Microsoft prepares Windows patch CD

Microsoft prepares Windows patch CD

Summary: The security update CD for older Windows systems, set to begin testing soon, is Microsoft's latest attempt to tackle an increasingly thorny security situation

TOPICS: Security

Microsoft is planning to begin testing next week a security CD designed to allow users of older Windows systems to easily bring their PCs up to date -- a new attempt to change a situation that has been a boon to virus writers and spammers.

The software company last month called for users to beta test a CD designed to provide critical security updates to users of older editions of Windows, including Windows 98, Windows 98 SE and Windows ME. "This security update CD will be of special benefit to customers with slow Internet connections and for those customers who typically do not visit the Microsoft Web site to download updates for their computers," the company said in an email to potential testers, which made its way onto Windows rumour sites.

This week the project moved on to its next step, with testers who had been accepted into the programme informed that the first release candidate would be released sometime next week. The new email was published on rumour site Microsoft has not set a release date for the CD.

The potential product, which Microsoft said it is "considering developing", could be a first step towards ensuring that Internet-connected PCs are patched, a problem that has become increasingly thorny as virus and spam levels mount. Many users rarely or never apply security patches to their systems, because they are not aware that they should, can't be bothered or don't wish to spend hours downloading an enormous backlog of fixes over a slow Internet connection.

The result -- especially for unpatched computers with an always-on Internet connection -- can be serious for the rest of the Internet. "One of the biggest problems we're facing today is that viruses manage to infect and spread through the large number of unpatched computers on the Internet," said Mikko Hypponen, director of antivirus company F-Secure. "There are thousands and thousands of computers in the world that are always on the Internet, through DSL or cable connections, but the users have no skills to keep those computers up to date."

Many users leave their machines unpatched for months, even after a virus infection, allowing their computers to continue to bombard the rest of the Internet with attacks, Hypponen said. This is one of the reasons why viruses such as Sobig continue to linger for months.

Some viruses allow spammers to use the infected machines to relay junk email, making the spam nearly impossible to track down or stop. Antivirus company Sophos recently estimated that a third of all spam is carried by infected PCs.

The programme could be a good way to get users to patch their PCs, Hypponen said. "I applaud them for doing this," he said. "I think it's a good idea. In fact, maybe they should have done it sooner."

He cautioned that patching alone wouldn't be enough, saying users should be encouraged to run a firewall and antivirus software. He also said that broadband users shouldn't leave their PCs connected to the Internet when it isn't necessary.

Microsoft is pursuing other ways of getting Windows computers patched, including an advertising campaign and possibly making future versions of Windows download patches automatically by default.

Topic: Security

Kick off your day with ZDNet's daily email newsletter. It's the freshest tech news and opinion, served hot. Get it.


Log in or register to join the discussion
  • ...and maybe Microsoft will finally start mailing service packs to countries other than the USA (third-world nations like, um, Britain, for example).

    It's all very well making CDs available to the USA where so many people can easily download huge patches instead because they have broadband anyway. What about everywhere else? Constant system updates via dial-up? Go figure.
  • I could not agree More with Your Last Submitter,When you install XP,Windows Update Site takes ages to update and install,I am into anything that would make it a lot easier,With installing Graphic cards and Up to date New Browers,so your windows updates,do not install correctly.Yes and thats with a Broadband connection,if isps can send cds,in magazines,so can Microsoft.
  • They're always a day late and a CD short on things like this. We all have been beta testers for their products for years. Now they want to supply us with patches that will supposedly repair their previous mistakes. Why weren't they creating these patches instead of creating new operating systems for us to buy??
    Now that there is a backlash and sales are getting hurt, they are trying to act benevolent. I, for one, think that it's too little. too late.
  • It is about time Microsoft did something like this but it should be extended to include WinXP. We are currently upgrading our PC's and at the moment this means a download of any thing from 40 to 60 Mb to obtain SP1 and all other patches and fixes. I pity the home users without a broadband connection. To do this on a dial up connection is just not on.
  • Good article but how does one get this CD??
  • I Think every one will look forward to getting the CD