Microsoft Sparks Backlash By Tying Internet Explorer Changes To Security Patch

Security vendors say the security patch that Microsoft released on Tuesday will break the browser for some users.

By packaging a functionality change for Internet Explorer with a needed security update, Microsoft has alienated some IT pros, security vendors complained Wednesday.

Along with the 10 patches in Tuesday's MS06-013 security bulletin, Microsoft bundled changes to IE's handling of ActiveX controls. Those changes, which were prompted by a 2003 $521 million judgment against Microsoft in a patent lawsuit brought by Eolas Technologies Inc. and the University of California, will require users to manually activate controls on some sites.


More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

"Microsoft often bundles non-security-related code in security updates," said Mike Murray, director of research at vulnerability management vendor nCircle. "Little optimizations and that kind of thing. But I don't remember them ever bundling a functionality update or, as in this case, removing functionality, with a security bulletin."

The inclusion of the ActiveX changes "makes everything a mess" for companies deploying and testing Microsoft's monthly patches, Murray said. "I've talked to some of our customers, and they're at the point where they're pulling out their hair.

Instead, Microsoft should have separated the IE ActiveX changes from the security fixes. "They easily could have deployed it as a separate patch or rolled it into a service pack," said Murray.

In late March, Mike Nash, Microsoft's head of security, gave administrators a heads-up that the ActiveX changes would be coming April 11 and would be blended with the security update. At that time, his explanation for the bundling was that " in order to reduce the complexity of updates and to improve quality, we ship all IE updates as cumulative updates."

On Wednesday, a Microsoft spokesman went into more detail.

"While Microsoft tries to minimize the amount of non-security updates that go out with the regularly scheduled security updates, occasionally changes are permanently made to the Windows source code and therefore are picked up in the subsequent security update that installs the affected files," he said. "This particular change falls in that category."

He also hinted that the decision to roll the change into the security update was made in consultation with customers and partners, and after talking with them, the company concluded that this approach was the easiest to implement.

"Microsoft has been working with its customers and partners on the IE ActiveX update since early December 2005, and has been actively soliciting customer feedback on how to make this process as easy as possible," he said.

Microsoft has posted a "compatibility patch" to delay the court-mandated changes to IE until June 13, that month's scheduled bulletin release date, when the changes will be made permanent.


Page 2: 
 1 | 2 |Next Page » 

Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links