Thursday, November 27, 2003

Doctor, Doctor!!

"Hey, Doc! It hurts when I do this!"

"So don't do that."

While that may make for shoddy medical practice, it's even worse for security. According to ZDNet, Microsoft has issued a "knowledge paper to fix the hole in MS Exchange's OWA.

Anyone else see bad practice here?

(Hint: if they call it a "fix", marketing can claim that MS "fixes" things rapidly.) Want to talk fast, an ElGamal bug in GPG was announced today. Guess how long you have to wait for the patch? Answer: It's already out.

