Ads by TechWords

See your link here
Receive the latest technology news and information.
Macintosh
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Apple's patch process a mess, say researchers

Constant updating shows Mac OS X isn't ready for the enterprise

September 22, 2008 12:00 PM ET

Active Comments
jj says: For one thing, do you not know that you can set Macs to check for updates daily, weekly (like on...
Lawrence says: IT "professionals", fearing for their jobs if Apple makes inroads in the "enterprise", enter into FUD mode. News at 11:00!...


Computerworld - Apple Inc.'s patching process proves that the company isn't serious about moving Macs into the enterprise, security researchers said today.

One dissenting expert, however, said it was unfair to compare Apple's patching procedures with, say, Microsoft Corp.'s.

"You have to evaluate the patching performance of the company if you're looking at Macs," said Andrew Storms, director of security operations at vendor nCircle Network Security Inc. "And the last two weeks hasn't been a gold star for Apple."

Unlike its operating system rival Microsoft, which schedules security updates for the second Tuesday of each month and typically limits other updates to twice monthly, Apple releases updates, security fixes included, on any day of the month. Apple, for example, has rolled out updates on five of the 10 business days since Sept. 9.

"You get an update from Apple and it's always a surprise," Storms said. "The first thing you do is sit down with your team, look at the update, set priorities and assign resources. And then the next day, another update arrives, and you have to do it all over again.

"If you can't properly plan for this, you're in a constant firefighting mode," Storms continued. "Now it's affecting the management of the IT team."

And that has to spook businesses, whose administrators are used to pinning Microsoft's updates to specific dates on the calendar. "Even if you realize that the Mac may be an effective tool, it's going to have a greater impact on the infrastructure because of the way Apple patches," Storms said. "The question is, can your infrastructure withstand it?"

Charlie Miller, a researcher at Baltimore-based Independent Security Evaluators who is well-known for his Mac and iPhone vulnerability work, agreed that Apple's patching process makes it tough on corporate IT staffers. "Administrators rely on knowing what will happen," Miller said. "If they know, they can plan their week around it."

Posting patches without a schedule, Miller said, is an invitation for businesses to simply not patch. "For someone like me, it's no big deal, but for professionals, it's a whole different story," he said. "The last they want is a patch that just shows up. They can't patch without testing. So this is one more reason for them to go, 'I just won't patch.' "

Another researcher, Swa Frantzen of the SANS Institute's Internet Storm Center, however, disagreed with Storms and Miller. Frantzen argued that it was, no pun intended, an apples-and-oranges comparison to pit Apple's patching procedure against Microsoft's.

"If Apple should be compared with other vendors, take the other Unix vendors," Frantzen urged. "Sun, HP, FreeBSD, OpenBSD, the different Linux distributions -- very few of them group together patches in a monthly cycle."



Jump to comments

Apple

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

What People Are Saying