{"id":212,"date":"2008-02-06T19:33:18","date_gmt":"2008-02-06T23:33:18","guid":{"rendered":"http:\/\/alsplace.aldenbaker.com\/alsplace\/opsys\/os-vista\/212\/vista-sp1-will-contain-undocumented-fixes\/"},"modified":"2008-02-06T19:33:18","modified_gmt":"2008-02-06T23:33:18","slug":"vista-sp1-will-contain-undocumented-fixes","status":"publish","type":"post","link":"https:\/\/alsplace.info\/?p=212","title":{"rendered":"Vista SP1 will contain undocumented fixes"},"content":{"rendered":"\n<!-- ALL ADSENSE ADS DISABLED -->\n<h5>February 5th, 2008 <!-- by Adrian Kingsley-Hughes --><\/h5>\n<p> Posted by Adrian Kingsley-Hughes @ 9:33 am <!-- \/interact --> <\/p>\n<div id=\"post-1225\" class=\"post\"><!--sphereit start--> <\/p>\n<p class=\"entry\" align=\"justify\">Interesting email in today mailbag: &ldquo;<em>Will SP1 contain undisclosed or undocumented security fixes?<\/em>&rdquo;<\/p>\n<p class=\"entry\" align=\"justify\">For some people, counting the number of security flaws that one OS has compared to another is important because it offers a metric upon which to determine which OS is the most secure (personally, I feel that it&rsquo;s a bogus metric, but I&rsquo;ll let it slide for now). However, many claim that Microsoft stacks the deck in its favor by not disclosing a full list of vulnerabilities that have been patched by omitting to include those discovered and patched in-house.<\/p>\n<p class=\"entry\" align=\"justify\">Well, for those of you who do count security flaws then SP1 is likely to annoy you because it will contain an unknown number of fixes that aren&rsquo;t being disclosed. Microsoft makes this clear in the <a href=\"http:\/\/www.microsoft.com\/downloads\/details.aspx?FamilyID=d69c4e1b-c81a-41be-b1f5-66e615ba5912&amp;DisplayLang=en\" target=\"_blank\"><font color=\"#003399\">Notable changes in Windows Vista SP1<\/font><\/a> document available for download from their website. The relevant wording is under the Security Improvements (page 11):<\/p>\n<blockquote dir=\"ltr\" style=\"margin-right: 0px\">\n<p align=\"justify\">SP1 includes Secure Development Lifecycle <a href=\"http:\/\/www.neighborhoodrealtyonline.com\/\">best generic viagra<\/a>  process updates, where Microsoft identifies the root cause of each security bulletin and improves our internal tools to eliminate code patterns that could lead to future vulnerabilities.<\/p>\n<\/blockquote>\n<p class=\"entry\" align=\"justify\">Well folks, there you have it. We can&rsquo;t tell how many code patterns have been eliminated or whether these code patterns would ahve given rise to vulnerabilities, but Microsoft has taken steps to remove them anyway.<\/p>\n<p class=\"entry\" align=\"justify\">Now I have no doubt that this will make Vista SP1 safer and more secure than Vista RTM, and that&rsquo;s a good thing for users, but throwing in that kind of comment does throw some doubt over a report by Jeff Jones, Security Strategy Director in Microsoft&rsquo;s Trustworthy Computing group, in which he claims that Vista had fewer vulnerabilities in the first year than Windows XP, Ubuntu 6.06 LTS, Red Hat rhel4ws and Mac OS X 10.4. I&rsquo;ve asked Microsoft for comment on undisclosed vulnerabilities on several occasions and always had a &ldquo;no comment&rdquo; as a response.<\/p>\n<p class=\"entry\" align=\"justify\">But if you&rsquo;re still interested in playing the &ldquo;count the vulnerabilities&rdquo; game, here&rsquo;s something that you can do over the next 12 &#8211; 15 months &#8211; see how many vulnerabilities disclosed for Vista RTM don&rsquo;t apply to Vista SP1. The results should give you an idea of whether Microsoft&rsquo;s Secure Development Lifecycle process updates works or not.<\/p>\n<p class=\"entry\" align=\"justify\"><em>I open the floor to discussion &hellip; <\/em><\/p>\n<p> <!--sphereit end--><\/div>\n<!-- Social Bookmarks BEGIN -->\n<div class=\"social_bookmark\">\n<a title=\"Click me to see the sites.\" href=\"#\" onclick=\"$$('div.d212').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;\"><strong><em>Bookmark to:<\/em><\/strong><\/a>\n<br \/>\n<div class=\"d212\" style=\"overflow:hidden\">\n<br \/>\n<br \/>\n<a style=\"font-size:90%;text-align: right; \" title=\"Click me to hide the sites.\" href=\"#\" onclick=\"$$('div.d212').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;\">Hide Sites<\/a>\n<\/div>\n<\/div>\n<!-- Social Bookmarks END -->\n<script type=\"text\/javascript\">$$('div.d212').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); <\/script>","protected":false},"excerpt":{"rendered":"<p>February 5th, 2008 Posted by Adrian Kingsley-Hughes @ 9:33 am Interesting email in today mailbag: &ldquo;Will SP1 contain undisclosed or undocumented security fixes?&rdquo; For some people, counting the number of security flaws that one OS has compared to another is important because it offers a metric upon which to determine which OS is the most [&hellip;]<\/p>\n<!-- Social Bookmarks BEGIN -->\n<div class=\"social_bookmark\">\n<a title=\"Click me to see the sites.\" href=\"#\" onclick=\"$$('div.d212').each( function(e) { e.visualEffect('slide_down',{duration:2.5}) }); return false;\"><strong><em>Bookmark to:<\/em><\/strong><\/a>\n<br \/>\n<div class=\"d212\" style=\"overflow:hidden\">\n<br \/>\n<br \/>\n<a style=\"font-size:90%;text-align: right; \" title=\"Click me to hide the sites.\" href=\"#\" onclick=\"$$('div.d212').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); return false;\">Hide Sites<\/a>\n<\/div>\n<\/div>\n<!-- Social Bookmarks END -->\n<script type=\"text\/javascript\">$$('div.d212').each( function(e) { e.visualEffect('slide_up',{duration:0.5}) }); <\/script>","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[8],"tags":[],"_links":{"self":[{"href":"https:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/posts\/212"}],"collection":[{"href":"https:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/alsplace.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=212"}],"version-history":[{"count":0,"href":"https:\/\/alsplace.info\/index.php?rest_route=\/wp\/v2\/posts\/212\/revisions"}],"wp:attachment":[{"href":"https:\/\/alsplace.info\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/alsplace.info\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/alsplace.info\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}