Personally, I'd rather they not tell me what the gaping security hole is other than to state that it's not there anymore. Code Red, Sasser, and Slammer should have taught us all that patch notes about security patches are dangerous things.
*They* know what it is. They just don't want to make it public twelve hours before a patch., because without a patch, that's 12 hours of every computer on the internet being vulnerable to executing arbitrary code.
They gave out details on *where* the hole was about 4 hours before the patch, and in the patch itself. In about a week, they'll release example code to exploit it on unpatched systems.
Even after the fact, there are people who have ignored all the wonderful automatic update information and are now suddenly at huge risk because the details of the vulnerability are now available. Thus my reference to the most prolific and damaging virii we've ever seen, all of which were written based on security patch notes after the patch was released.
Oh, fuck you Preachy McPreacherkins. I know I should have done that, but sometimes a boy forgets. Or falls over from all the narcotics and can't hit "save."
(no subject)
Date: 2008-10-23 11:25 pm (UTC)(no subject)
Date: 2008-10-23 11:52 pm (UTC)(no subject)
Date: 2008-10-24 11:52 am (UTC)Security through obscurity doesn't work well.
(no subject)
Date: 2008-10-24 11:59 am (UTC)They gave out details on *where* the hole was about 4 hours before the patch, and in the patch itself. In about a week, they'll release example code to exploit it on unpatched systems.
(no subject)
Date: 2008-10-24 03:19 pm (UTC)And I forgot blaster in the list. *facepalm*
(no subject)
Date: 2008-10-24 02:22 pm (UTC)(no subject)
Date: 2008-10-24 02:37 pm (UTC)And also: Save your work every time you stand up!
(no subject)
Date: 2008-10-24 02:40 pm (UTC)(no subject)
Date: 2008-10-24 02:52 pm (UTC)(no subject)
Date: 2008-10-24 03:10 pm (UTC)(no subject)
Date: 2008-10-24 03:17 pm (UTC)In XP, click Start -> Control Panel
(Or Start -> Settings -> Control Panel, if you're using the older-model start menu.)
Click Automatic Updates.
There's a radio button with four options: Automatic (recommended) is ticked.
The next option down is the one to download and notify you but not install anything without permission.
That's the one you want. Select it and click OK.
You're done.
(Vista is very similar, but I don't think it's exactly the same process)