August 21, 2003 8:28 AM PDT

Windows patches may become automatic

In the aftermath of the MSBlast worm, Microsoft says it may be time to change the way Windows updates its security patches by making the process automatic by default.

A Microsoft representative said the company is "giving strong consideration to enabling Auto Update by default in future versions of Windows," though the company has not yet committed to a time frame. If Microsoft decides to go ahead with the change, it could be implemented in "Longhorn," the code name for the next version of Windows expected to come out in late 2004.

Automatic installation of security patches might have helped prevent the recent MSBlast worm, which successfully attacked hundreds of thousands of PCs that had not installed a month-old patch.

Currently, automatic updates are available as an option. Microsoft executives said the company decided not to make the feature a Windows default with Windows XP after customer feedback that suggested people did not want Microsoft controlling their PCs.

Some security experts, even those normally suspicious of Microsoft, said automatic updates might be the best way to secure PCs--particularly those of home users and small businesses.

Bruce Schneier, co-founder of Counterpane Internet Security and a well-known Microsoft critic, came out in support of the suggestion, telling The Washington Post that it was a "trade-off that's worthwhile."

Market research firm Gartner said such a move could help average people who generally lack the time and IT knowledge to keep up with the latest patches.

But Gartner asserts that Microsoft must make some changes to its updating system before it can be trusted to install software automatically on people's PCs. Gartner said Microsoft must promise not to use the auto-update feature for anything but security patches and should allow a security review of the system by outside parties.

"A compromise of this comparatively new feature could have catastrophic results," Gartner's Terry Allan Hicks said in a statement.

Many people, particularly enterprise system administrators, like to evaluate patches before they are applied because patches can interfere with other software, or even cause system failures. In a well-known incident, Microsoft's Service Pack 6 for Windows NT crashed thousands of servers.

When the first Windows XP service patch appeared last fall, critics said the patch's terms of use gave Microsoft the right to check product versions and block some programs, although Microsoft insisted that no personal information would be collected.

This is not the first time Microsoft has wanted to change its software update mechanism. In June, the company said it planned to simplify its patch technology and to expand its automatic update service to include more products.

The software giant identified four areas in which it plans to make improvements over the next 12 months: patch quality; delivering information to its customers; broadening the number of applications supported by its automated update technology; and simplifying the way that patches are applied.

Matthew Broersma of ZDNet UK reported from London. CNET News.com's Robert Lemos contributed to this report.

Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • News - Business Tech

    Chrome's JavaScript challenge to Silverlight

    The advent of Google's Chrome browser, software pros say, should spur a big speedup for JavaScript, which would raise its standing against Microsoft's Silverlight technology.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • News - Digital Media

    Google-focused satellite enters orbit

    The search titan has exclusive rights among online mapping sites to images from the new GeoEye-1 satellite, which launched Saturday.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crossfade

    The Standard, 'A Different Skin': Free MP3 of the Day

    Eschewing the danceable beats favored by many of its post-punk brethren, while opting instead for more ominous and insistent rhythms, is what makes the Standard visceral and engaging. Download a free MP3 of "A Different Skin" courtesy of CNET Download Mus

  • Green Tech

    Duke Energy to invest in mini solar power plants

    Can hundreds of rooftop solar panels collectively operate like a central power plant? Duke Energy launches $100 million distributed solar program to find out.