iEntry 10th Anniversary RSS Archive

IT Management Begins With Security
SecurityProNews > News > Security News > Microsoft Speeds Up DRM Patch
Search:
[ news_security_news ]

Microsoft Speeds Up DRM Patch



David Utter
Staff Writer
2006-09-07

SecurityProNews: Insider Reports Insider Reports RSS Feed


Cryptography and security expert Bruce Schneier observed that Microsoft's reaction to having its digital rights management scheme cracked was a far cry from its IE or Windows patch efforts.

When news of FairUse4WM began to make the rounds online, it opened up Windows Media Player 10 and 11 files to being relieved of their DRM and usable in whatever way suited the user.

That situation could not last, and three days later, a patch for the problem had been crafted.

"If you really want to see Microsoft scramble to patch a hole in its software, don't look to vulnerabilities that impact countless Internet Explorer users or give intruders control of thousands of Windows machines," Schneier wrote. "Just crack Redmond's DRM."

"There's no month-long wait for copyright holders who rely on Microsoft's DRM," he wrote. Then, just as rapidly, the people behind FairUse4WM updated their software to not only get around the patch for Windows Media DRM 10 and 11 files, but version 9 and 11beta2 files as well.

Patching a single DRM scheme is much different than patching Internet Explorer or Windows. Other applications, including legacy ones, may depend on some bit of functionality that a faster patching effort would break on the operating system or the browser.

Schneier also noted that Microsoft faces an "economic balancing act" when it comes to the patch cycle. While end users and corporate administrators benefit from having a regular cycle of updates, Microsoft incurs lower development costs by only having to build and test patches once a month.

"The user pays for this strategy by remaining open to known vulnerabilities for up to a month," said Schneier. This downside happens when a vulnerability enters the wild shortly after a "Patch Tuesday" update has been released. Microsoft has shown reluctance to make security patches available out of cycle for those incidents.

Unless, it seems, if it affects their DRM, so another patch to thwart FairUse4WM should be arriving soon.

---
Tags: ,

Add to Del.icio.us | Digg | Yahoo! My Web | Furl

Get all the updates in RSS:





About the Author:
David Utter is a business and technology writer for SecurityProNews and WebProNews.

More news_security_news Articles

SecurityProNews: Insider Reports Insider Reports RSS Feed


Get Your Site Submitted for Free in the World's Largest B2B Directory!

Email Address:
* URL:
*
*Indicates Mandatory Field

Terms & Conditions

iEntry Featured Services: Jayde Member Services | Forums | Freeware | Advertise with Us

Virus Warnings

Subscribe to
SecurityProNews FREE!



[ more newsletters ]

article resources
Search Articles:
[advanced search]

WebProWorld.com
Get in-touch with industry experts and leaders
Post your site for review by expert and peers
Ask Security, IT, Development and Design questions

Free Membership: Join Now!

Visit WebProWorld.com

Titan Quest Forum
The #1 Titan Quest forum
Halo 3 Forum
The best Halo, Halo 2, Halo 3 forum
Nintendo Wii
Nintendo Wii news and views
Mac Software
The best in OS X freeware
Graphics Forum
Your source for graphic tutorials
SecurityProNews.com | Breaking eBusiness News Get Your IT Questions Answered - Click Here SecurityProNews News Feeds