Join the Community

22,238
Expert opinions
44,206
Total members
424
New members (last 30 days)
214
New opinions (last 30 days)
28,750
Total comments

To patch or not to patch, that is the question

Interesting article from Ryan Naraine about hackers and Microsoft's practice of silently fixing vulnerabilities it finds in code. Microsoft claim that by not drawing attention to new flaws this makes it harder for malware writers to exploit any holes that may be present.

However it seems the baddies are some steps ahead. Every time a patch is released it is studied in depth by being expanded and then compared against an unpatched binary. Hackers can then spot potential vulnerabilities, including ones that may not have been announced and launch suitable attacks.

In the meantime, IT managers may have read the public information and decided the patch isn't that vital - and before you know it - your machine is compromised by a flaw you didn't know was there. Eek. Run Windows update recently?

Read the full story here.

External

This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.

Join the Community

22,238
Expert opinions
44,206
Total members
424
New members (last 30 days)
214
New opinions (last 30 days)
28,750
Total comments

Now Hiring