Jeff's Connected Corner

Windows Server System news and real-world info

What Symantec Could Learn from Microsoft

People can joke all they want about the number and severity of Microsoft security vulnerabilities, but all this practice has enabled them to develop an excellent security response system.

Symantec should take note.  Their most recent security vulnerability (SYM06-010) has spawned a confusing array of maintenance and point patches.  Initial media reports claimed that only version 10.1 was affected.  However, after reviewing the most recent Symantec e-mail bulletin it appears that version 10.0 is affected as well.

In Symantec’s defense, the vulnerability information page for SYM06–010 is fairly well laid out.  In fact, I like that I don’t need to expand a nested hierarchy to get the information I’m looking for.  See Microsoft security bulletin MS06–018 as an example.  Scroll down to the General Information section… why should I have to click so many ‘+’ symbols?  At least give me an expand all option or something.

Oh, and this guys post is classic.  According to him, now that a patch is released there’s nothing to worry about.  Here’s his quote:

“The issues of remote code execution have been resolved now, thanks to the fix which means that the products are no longer vulnerable to a stack overflow”

Please move along… nothing to see here.  What a joke.  How many people spent their holiday weekend patching Symantec products?  Not very many, I’m sure.  This issue will continue to dog Symantec for many weeks to come.  I sincerely hope we don’t see any widespread attacks as a result of this vulnerability.  Anyway, it’s too bad we have a double-standard when it comes to reporting security issues.

Here is a list of things I’d like to see from Symantec:

  • Simplify the servicing of your software.  Not everyone understands the difference between maintenance releases, point releases, etc.
  • Offer an RSS feed of Symantec product vulnerabilities (including Veritas and other recent acquisitions).  The Symantec Security Response page would be a good place to locate such a feed.
  • Provide a security bulletin search tool similar to the Microsoft one found here.  Let me choose my product version, my OS, etc. and show all applicable updates.

What do you think?  If you’re a Symantec customer, how did you learn about the SYM06–010 vulnerability?  What about vulnerabilities 001 through 009?

Only published comments... May 29 2006, 02:12 PM by Jeff
Filed under:

Comments

 

Jerry said:

Jeff, the MS bulletins have a trick. Hit the "Printer Friendly Version" link at the very bottom left and you get what you wanted - expand all.

Jerry
May 29, 2006 1:33 PM
 

Josh Phillips said:

Totally agree...
May 29, 2006 6:38 PM
 

Jeff said:

There is so much to dislike about Symantec... the bundling of more and more junk into each release, the service issues, the overhead in your operating system, John Thompson's antics (zero credibility from the guy who used to run OS/2), and now this (not a surprise). Time to ditch this product and go elsewhere.
May 30, 2006 4:01 AM

Leave a Comment

(required)  
(optional)
(required)  
Add

About Jeff

Jeff Centimano is a Windows Server MVP based in Fairway, KS (USA). In addition to blogging and freelance technical writing for Microsoft, Jeff leads the KC-MEC User Group (kcmec.org) and assists with various site duties here at WindowsConnected.com. Jeff has been in the IT industry since 1994 and is currently a Solutions Architect at EMC Global Services.
Windows is a registered trademark of Microsoft Corporation.
Powered by Community Server (Non-Commercial Edition), by Telligent Systems Themed By nb development