BZU PAGES: Find Presentations, Reports, Student's Assignments and Daily Discussion; Bahauddin Zakariya University Multan Right Header

Register FAQ Community Calendar New Posts Navbar Right Corner
HOME BZU Mail Box Online Games Radio and TV Cricket All Albums
Go Back   BZU PAGES: Find Presentations, Reports, Student's Assignments and Daily Discussion; Bahauddin Zakariya University Multan > Welcome to all the Students > Daily News And halat-e-hazra

Daily News And halat-e-hazra National & Intentional Daily News


Reply
 
Thread Tools Search this Thread Rate Thread Display Modes
  #1  
Old 26-09-2008, 10:45 PM
BSIT07-01's Avatar
Addicted to Computer


 
Join Date: Sep 2007
Location: ------------
Age: 34
Posts: 1,309
Contact Number: ---------------
Program / Discipline: BSIT
Class Roll Number: 07-01
BSIT07-01 has a brilliant futureBSIT07-01 has a brilliant futureBSIT07-01 has a brilliant futureBSIT07-01 has a brilliant futureBSIT07-01 has a brilliant futureBSIT07-01 has a brilliant futureBSIT07-01 has a brilliant futureBSIT07-01 has a brilliant futureBSIT07-01 has a brilliant futureBSIT07-01 has a brilliant futureBSIT07-01 has a brilliant future
Default Apple slammed for patching cycle

Apple slammed for patching cycle


Apple's patching process shows that the company isn't serious about moving Macs into the enterprise, security researchers have said.


One dissenting expert, however, said it was unfair to compare Apple's patching procedures with, say, Microsoft.
"You have to evaluate the patching performance of the company if you're looking at Macs," said Andrew Storms, director of security operations at vendor nCircle Network Security Inc. "And the last two weeks hasn't been a gold star for Apple."
Unlike its operating system rival Microsoft, which schedules security updates for the second Tuesday of each month and typically limits other updates, Apple releases updates, security fixes included, on any day of the month. Apple, for example, has rolled out updates on five of the 10 business days since September 9.
"You get an update from Apple and it's always a surprise," Storms said. "The first thing you do is sit down with your team, look at the update, set priorities and assign resources. And then the next day, another update arrives, and you have to do it all over again.
"If you can't properly plan for this, you're in a constant firefighting mode," Storms continued. "Now it's affecting the management of the IT team."
And that has to spook businesses, whose administrators are used to pinning Microsoft's updates to specific dates on the calendar. "Even if you realise that the Mac may be an effective tool, it's going to have a greater impact on the infrastructure because of the way Apple patches," Storms said. "The question is, can your infrastructure withstand it?"
Charlie Miller, a researcher at Baltimore-based Independent Security Evaluators who is well-known for his Mac and iPhone vulnerability work, agreed that Apple's patching process makes it tough on corporate IT staffers. "Administrators rely on knowing what will happen," Miller said. "If they know, they can plan their week around it."
Posting patches without a schedule, Miller said, is an invitation for businesses to simply not patch. "For someone like me, it's no big deal, but for professionals, it's a whole different story," he said. "The last they want is a patch that just shows up. They can't patch without testing. So this is one more reason for them to go, 'I just won't patch.' "
Another researcher, Swa Frantzen of the SANS Institute's Internet Storm Center, however, disagreed with Storms and Miller. Frantzen argued that it was an apples-and-oranges comparison to pit Apple's patching procedure against Microsoft's.
"If Apple should be compared with other vendors, take the other Unix vendors," Frantzen urged. "Sun, HP, FreeBSD, OpenBSD, the different Linux distributions - very few of them group together patches in a monthly cycle."




In fact, argued Frantzen, Apple's process of patching when the patch is ready reduces the window of vulnerability for users. "[Microsoft's] monthly cycle adds an average of half a month of unnecessary vulnerability while the patch is fully finished and not being offered to customers," said Frantzen said.
"I think Apple is actually in a tough spot," offered Miller, who blamed Apple's patching problem on its having to maintain aging code and the company's late start in following Microsoft's lead in applying secure code development practices. "They are so far behind on that," Miller said. "They're doing things, but even on some of the basic stuff, they're lagging behind Microsoft."
If Miller had his way, Apple would invest in a Microsoft-like secure code process - which its rival calls its ‘Security Development Lifecycle' - to make its operating system more competitive in the enterprise. "I think they should do that, but I doubt they will be forced to do that," Miller said.
Reply With Quote
Reply

Tags
apple, cycle, patching, slammed


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Integration of life cycle usman_latif_ch BZU Graphics and Wallpapers 0 23-01-2012 12:14 PM
Arabic BYE CYCLE.....! zeesmile Funniest Pictures 0 18-12-2011 07:40 PM
No dogs no cycle no swimming thecool Funniest Pictures 0 07-11-2010 11:07 AM
Cool Cycle Stunts thecool Howto & Style 0 30-10-2010 05:49 AM
Why the Apple/Command Key Finally Lost Its Apple .BZU. Computer & Programming 0 17-11-2008 03:36 AM

Best view in Firefox
Almuslimeen.info | BZU Multan | Dedicated server hosting
Note: All trademarks and copyrights held by respective owners. We will take action against any copyright violation if it is proved to us.

All times are GMT +5. The time now is 06:57 PM.
Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.