Security pros pan and praise Microsoft's plans on updating Modern apps in Windows 8, RT
Experts like the on-the-fly updating of apps, but the alerts ... not so much
Computerworld - Microsoft will issue security fixes for its Windows Store apps on the fly, not just on the familiar monthly Patch Tuesday, the company said this week.
At the same time, Microsoft spelled out how it will alert customers of security updates.
Windows Store apps are those written for the tile-style Modern user interface (UI) -- formerly called "Metro" -- in Windows 8 and Windows RT, the scaled-down version strictly for tablets. Those apps, such as the one that Twitter launched yesterday, are distributed only through the Windows Store, just as iPad apps are available only on Apple's iOS App Store.
App patches will be released whenever Microsoft has them ready, the company said, a departure from a long-established practice that has earned "Patch Tuesday" a place in the security lexicon: Microsoft issues security updates on the second Tuesday of each month. Only emergency updates, dubbed "out-of-band," appear on other days.
"App security updates can be delivered on days other than the second Tuesday of the month," stated an explanatory page on the Microsoft Security Response Center's (MSRC) website.
"Providing security updates to these apps more frequently will allow us to add new functionality, fix issues and improve security," argued Mike Reavey, senior director of the Microsoft Security Response Center (MSRC), on the group's blog.
Security experts applauded Microsoft for that.
"This moves normal PCs closer to phones and tablets as far as updates are concerned, not controlled by IT anymore," said Wolfgang Kandek, CTO of Qualys. "Instead [the apps are] generically kept as updated as possible. The more PCs we can replace by tablets and phones, the safer the network will be."
But they weren't as happy with the way Microsoft was alerting customers of security issues.
Microsoft will create a single, perpetual security advisory that will list every update -- both those downloaded from the Store as well as the ones bundled with Windows 8 and RT, like Mail and Messaging -- that in turn will offer links to individual support, or Knowledge Base, documents. The latter will spell out each individual update's contents.
"Windows Store app security updates will be documented in one security advisory, which will have a permanent URL and will be revised when new issues are added," said Dustin Childs, group manager of Microsoft's Trustworthy Computing group, in an email reply to questions. "A unique Microsoft Knowledge Base article number will accompany each issue, in order to provide a transparent and unique reference for individual security updates."
But the standing advisory got a pan from the pros.
"This is the wrong tactic," said Andrew Storms, director of security operations at nCircle, in an interview using instant messaging. "The single advisory method is confusing. It's difficult to keep track of what's been updated, what was updated in each release, and when. And in the event they issue mitigation guidance for a specific bug, it will be even more difficult to go and find the information. Considering all the apps they distribute, how would one neatly organize all that info in a single advisory?"
- Microsoft plans to patch critical under-attack IE bug next week
- Ballmer regrets not aping Apple sooner
- OS upgrades: Cheap is better than pricey, free is better than cheap
- Update: More top-tier Microsoft execs head for the door
- Microsoft ships Office 2013 SP1 the old-fashioned way
- Microsoft's 'go-low' play puts Windows revenue on the line
- Microsoft: Android Nokia not our call to make
- Gates sells another 20M shares; lead over Ballmer shrinks to nearly nothing
- Hey Microsoft, where's the next Mac Office?
- Microsoft dubs 'confusing' Office Web Apps as Office Online
- Best iPhone, iPad Business Apps for 2014
- 14 Tech Conventions You Should Attend in 2014
- 10 Desktop Apps to Power Your Windows PC
- How to Add New Job Skills Without Going Back to School
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts