Profile

unixronin: Galen the technomage, from Babylon 5: Crusade (Default)
Unixronin

December 2012

S M T W T F S
      1
2345678
9101112131415
16171819202122
23242526272829
3031     

Most Popular Tags

Expand Cut Tags

No cut tags
Wednesday, May 19th, 2010 05:43 pm

Microsoft has launched a pilot program for governments and critical infrastructure providers to gain access to in-depth technical information about operating system patches before they are released on the second Tuesday of each month.

I find this bothers me.  What makes the government so special that they should get this information but I shouldn't be able to access it?

Make the information available, or not.  But making it available just to the government and "critical infractructure providers" Because They're Somehow Special is silly.  My infrastructure is crucial to me.  How come I don't rate access to the information?  Who gets to decide whose infrastructure is "crucial"?

Tags:
Thursday, May 20th, 2010 02:18 am (UTC)
There are several weapons, sensor and C3I systems in the US DoD which operate, I kid you not, on MSFT OS, going as far back as XP.
Yeah, I know. I've always found that kind of worrying, honestly.

As far as I know, they're not getting the patches early, just advance technical information. Really, the question I'm asking here is, if they're making that advance technical information available to the government and to whoever Microsoft thinks is a "crucial" service provider who needs it, does it really cost any more to just give everyone access to it?
Thursday, May 20th, 2010 05:55 am (UTC)
Does it cost more, in $? Probably not; it depends on the method chosen to distribute the information. However...

The easier it is for N. E. Miscellaneous-Sysadmin to get the advance info on the patch, the easier it is for I. M. A. Malicious-Bastard to get it and use it to circumvent it, especially in the case of patches that correct security exploits, which seem to be the vast majority of patches that MS releases - even for Windows Seven.

Given that Certain Not Openly Hostile Governments But We Know Better, Don't We have been implicated in cyberattacks on Governments Not Considered Hostile But Maybe We Still Know Better, well... I can't really say that it's the wrong thing to do.
Friday, May 21st, 2010 02:37 am (UTC)
I don't think it would - but is any advantage gained by limiting access to patches to US interests, at least for a period?

Friday, May 21st, 2010 03:54 am (UTC)
Honestly, I doubt it.