Software, Hockey, and random ramblings.
5 Jan
I just sent this note to my family members. I typically don’t make a big deal out of this kind of stuff, but this one warrants it:
I just wanted to send you a note to say that if you’ve been postponing an automatic Windows Update, please do it. Also, if you haven’t, open Internet Explorer and visit www.windowsupdate.com and make sure you install any critical updates.
There’s a really nasty security hole in all Windows systems that can allow the system to be compromised by simply viewing an image file - and the image could be in an email or browser or even Instant Messaging client. This is a nasty one. Microsoft just released a fix for it, so please update!
Marc over at the Unofficial Microsoft Weblog (where I also blog) has the details, and boy, they’re scary. Looks like Microsoft in all their wisdom have decided not to release an update for Windows 2000, as it has reached the end of its product support life cycle. This is simply ludicrous, and can be seen only as a cash grab. Windows 2000 is still installed and working wonderfully on hundreds of thousands of machines on the internet. Not providing a fix for this vulnerability is irresponsible in the extreme, and reprehensible. I’m personally disgusted with this decision.
And to think earlier today I was getting excited about the features listed on the Windows Vista website. Decisions like this push me ever closer to purchasing my first ever Mac, and leaving the Windows world (except at work) forever. Nice job, M$.
[Update]
As Marc notes in the comments below, Windows 2000 SP4 is, in fact, protected by this latest Windows Update; it’s simply versions previous to SP4 that are not. This is very good news.
I may have prematurely cried wolf above, but I think it’s a valid issue that deserves open discussion. Windows 2000 is a solid OS that will run on extremely modest hardware. I know many people that have systems that simply will not run XP, and they are able to safely browse the internet and do all the necessary computing tasks they need to do using Windows 2000. I realize this doesn’t help Microsoft meet their quarterly earnings, but at some point, that hardware will eventually fail, and those people will need to upgrade.
I guess my feeling is simply that upgrading hardware for non-geeks doesn’t need to be done nearly as frequently as the technology companies would have us believe. When you’re operating a company that is effectively a monopoly, if not explicitly so, I believe you should have a responsibility to keep an operating system available for 10 years that is safe to use.
Maybe that’s just me.
Technorati Tags: microsoft, wmf, vulnerability, windows2000
2 Responses for "Do Your Windows Updates!"
Jason: I updated my post. Technically, Windows 200 is supported is you’re using SP4. Only SP3 and earlier will not be patched. It’s a tough call - it’s no secret that Win2K has been “end-of-lifed” and that the day would come when lack of support from Microsoft would become an issue. I think part of the reason Microsoft has been struggling to ship new product is the amount of legacy support they have traditionally committed to. They’re recognizing that they’ll have to change that strategy to move forward. It worked for Apple.
Just wanna say thanks for the heads up I’ve finally updated
Leave a reply