<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Microsoft Issues Stopgap Fix for IE 0-Day Flaw</title>
	<atom:link href="http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Wed, 22 May 2013 03:56:06 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: SeymourB</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-117743</link>
		<dc:creator>SeymourB</dc:creator>
		<pubDate>Fri, 28 Sep 2012 15:57:24 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-117743</guid>
		<description><![CDATA[So Microsoft is supposed to send out a legion of employees to every Windows desktop in the world and force the end user to install an update? What about users on desktops which the admin has blocked their ability to install updates, what then?

Android is a whole other ballgame with phone companies dropping the ball again and again. They&#039;re like power companies caught flat-footed by security holes and not able to understand why they can&#039;t just push out product and never issue updates for it. The world is changing and their business models have to change, but of course they fight it tooth and nail.

While Microsoft did release this update in a timely manner and gave everyone a workaround ahead of time, I wish they had offered the workaround earlier and hadn&#039;t done the usual spin doctoring to claim it&#039;s not a big deal. But that&#039;s Microsoft - they&#039;re more and more a marketing company now than a technology company, most of what they produce is a little bit of tech underneath a load of frothy spin.]]></description>
		<content:encoded><![CDATA[<p>So Microsoft is supposed to send out a legion of employees to every Windows desktop in the world and force the end user to install an update? What about users on desktops which the admin has blocked their ability to install updates, what then?</p>
<p>Android is a whole other ballgame with phone companies dropping the ball again and again. They&#8217;re like power companies caught flat-footed by security holes and not able to understand why they can&#8217;t just push out product and never issue updates for it. The world is changing and their business models have to change, but of course they fight it tooth and nail.</p>
<p>While Microsoft did release this update in a timely manner and gave everyone a workaround ahead of time, I wish they had offered the workaround earlier and hadn&#8217;t done the usual spin doctoring to claim it&#8217;s not a big deal. But that&#8217;s Microsoft &#8211; they&#8217;re more and more a marketing company now than a technology company, most of what they produce is a little bit of tech underneath a load of frothy spin.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meh</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-116247</link>
		<dc:creator>meh</dc:creator>
		<pubDate>Tue, 25 Sep 2012 20:49:20 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-116247</guid>
		<description><![CDATA[I saw that later on.  I still stand by my original statement, it is a piss poor way to foster security to ask like Droopy for a hundred million users to update something on their own.

Android suffers from a similar problem where updates are available but wait around on users or vendors to get around to the update, and as a result the vast majority are running insecure and outdated versions.

I strongly believe if you leave the responsibility for security up to the end user you can&#039;t complain when they mess it up.  Murphy&#039;s law or some such.]]></description>
		<content:encoded><![CDATA[<p>I saw that later on.  I still stand by my original statement, it is a piss poor way to foster security to ask like Droopy for a hundred million users to update something on their own.</p>
<p>Android suffers from a similar problem where updates are available but wait around on users or vendors to get around to the update, and as a result the vast majority are running insecure and outdated versions.</p>
<p>I strongly believe if you leave the responsibility for security up to the end user you can&#8217;t complain when they mess it up.  Murphy&#8217;s law or some such.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jerry</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-113738</link>
		<dc:creator>Jerry</dc:creator>
		<pubDate>Sat, 22 Sep 2012 09:06:56 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-113738</guid>
		<description><![CDATA[Chris, I was a performance analyst at msft.  I consider IE9 to be a memory hog.  To me, Chrome&#039;s smaller footprint makes sense performance-wise.  If you like IE9 better, then be my guest.

There are features, such as the cached bookmarks, that I really like.  There are some bugs, such as when Chrome loses network connection and occasionally cannot recover.  The residual chrome.exe process won&#039;t die, even when I try to kill it with ProcExplorer.  

I like the auto-update feature (which I can block with Vipre IS 2012 firewall HIPS).  I like the way they integrate Flash into the auto-update.

All in all, I like Chrome.]]></description>
		<content:encoded><![CDATA[<p>Chris, I was a performance analyst at msft.  I consider IE9 to be a memory hog.  To me, Chrome&#8217;s smaller footprint makes sense performance-wise.  If you like IE9 better, then be my guest.</p>
<p>There are features, such as the cached bookmarks, that I really like.  There are some bugs, such as when Chrome loses network connection and occasionally cannot recover.  The residual chrome.exe process won&#8217;t die, even when I try to kill it with ProcExplorer.  </p>
<p>I like the auto-update feature (which I can block with Vipre IS 2012 firewall HIPS).  I like the way they integrate Flash into the auto-update.</p>
<p>All in all, I like Chrome.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SeymourB</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-113494</link>
		<dc:creator>SeymourB</dc:creator>
		<pubDate>Sat, 22 Sep 2012 01:00:21 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-113494</guid>
		<description><![CDATA[They released a patch for it today, and I rolled the Fixit out through Group Policy on Wednesday to all the desktops I&#039;m responsible for... if companies didn&#039;t do the same, I feel sorry for the schmuck who&#039;ll get blamed for not having done it.]]></description>
		<content:encoded><![CDATA[<p>They released a patch for it today, and I rolled the Fixit out through Group Policy on Wednesday to all the desktops I&#8217;m responsible for&#8230; if companies didn&#8217;t do the same, I feel sorry for the schmuck who&#8217;ll get blamed for not having done it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: meh</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-113373</link>
		<dc:creator>meh</dc:creator>
		<pubDate>Fri, 21 Sep 2012 20:43:20 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-113373</guid>
		<description><![CDATA[Not a great way to address the issue, tens of millions of users with the browser and they ask them please please install a patch...  

Eventually it will probably be baked in but the whole series of articles about this issue has smacked of a poorly handled response to a major scandal - how many corporate or non news reading users is microsoft really expecting will do this?  I&#039;d be surprised if even 10% of their total client base ends up doing any of these measures.]]></description>
		<content:encoded><![CDATA[<p>Not a great way to address the issue, tens of millions of users with the browser and they ask them please please install a patch&#8230;  </p>
<p>Eventually it will probably be baked in but the whole series of articles about this issue has smacked of a poorly handled response to a major scandal &#8211; how many corporate or non news reading users is microsoft really expecting will do this?  I&#8217;d be surprised if even 10% of their total client base ends up doing any of these measures.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: SeymourB</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-113332</link>
		<dc:creator>SeymourB</dc:creator>
		<pubDate>Fri, 21 Sep 2012 19:25:39 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-113332</guid>
		<description><![CDATA[Eh? Windows 7 shipped with IE 8 (though I believe SP1 includes IE9).

Are you absolutely sure you have builds with IE 7? Because you can run IE 8 in a mode where it&#039;s virtually identical to IE 7 (switch Browser Mode to IE7 and Document Mode to IE7). But it&#039;s still IE8 and security advisories for IE8 should apply.

In short, the reason W7 &amp; W2K8 isn&#039;t included under IE7 is because, if you went out of your way to install IE7 on W7 and managed to hack it in, you get to deal with supporting it.]]></description>
		<content:encoded><![CDATA[<p>Eh? Windows 7 shipped with IE 8 (though I believe SP1 includes IE9).</p>
<p>Are you absolutely sure you have builds with IE 7? Because you can run IE 8 in a mode where it&#8217;s virtually identical to IE 7 (switch Browser Mode to IE7 and Document Mode to IE7). But it&#8217;s still IE8 and security advisories for IE8 should apply.</p>
<p>In short, the reason W7 &amp; W2K8 isn&#8217;t included under IE7 is because, if you went out of your way to install IE7 on W7 and managed to hack it in, you get to deal with supporting it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-113159</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Fri, 21 Sep 2012 14:35:33 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-113159</guid>
		<description><![CDATA[Interesting, I downloaded Chrome two weeks ago, and I&#039;ve only used it a couple of times because I dislike it so much after using IE9 - I had downloaded the beta version when it was released. Chrome seems cluttered.

I think IE9 is cleaner, and has a more organic feel than Chrome, plus I love the pictures.  I love the security features for IE9, because I have other users that will click on anything, including a brother with severe mental limitations.  (I removed Java a while ago, and I haven&#039;t needed it for anything.)

I&#039;ll keep Chrome as a backup, but I&#039;m not impressed.]]></description>
		<content:encoded><![CDATA[<p>Interesting, I downloaded Chrome two weeks ago, and I&#8217;ve only used it a couple of times because I dislike it so much after using IE9 &#8211; I had downloaded the beta version when it was released. Chrome seems cluttered.</p>
<p>I think IE9 is cleaner, and has a more organic feel than Chrome, plus I love the pictures.  I love the security features for IE9, because I have other users that will click on anything, including a brother with severe mental limitations.  (I removed Java a while ago, and I haven&#8217;t needed it for anything.)</p>
<p>I&#8217;ll keep Chrome as a backup, but I&#8217;m not impressed.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dirgster</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-112762</link>
		<dc:creator>Dirgster</dc:creator>
		<pubDate>Fri, 21 Sep 2012 00:55:51 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-112762</guid>
		<description><![CDATA[As always, thanks for keeping us safe out there, Brian!  

And Phoenix, thanks for the update reminder for Flash Player!  May I add that there is also an update for Adobe Shockwave Player, the newest version being 11.6.7.r637 at http://get.adobe.com/shockwave/]]></description>
		<content:encoded><![CDATA[<p>As always, thanks for keeping us safe out there, Brian!  </p>
<p>And Phoenix, thanks for the update reminder for Flash Player!  May I add that there is also an update for Adobe Shockwave Player, the newest version being 11.6.7.r637 at <a href="http://get.adobe.com/shockwave/" rel="nofollow">http://get.adobe.com/shockwave/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VulnVet</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-112649</link>
		<dc:creator>VulnVet</dc:creator>
		<pubDate>Thu, 20 Sep 2012 21:12:10 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-112649</guid>
		<description><![CDATA[The MS KB page http://support.microsoft.com/kb/2757760  does not list Windows 7 or Windows 2008 (or 2008 R2) under IE 7 affected O/S.  We actually have Windows 7 builds with that lower version of IE.  If applicable, it should advise.]]></description>
		<content:encoded><![CDATA[<p>The MS KB page <a href="http://support.microsoft.com/kb/2757760" rel="nofollow">http://support.microsoft.com/kb/2757760</a>  does not list Windows 7 or Windows 2008 (or 2008 R2) under IE 7 affected O/S.  We actually have Windows 7 builds with that lower version of IE.  If applicable, it should advise.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: JimV</title>
		<link>http://krebsonsecurity.com/2012/09/microsoft-issues-stopgap-fix-for-ie-0-day-flaw/comment-page-1/#comment-112514</link>
		<dc:creator>JimV</dc:creator>
		<pubDate>Thu, 20 Sep 2012 17:02:41 +0000</pubDate>
		<guid isPermaLink="false">http://krebsonsecurity.com/?p=16926#comment-112514</guid>
		<description><![CDATA[I believe that 64-bit versions of the Windows 7 OS flavors have both 32-bit and 64-bit versions of IE installed, so the FixIt patch is advisable even if it only addresses the 32-bit version.

I had no problems with the patch installation on 5 of my 6 machines, but it wouldn&#039;t install on a Vista Ultimate SP2 32-bit machine just as an earlier FixIt patch wouldn&#039;t -- could never get that resolved, so like before I&#039;ll just have to wait until tomorrow for the out-of-band update to resolve the IE flaw for that computer.]]></description>
		<content:encoded><![CDATA[<p>I believe that 64-bit versions of the Windows 7 OS flavors have both 32-bit and 64-bit versions of IE installed, so the FixIt patch is advisable even if it only addresses the 32-bit version.</p>
<p>I had no problems with the patch installation on 5 of my 6 machines, but it wouldn&#8217;t install on a Vista Ultimate SP2 32-bit machine just as an earlier FixIt patch wouldn&#8217;t &#8212; could never get that resolved, so like before I&#8217;ll just have to wait until tomorrow for the out-of-band update to resolve the IE flaw for that computer.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 21/22 queries in 0.002 seconds using memcached
Object Caching 385/401 objects using memcached

 Served from: krebsonsecurity.com @ 2013-05-22 03:20:42 by W3 Total Cache -->