time that my phone at home would be engaged.
That is for my one PC... if I had others the time to download and patch would be longer.
Enter the amazing AutoPatch software. All the Microsoft Patch Happiness you can get (and other stuff too!) all on one little platter! Basically it is all the Microsoft Patches on CD with a utility to work out what is needed and deploy. Download it at work, burn it, take it home and patch patch patch. This is one amazing little package and so necessary for smaller companies and home users.
Microsoft also benefit with the bandwidth savings and happier customers (isn't that what business is all about?)
But now Microsoft have instructed AutoPatcher to remove the Microsoft patches from their site. They are quite allowed to do this under copyright law because the patches are really Microsoft patches repackaged. It means that AutoPatcher really doesn't have much of a purpose though.
I can understand the fact that Microsoft doesn't want to face legal liability if AutoPatcher breaks a third party machine but I have no idea now how I can patch my home PC quickly and easily like I was able to before.
If I were Microsoft I would have bought out AutoPatcher for less than Bill Gates makes in a day and renamed it Microsoft CDPatcher. That move would have shown that Microsoft is serious about security and cares for customers rather than serious about security only to make money.
As it stands today I think Microsoft has made a mistake.
Showing posts with label legal. Show all posts
Showing posts with label legal. Show all posts
Thursday, August 30, 2007
Tuesday, August 7, 2007
The Wall Street Journal only got one (major) thing wrong.
The Wall Street Journal, published by Dow Jones & Company published an article that had a few of my peers quite upset.
Particularly upset was my brother-from-another-mother Andy the IT Guy. I call him that because although we are thousands of miles apart we have similar jobs and usually see eye to eye on matters. His post on the issue is here. In the post he links to other bloggers who rip the article to shreds.
I leave it up to the dedicated reader to follow all the links and get acquainted with the article and see why it has upset Andy and several others. Go do that now...I'll wait...
...
If you are reading this I hope you clicked the above links and read up on the issue...here comes my 2c.
The article got it exactly right except for 1 major issue and it is in the title!
It is not the IT department that is trying to stop you doing all of those things, it is the security department.
In fact, in most companies if you are quick (and you have to be quick) you'll see that IT guys are the guys who break the rules the most. Find the geek with the long black coat and chances are he is the guy running the phantom MP3 server that everyone knows about but doesn't exist.
Now that that is cleared up, you may ask: so what? Information Security department...IT department..who cares? But it does make a difference. IT has a mandate from Management to keep the servers humming and the information flowing - thats their job in a nutshell.
Information Security has a mandate from Management to make sure that the company does not leak information and does not break the law. The Information Security guys are also not the ones who make the rules, they may make suggestions but the guys who sign off the policies and rules are Management (read: your boss, his boss, etc etc up to the CEO). The rules you are breaking are the rules set down not by IT but by your boss.
Some of the rules (such as rules 1,2,3) are actually made to stop the top level guys from going to jail or at least to stop the company from being at the receiving end of some expensive legal problems. You can be sure that they would not take kindly at having these rules broken.
Obviously I am all for freedom of the press but just know who sets the rules and who signs off on them - its not IT.
Wednesday, August 1, 2007
Facebook privacy... I'm sure it was there a second ago..

So, some people I know were bored yesterday, looking for something to do while FaceBook got its act together. The site was down and productivity worldwide picked up.
But worse than that, according to an article in The Times, Facebook also let private information slip.
I love it when Information security makes the general news: it get people thinking about Information Security.
Basically, you could read your friend's private facebook messages and see their private content even though they had set it not to be shared.
Wow, you must think, Facebook's lawyers must be sweating... not quite.. in their privacy agreement is this little nugget:
"You post User Content (as defined in the Facebook Terms of Use) on the Site at your own risk"
Maybe you should reconsider what information is shared on a publicly accessible site.
Subscribe to:
Posts (Atom)