"Joe Morris" <> wrote in message
news:...
> "Dave "Crash" Dummy" <> wrote:
>> Andy Burns wrote:
>>> Percival P. Cassidy wrote:
>
>>>> Yesterday Windows Update (Win7Pro) informed me that two important
>>>> updates were available. I selected them, they downloaded and
>>>> started to install, then Windows reported that they were not
>>>> needed/unnecessary/not necessary (whatever the actual wording was).
>>>> I didn't make a note of the KB numbers. What on earth was going on?
>
>>> Yesterday the only patches I got were KB2570791 for some timezone
>>> changes and the regular KB2310138 update for MSE.
>
>> Me, too. I was surprised to get the KB2570791 patch on other than the
>> usual Patch Tuesday, though.
>
> Patch Tuesday updates are restricted to security fixes; 2570791 is the
> latest in the seemingly unending stream of timezone updates; this patch
> updates the time zone info for Turkey, Egypt, Pacific SA, Morocco, Fiji,
> and Samoa Standard Time.
>
> I'm *strongly* in favor of keeping non-security updates out of the Patch
> Tuesday release; security patches need to be installed very soon after
> they are released; the Bad Guys will be reverse-engineering the fixes to
> identify the vulnerability they fix, and some of those Bad Guys have shown
> themselves to be able to quickly find those vulneabilities and develop an
> attack using them. Having non-security updates come out at the same time
> muddles the water, even if their documentation says "not a security
> update."
>
> Joe Morris
>
If you're still getting your security fixes, why would it matter if there is
another patch included? Having the other patch included doesn't give the
"Bad Guys" any more of a head start than they already have. Are you
thinking that the extra 2 minutes for the non-security related patch is the
open window for your computer to join the botnet?
|