
No, the first of April was yesterday...
Published: 2 April 2004 08:50 GMT
Security professionals say Microsoft's Trustworthy Computing initiative may finally be improving their lives because the latest patches and fixes being distributed by Redmond rarely break other applications.
Just over two years ago, Bill Gates fundamentally changed the way Microsoft approached software development by making security the highest priority. The company has spent millions of dollars to train staff in privacy concerns and secure programming, while building new tools and processes to help create reliable software. Although even Microsoft executives admit there is a long way to go, the investment seems to be paying off.
Security professionals attending a security event organised by non-profit organisation ISSA UK, which was held at Microsoft's headquarters in Reading on Wednesday, said that although Microsoft still has a lot of work to do before its patching system even meets basic requirements, the patches themselves have improved.
David Merry, senior network engineer at UK consultancy Polar Computer communications, said the change in Microsoft's policy is working well, so far: "We see that Microsoft's patches do tend to be more reliable and cause less interference with our client's machines than they did in the past. We are all seeing that security is a bigger issue - in Windows 95, accessibility was the key but there is more focus now," he said.
A senior consultant from a major financial institution, who asked to remain anonymous, said that over the past nine months Microsoft patches have not caused any problems with existing applications: "Historically, in my department the view is that you don't trust Microsoft patches, but over the past eight or nine months, we haven't had any integration problems at all. Yes, I'd say there is a definite improvement there," he said.
Graham Titterington, principal analyst at Ovum, said he had heard of "very few" reports where patches were breaking systems because Microsoft's testing procedures has improved. However, he warned companies to not get complacent with their own internal testing: "This is quite an achievement when you think that they are being applied to systems with varying levels of previous patching. However, good system management practice says that you shouldn't make any changes to a working system without testing the system in its new form and every large organisation has a system that is to some extent unique - so a risk remains," he said.
However, there are still problems. In February Microsoft released a patch for Internet Explorer outside of its monthly cycle to stop the company's browser from being used to fix a URL spoofing flaw. But the update also stopped certain URLs from being used to access password-protected internet resources, which was a relatively common practice.
Munir Kotadia writes for ZDNet UK
My client is a leading financial institution, based in the heart of Edinburgh who are currently recruiting a .NET Team Leader for their Scottish HQ. ...
Build machine administration • Maintenance of build scripts (dependency gathering, packaging, iso generation) • Producing bespoke builds ...
Should you be looking for a Business Analyst opportunity within the IT department of a leading financial institution please call to find out ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Data Protection Strategies: Deduplication for More Efficient Backups
Dell PowerVault DL2100 Powered by CommVault - Spec Sheet
True Convergence Demands a Communication Service Provider that Embraces a Customer-Centric...
Learn how Performance Metrics for Telcomm Expense Management Drive new ROIs and SLAs
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Mark Crichard Doing business with citizen developers: Beware the legal pitfalls Legal Eye: Make sure your business is protected from potential hazards
Tim Ferguson How CIOs can achieve post-recession success Q&A: McKinsey & Company on living in the 'new normal' business world