On TechRepublic: Windows 7 keyboard shortcut cheat sheet
BNET Business Network:
BNET
TechRepublic
ZDNet

February 5th, 2008

Vista SP1 will contain undocumented fixes

Posted by Adrian Kingsley-Hughes @ 9:33 am

Categories: Security, Vista

Tags: Vulnerability, Microsoft Windows Vista, Microsoft Corp., Microsoft Windows Vista SP1, Microsoft Windows Vista (Longhorn), Security, Operating Systems, Microsoft Windows, Software, Adrian Kingsley-Hughes

In Focus » See more posts on: Vista

Interesting email in today mailbag: “Will SP1 contain undisclosed or undocumented security fixes?

For some people, counting the number of security flaws that one OS has compared to another is important because it offers a metric upon which to determine which OS is the most secure (personally, I feel that it’s a bogus metric, but I’ll let it slide for now). However, many claim that Microsoft stacks the deck in its favor by not disclosing a full list of vulnerabilities that have been patched by omitting to include those discovered and patched in-house.

Well, for those of you who do count security flaws then SP1 is likely to annoy you because it will contain an unknown number of fixes that aren’t being disclosed. Microsoft makes this clear in the Notable changes in Windows Vista SP1 document available for download from their website. The relevant wording is under the Security Improvements (page 11):

SP1 includes Secure Development Lifecycle process updates, where Microsoft identifies the root cause of each security bulletin and improves our internal tools to eliminate code patterns that could lead to future vulnerabilities.

Well folks, there you have it. We can’t tell how many code patterns have been eliminated or whether these code patterns would ahve given rise to vulnerabilities, but Microsoft has taken steps to remove them anyway.

Now I have no doubt that this will make Vista SP1 safer and more secure than Vista RTM, and that’s a good thing for users, but throwing in that kind of comment does throw some doubt over a report by Jeff Jones, Security Strategy Director in Microsoft’s Trustworthy Computing group, in which he claims that Vista had fewer vulnerabilities in the first year than Windows XP, Ubuntu 6.06 LTS, Red Hat rhel4ws and Mac OS X 10.4. I’ve asked Microsoft for comment on undisclosed vulnerabilities on several occasions and always had a “no comment” as a response.

But if you’re still interested in playing the “count the vulnerabilities” game, here’s something that you can do over the next 12 - 15 months - see how many vulnerabilities disclosed for Vista RTM don’t apply to Vista SP1. The results should give you an idea of whether Microsoft’s Secure Development Lifecycle process updates works or not.

I open the floor to discussion …

Adrian Kingsley-HughesAdrian is a technology journalist and author who has devoted over a decade to helping users get the most from technology. He also runs a popular blog called The PC Doctor. See his full profile and disclosure of his industry affiliations

Want to get in touch? Got a tip? Feel free to drop me a note! I ALWAYS respect anonymity. I'm also on Twitter (@the_pc_doc)

Right to Reply: Should any industry representatives wish to comment on any posts on Hardware 2.0, I will be happy to publish their reply verbatim on this blog.

Subscribe to Hardware 2.0 via Email alerts or RSS.

  • Talkback
  • Most Recent of 119 Talkback(s)
don't know about pintos...
I don't really remember Pintos doing this, but I do remember the big deal made about trucks with exploding gas tanks (when the tanks were located right behind the seat, yet).... (Read the rest)
Posted by: Drakaran Posted on: 02/11/08 You are currently: a Guest | | Terms of Use
The WOW really starts now.  TripleII | 02/05/08
3.6  Michael Kelly | 02/05/08
Good catch.  TripleII | 02/05/08
Way to run  Blogsworth | 02/05/08
It's not so much  Michael Kelly | 02/05/08
Is that you Mike Cox?  D. T. Schmitz | 02/05/08
Good Mike Cox imitation: 9:5  John L. Ries | 02/06/08
But does it get better gas mileage?  kd5auq | 02/05/08
Re: But does it get better gas mileage?  tmkent@... | 02/06/08
This GAS TANK IS FULL  lrbear@... | 02/06/08
Urban Legend  mikesnewname@... | 02/06/08
BOOM!!!  i2fun@... | 02/06/08
Depends On......  i2fun@... | 02/06/08
A bit off topic, but:  seannj427 | 02/07/08
you must be young  cwhull | 02/06/08
As I recall  seannj427 | 02/07/08
don't know about pintos...  Drakaran | 02/11/08
Just an aside  mdsock@... | 02/07/08
All new software releases have undocumented fixes  georgeou | 02/05/08
Correction George  nucrash | 02/05/08
Not really if you think about it  georgeou | 02/05/08
Pre-release bugs undocumented?  Fred Fredrickson | 02/05/08
errr.. this is MS you are refering to  deaf_e_kate | 02/06/08
I guess this should read "publicly" documented fixes...  JohnSmith2000 | 02/06/08
Uh, don't you mean "Known Bugs" ???  jrbeaman | 02/06/08
Confusion in nomenclature  grail@... | 02/06/08
Agreed and then some  nucrash | 02/07/08
rofl  pcguy777 | 02/06/08
Security Racket  Harry Bardal | 02/05/08
Don't agree on the security expert bit  voska1 | 02/05/08
Counting Vulnerabilities  DannyO_0x98 | 02/05/08
Not true for open source!  CobraA1 | 02/05/08
You're not going to document the bug fixes pre-release  georgeou | 02/05/08
But Vista has been out for some time  voska1 | 02/05/08
Lest we forget.....  ajv123 | 02/05/08
Those counts can't be used when spanning service packs  georgeou | 02/06/08
I was un aware that Vista was a Pre-Release  goxk@... | 02/05/08
Vista SP1 is a brand new kernel  georgeou | 02/06/08
that's a nice one  tombalablomba | 02/06/08
You will one day kill me George. Your plan  goxk@... | 02/06/08
Define "release"  CobraA1 | 02/05/08
Wrong  tombalablomba | 02/05/08
What about bug fixes before they're checked in?  georgeou | 02/06/08
that's a non issue  tombalablomba | 02/06/08
No understanding......  thungurknifur | 02/06/08
What happens to fixes before the code is checked in?  georgeou | 02/06/08
BUZZZ! Wrong!  Mitch 74 | 02/06/08
Nonsense, George.  handydan918 | 02/06/08
Thats what makes it open source  zachschi@... | 02/06/08
In which case...  John L. Ries | 02/06/08
Responding to the correct article?  Larry the Security Guy | 02/06/08
Maybe you should research other software  zarchasmpgmr | 02/06/08
Broadcast Your Vulnerabilities  ceh4702 | 02/05/08
No need to broadcast  Spîkeý | 02/05/08
Primary purposes...  techboy_z | 02/05/08
of course!  CobraA1 | 02/05/08
Ah MS, what they don;t know can;t hurt us.  LittleGuy | 02/05/08
Baloney  ThinkFr33ly | 02/05/08
Of course it counts!!!  techboy_z | 02/05/08
Service packs are applied by real computer users  Tiggster | 02/05/08
Not entirely true  voska1 | 02/05/08
Test it during beta  Tiggster | 02/05/08
Well actually in the past you had to wait  voska1 | 02/06/08
Actually  dellpj@... | 02/06/08
Not so...  techboy_z | 02/06/08
Balony? Yep, sure is  Fred Fredrickson | 02/05/08
Incorrect  ThinkFr33ly | 02/05/08
Just what the world needs!  Ole Man | 02/05/08
Your hat needs thicker tin foil  No_Ax_to_Grind | 02/05/08
Your trust is thicker than your imagination  Ole Man | 02/06/08
Paranoia running wild  Tiggster | 02/05/08
Kinda....  deuce63 | 02/06/08
It's simply a matter of principle.  Ole Man | 02/06/08
How do you document a closed source system?  D. T. Schmitz | 02/05/08
Exactly, this is one of the major problems of closed source software...  xunil skcor | 02/06/08
Call your Microsoft Rep  Ole Man | 02/06/08
RE: Call your Microsoft Rep  seannj427 | 02/07/08
Socking - Why fix problems before they manifest?  Carl G | 02/05/08
MS should disclose all vulnerabilties...  killerbunny | 02/05/08
Major Downer  D. T. Schmitz | 02/05/08
Hardly a downer  mdemuth | 02/05/08
Forced upgrades?  Steve4Fluff | 02/06/08
Uh, you are wrong.  jrbeaman | 02/06/08
Good Code Bad Code  D. T. Schmitz | 02/05/08
Wake me up when vista saves the planet.  kraterz | 02/05/08
I don't care  Tiggster | 02/05/08
Commonly know as apathy  Ole Man | 02/06/08
2K/XP rebuilds my moneymaker now  zach.winchester | 02/07/08
Secure Development Lifecycle process updates doesn't mean they fixed flaws!  qmlscycrajg | 02/06/08
Behind closed doors.....  chaz15 | 02/06/08
RE: Vista SP1 will contain undocumented fixes  Rand777 | 02/06/08
Another reason to go back to XP  SaltySkipper | 02/06/08
More nonsense from MS  green alien | 02/06/08
You can check the updates... Or at least pretty sure  Drakaran | 02/06/08
Message has been deleted.  rford75@... | 02/06/08
Find and replace  jttt@... | 02/06/08
RE: Vista SP1 will contain undocumented fixes  mypl8s4u2 | 02/06/08
Danger: Now we don't know if Vista is safer!  TristanGrimaux | 02/06/08
RE: Vista SP1 will contain undocumented fixes  MajikUF | 02/06/08
WOW this makes NO differance to me and my business...  carlsf@... | 02/06/08
have you ever heard of training  pcguy777 | 02/06/08
have you ever heard of training  Ole Man | 02/06/08
Issues with Microsoft  tbuccelli | 02/06/08
Some virus look like registry update files  BALTHOR | 02/06/08
Adobe updated Reader with stealth patch, but few arcreaming about that  killerbunny | 02/06/08
Vista is NT ?  Mahegan | 02/06/08
You Don't Get It  ThinkFr33ly | 02/06/08
Re: You Don't Get it  seannj427 | 02/07/08
Then There is No Way To Quantify Security  ThinkFr33ly | 02/06/08
RE: Vista SP1 will contain undocumented fixes  roseman | 02/06/08
ZDNET  derekgore | 02/06/08
RE: Vista SP1 will contain undocumented fixes  JelMin | 02/07/08
This is the same as XP SP2, IE7  cquirke | 02/07/08
ComputerWorld reported sp1 breaks more drivers  Randalllind | 02/07/08
RE: Vista SP1 will contain undocumented fixes  royha1@... | 02/07/08
RE: Vista SP1 will contain undocumented fixes  atari8bit@... | 02/07/08
Here at Headquarters...  Kromaethius | 02/08/08
Here at Headquarters...  Ole Man | 02/08/08
RE: Vista SP1 will contain undocumented fixes  leeepson7800 | 02/09/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here