Takeaway: A group of four computer scientists urged Microsoft to redesign the way
it distributes patches, after they created a technique, called automatic patch-based exploit generation (APEG), that
automatically produces attack code by comparing the vulnerable and
repaired versions of a program. "When Microsoft releases a patch, what they are saying -- from a security standpoint -- is, 'Here is an exploit,'" Brumley said.
FYI: FYI: Interested in the secure B2B identity architecture of tomorrow, replay the Federation and User Centric Identity webinar today!
Source: Security Focus
|