{"id":29,"date":"2008-07-02T15:22:32","date_gmt":"2008-07-02T13:22:32","guid":{"rendered":"http:\/\/www.ofcourseimright.com\/?p=29"},"modified":"2008-07-02T15:22:32","modified_gmt":"2008-07-02T13:22:32","slug":"good-fences-make-good-neighbors","status":"publish","type":"post","link":"https:\/\/ofcourseimright.com\/?p=29","title":{"rendered":"Good Fences Make Good Neighbors"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-medium wp-image-30\" style=\"margin-left: 5px; margin-right: 5px; float: left;\" title=\"fence\" src=\"http:\/\/www.ofcourseimright.com\/blog\/wp-content\/uploads\/2008\/07\/fence.jpg\" alt=\"A Fence\" width=\"166\" height=\"125\" \/>When I was about 13 years old, my neighbors put a pool in their back yard.\u00a0 However, they failed to put a fence around it.\u00a0 My sister at the time was only four years old, and there were many people her age in the neighborhood.\u00a0 In our community there was an ordinance that required such fences, but the neighbors ignored it, as they did my parents&#8217; pleas.<\/p>\n<p>While you can question the wisdom of letting a four year old walk around on his or her own, at the time it was the norm for our community, and one day little Donald was on his own, dangling his feet in the neighbor&#8217;s unsupervised pool.\u00a0 After running out of our house as fast as she could and pulling Donald away from the pool, my mother filed a complaint, causing the neighbors to have to pay a fine.\u00a0 Donald&#8217;s parents could have sued.<\/p>\n<p>Our neighbors created an <a href=\"http:\/\/en.wikipedia.org\/wiki\/Attractive_nuisance\">attractive nuisance<\/a> and needed to be held accountable. While not exactly the same, regularly updating your software with the latest versions <strong>does<\/strong> reduce a computer&#8217;s exposure to vulnerabilities.\u00a0 What&#8217;s more, there is a well known network effect of doing so.\u00a0 When you patch your software, not only do you protect your computer against attack by others, but you also prevent your computer from being used as a vehicle to attack others.\u00a0 Put another way, <strong>not<\/strong> patching your software makes your system a nuisance to others.\u00a0 The bad guys know this.\u00a0 One <a href=\"http:\/\/weis2008.econinfosec.org\/papers\/Holz.pdf\">study<\/a> by Jianwei Zhuge, et al, shows that exploits often appear in the wild <strong>before<\/strong> or very shortly after a patch is released.\u00a0 A <a href=\"http:\/\/weis2008.econinfosec.org\/papers\/MooreSecurity.pdf\">position paper<\/a> written by Ross Anderson, et al., for ENISA will tell you which vendors are better and which are worse at patching.<\/p>\n<p>A new <a href=\"http:\/\/www.techzoom.net\/publications\/insecurity-iceberg\/index.en\">study<\/a> released this week by people at the <a href=\"http:\/\/www.eth.ch\">ETH<\/a>, <a href=\"http:\/\/www.google.com\">Google<\/a>, and <a href=\"http:\/\/www.ibm.com\">IBM<\/a> shows that in the best case with Firefox, no more than 83% of users patch their browsers.\u00a0 The worst case is Internet Explorer, where you are more than likely not to have the latest patch.<\/p>\n<p>What does all this say?\u00a0 First of all it says that Firefox is probably doing a pretty good job.\u00a0 One wonders what is going on with the 17% of individuals who do not patch their browsers.\u00a0 Perhaps we have another case of rational ignorance, as I discussed <a href=\"http:\/\/www.ofcourseimright.com\/?p=28\">previously<\/a>.\u00a0 The study also says that Microsoft could do a better job.\u00a0 Part of Microsoft&#8217;s problem is that they have previously released \u201csecurity\u201d patches that do more than fix security problems. Distribution of <em>Windows Genuine Advantage<\/em>, which has been called a form of spyware, degraded peoples&#8217; trust in Microsoft.<\/p>\n<p>Apple isn&#8217;t all that much better than Microsoft.\u00a0 For one, their patch rates are actually slower than that of Microsoft.\u00a0 For another, Safari 3 broke stuff, which is precisely why many people do not upgrade.\u00a0 Sun and HP are even worse.<\/p>\n<p>Much as we like to blame vendors, in some cases we have nobody to blame but ourselves.\u00a0 Here is something to do.\u00a0 Check that you are running the latest version of the software you use.\u00a0 If you use anything more than the standard application suite for your computer, there is a very good chance you are out of date.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>When I was about 13 years old, my neighbors put a pool in their back yard.\u00a0 However, they failed to put a fence around it.\u00a0 My sister at the time was only four years old, and there were many people her age in the neighborhood.\u00a0 In our community there was an ordinance that required such &hellip; <a href=\"https:\/\/ofcourseimright.com\/?p=29\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Good Fences Make Good Neighbors&#8221;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[496],"class_list":["post-29","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/posts\/29","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=29"}],"version-history":[{"count":0,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=\/wp\/v2\/posts\/29\/revisions"}],"wp:attachment":[{"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=29"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=29"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ofcourseimright.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=29"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}