3 ms·
For something installed on so many devices, 90 days seems like an incredibly tight timeframe to change anything.
by fintler 8y ago
For something installed on so many devices, 90 days seems like an incredibly tight timeframe to change anything.
- pg_bot 8y ago3 months is more than enough time if you care about your customer's privacy and security.
- s2g 8y agoYOu are talking about a very large, complex, mission critical, and incredibly widely used piece of software. If they mess up a patch it's a big deal. If they break systems, introduce further bugs, etc... 90 days to understand the problem, fix the bug, verify the fix, plan the release, get it out to customers. There is a lot of work involved in such a thing.
- pg_bot 8y agoCorrect there is a lot of work to be done. It is not 90 days worth of work. If you think that is not enough time, you need to raise your standards.
- lawnchair_larry 8y agoPeople who think 90 days is not enough time don’t have insight into how long this actually takes and why it took so long. I don’t know where this meme came from but I know for certain that is not the reason that companies like Microsoft miss their deadlines.
- nurettin 8y agoDo you have any experience with complex systems where a security patch could possibly take more than three months to implement?
- oaiey 8y agoHe might have or not but I have. Not as complex but similar mission critical and distributed. 90 days is nothing as outlined. Once you go life or death situations, regulatory environment applies, backward compatability matters, ... Everything takes endless. It is not code, commit, test and deploy. Intake, Risk Analysis, project planning, approvals, alignments, etc. So many more processes. We should not fool ourselves that other platforms are better in that once you go for serious SLAs. Linux Kernel or user land patch might be fast, but RedHat delivery will take longer. Welcome to Enterprise development.
- Dylan16807 8y agoVery very little of enterprise is life or death, and windows is not suitable for life or death. When enterprise just falls on its face, I don't have much sympathy. "So many more processes" sounds like taking a handful of steps, splitting them up, and making each one require multiple days of memos back and forth. Can you provide any justification for this? Am I misreading?
- nurettin 8y ago>>Welcome to Enterprise development. That is assuming whoever you are replying to is foreign to enterprises.
- oaiey 8y agoIn that case - if you are not - congrats! Seems like you ended up in well organized places :)
- davidhakendel 8y agoI have that experience. Security patches take a long time. You need to ensure that mission critical operations are not impacted, that the private builds which had been supplied to customers are not impacted, that documentation gets updated, that laws and regulations are followed across the world and in specific regulated verticals, etc. Then customers need time to review the patches and follow through on their schedule of updating their devices.
- ge0rg 8y agoDon't forget that these 90 days are also 90 more days where this vulnerability can be exploited by attackers. Microsoft has set up a patch delivery infrastructure that's pretty effective and comparably fast by industry standards, if not deactivated by the people who got offended by the forced Windows 10 upgrade and feature creep.
- gmueckl 8y agoWell, Windows Update is forcing me to deactivate it in one machine bacause it continues to make it unusable. I have come to terms with most quirks of the forced updates, but in this particular situation Windows is nasty und uncooperative. Add to it Microsofts well established unwillingness to provide any useful diagnostic information and suddenly the only way to use the machine is to not update it.
- Laremere 8y agoPut another way: For something installed on so many devices, 90 days seems like an incredibly long time to leave so many devices vulnerable. Security fixes aren't a once and done thing. New exploits will be discovered that must be fixed. Missing deadlines for less severe exploits encourages getting better at sending security fixes out. Then, when more severe exploits are discovered, they can be patched in a reasonable amount of time. If extensions are always given, then deadlines become meaningless and "90 days" becomes "eh, 6 months given we can push for extensions."