LWN.net Logo

Advertisement

Advanced thin client solution for Linux, based on Open Source. Mix Windows and Linux applications on the same desktop.

Advertise here

Patching is bad!

Patching is bad!

Posted Jan 30, 2003 11:22 UTC (Thu) by NAR (subscriber, #1313)
In reply to: Patching is bad! by libra
Parent article: A look at the MS-SQL worm

I have installed something that is bad a one time during the process.

I think, it is more a joke, than a real issue. First of all, a really really really paranoid administrator can first deconnect the machine from the network, install the original ("flawed") version, then install the patch, then reconnect the machine, so in this case, the flawed version is not exposed to malicious user at all. Secondly, (at least our) costumers do get upgrades, not patches, even though our products are proprietary. And least, but not least, who cares (except you:-), if you install a patch, or install an upgrade? The end result, the exposure time to attacks, etc. are the exactly same.

Bye,NAR


(Log in to post comments)

Patching is bad!

Posted Jan 30, 2003 15:48 UTC (Thu) by libra (guest, #2515) [Link]

Obviously you have never seen a system dll badly replaced during a patch because another process locks it, or it has been duplicated in the dllcache, or whatever other nasty trick.
I've seen such things happen already. But I must say that it tends to happen more often with Microsoft products than other products develloped for Windows (except those of Microsoft partners). Maybe because they know Windows too well to use common sense when making a development.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds