6
Patching debate: quick fixes vs. full updates after a breach
My work server got hit with a vulnerability last Tuesday, and I patched it same day but ignored a firmware update. A buddy says that half measure is why we still saw issues 2 weeks later. Do you trust emergency patches alone, or do you always go for the full stack update?
3 comments
Log in to join the discussion
Log In3 Comments
corap6119d ago
That "half measure" comment hit close to home. I had a router that I only applied the quick security patch to and skipped the full update, it worked okay for a week then the whole network started dropping packets like crazy during a video call. Emergency patches just seem to cover the front door while the back window is still cracked open in my experience.
4
parker_webb19d ago
Saw a similar thing in a report about industrial control systems. They found that 60% of emergency patches only fixed the specific vulnerability and left other bugs in place. That matches what @park.aaron said about the truck cab rusting from the inside out. The real problem is these quick fixes are made under pressure with limited testing. They plug the obvious hole but miss the other weak spots that were already there. Full updates take longer because they address the whole system, not just the symptom. Companies push the emergency patch to look like they did something, but it's mostly just damage control.
1
park.aaron19d ago
Ignored a firmware update on a work server once after patching the security hole. Everything ran fine for about 10 days then the thing started rebooting itself in the middle of processing payroll. @corap61 you nailed it with that back window crack comment. Reminded me of my old truck where I fixed a leak in the roof only to find out the whole cab was rusting from the inside out. Emergency patches are basically putting a bandaid on a bullet wound. You gotta do the full stack or you're just buying time til the next thing breaks.
3