better analogies (“…Imagine someone traveling to a small town and learning …”)<\/li>\n<\/ul>\nand many, many more. Good reading and entertaining at the same time. Brian even provides spreadsheets with his data and links to sources.<\/p>\n
When I read this, I thought to myself “What if this article was about Microsoft?” – would the responses have been different? “What if the article was about Linux?” Sun? Oracle? I think it is clear from the emotional responses that the data matters less to some people than their belief system – and that’s not good for security!<\/p>\n
Here’s the question I ask myself. If I had one system that housed my critical business information (say customer credit cards) and I believed there were attackers who might target me to get that information, then wouldn’t I want to know<\/strong><\/em> how many vulnerabilities there are and how long a vendor might leave them unpatched? I would. If I was basing a 5-10 year business decision in part on security criteria, I certainly would (among many other things…). <\/p>\nOf course, I would also consider the threat of a virus and the threat of a targeted attack as two discrete risk issues and not muddle them together… but that’s for another day.<\/p>\n
<\/div>\n","protected":false},"excerpt":{"rendered":"
You’ve probably already read Brian Krebs article A Time to Patch III: Apple, but if you haven’t, I encourage you to read it and read the various responses he received – the responses run the gamut of Linux advocates (“You do understand that Mac OS X is not a version of Linux, and is not […]<\/p>\n","protected":false},"author":61,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ms_queue_id":[],"ep_exclude_from_search":false,"_classifai_error":"","_classifai_text_to_speech_error":"","footnotes":""},"content-type":[3662],"topic":[3688],"products":[],"threat-intelligence":[],"tags":[3822],"coauthors":[3653],"class_list":["post-744","post","type-post","status-publish","format-standard","hentry","content-type-news","topic-threat-trends","tag-microsoft-security-insights"],"yoast_head":"\n
Washington Post - A Time to Patch III: Apple | Microsoft Security Blog<\/title>\n \n \n \n \n \n \n \n \n \n \n \n\t \n\t \n\t \n \n \n \n\t \n\t \n\t \n