Experts: Don't rely solely on patches

By Victoria Ho, ZDNet Asia
Friday, July 10, 2009 05:57 PM

Users should take extra precautions against security holes and not rely only on critical patches to ensure safety, say security experts.

According to reports, Microsoft was aware of an ActiveX vulnerability affecting its Internet Explorer browser for over a year, but left it open. It issued a security advisory earlier this week, saying it was investigating the hole.

It has also issued a temporary workaround, till the issue is resolved.

Internet Explorer is used by almost 70 percent of the world, as of February this year.

The software giant's failure to issue a patch has led to a flurry of reports online, with some researchers comparing the potential spread of the vulnerability to the Conficker virus.

Paul Ducklin, head of technology for Asia-Pacific at Sophos, told ZDNet Asia the dangers of a software maker taking too long to fix a hole is that it leaves the opportunity open for malicious attacks.

While Microsoft may have not issued a patch sooner because it was wary of creating new problems in its attempt to fix the old, the onslaught of malware while the hole stays open "means you have to rush out a fix anyway", Ducklin said.

"A year sounds like a long time to me, though. Perhaps it could have been a bit swifter in this case," he said.

Ducklin added that users employing antivirus software are protected at a secondary level, with the software intended to catch and block malicious files should they encounter them.

Chia Wing Fei, security response senior manager at F-Secure Security Labs, also acknowledged the possibility of Microsoft's need to ensure stability of the patch.

According to Chia, another way to avoid the Internet Explorer hole is by using alternative browsers, such as Firefox, Opera or Chrome.

Microsoft was unable to respond by press time.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

3 lessons a CIO can learn from Windows 7

Tech Management

Microsoft's missteps with Vista, and attempts at redemption with Windows 7, offers firms valuable lessons in IT, be it in rolling out a new corporate application or delivering millions of copies of a new OS.


Read more »



Ultimate 2012 recovery site: the moon

Blog thumbnail

Have you seen the disaster movie "2012"? A friend from Control Risks and I did, and we reluctantly concluded we wouldn't be able to write off the cost of our..... by Nathaniel Forbes

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web