<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Channel 9 Forums - Coffeehouse - security patch win8</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Forums/rss"></atom:link>
	<image>
		<url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
		<title>Channel 9 Forums - Coffeehouse - security patch win8</title>
		<link>http://channel9.msdn.com/Forums</link>
	</image>
	<description>Channel 9 keeps you up to date with the latest news and behind the scenes info from Microsoft that developers love to keep up with. From LINQ to SilverLight – Watch videos and hear about all the cool technologies coming and the people behind them.</description>
	<link>http://channel9.msdn.com/Forums</link>
	<language>en</language>
	<pubDate>Mon, 20 May 2013 17:31:12 GMT</pubDate>
	<lastBuildDate>Mon, 20 May 2013 17:31:12 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<c9:totalResults>16</c9:totalResults>
	<c9:pageCount>-16</c9:pageCount>
	<c9:pageSize>-1</c9:pageSize>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p>Seriously Microsoft, patch it before release. Not saying you should hold off the security patch. But, I just feel less confident about my OS when it patch soon after its initial release.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/f1f1361e8851487381d1a1050104aa4c#f1f1361e8851487381d1a1050104aa4c</link>
		<pubDate>Sat, 10 Nov 2012 15:49:03 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/f1f1361e8851487381d1a1050104aa4c#f1f1361e8851487381d1a1050104aa4c</guid>
		<dc:creator>magicalclick</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/magicalclick/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p>@<a href="/Forums/Coffeehouse/security-patch-win8#cf1f1361e8851487381d1a1050104aa4c">magicalclick</a>: Chances are, to make it into Windows Update right now, the patch was in the works before the release but after RTM. You can't delay RTM for every little thing that you find, otherwise you'd never release.</p><p>EDIT: On another note, I didn't even know that there was an update. I consider that to be a very good thing, not only for me, but for consumers.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/4d6e6c17e39e4dd19256a105010756df#4d6e6c17e39e4dd19256a105010756df</link>
		<pubDate>Sat, 10 Nov 2012 15:58:47 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/4d6e6c17e39e4dd19256a105010756df#4d6e6c17e39e4dd19256a105010756df</guid>
		<dc:creator>kettch</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/kettch/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p>Microsoft releases a patch once a month for all of it's products. Why do you think Windows8 wouldn't be being patched a month after release?</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/eb5355b7f9e14300a729a105010df6eb#eb5355b7f9e14300a729a105010df6eb</link>
		<pubDate>Sat, 10 Nov 2012 16:22:54 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/eb5355b7f9e14300a729a105010df6eb#eb5355b7f9e14300a729a105010df6eb</guid>
		<dc:creator>evildictaitor</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/evildictaitor/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p>Because it should be future proof for a little while.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/cf63b7628f564caa9e78a105011f26a0#cf63b7628f564caa9e78a105011f26a0</link>
		<pubDate>Sat, 10 Nov 2012 17:25:29 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/cf63b7628f564caa9e78a105011f26a0#cf63b7628f564caa9e78a105011f26a0</guid>
		<dc:creator>magicalclick</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/magicalclick/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/security-patch-win8/cf63b7628f564caa9e78a105011f26a0">20 minutes&nbsp;ago</a>, <a href="/Niners/magicalclick">magicalclick</a> wrote</p><p>Because it should be future proof for a little while.</p><p></p></div></blockquote><p></p><p>Why? Microsoft stopped building Win8 in late June / early July.</p><p>Since then, they've had a ton of error messages back via Watson, external people have posted bugs, internal tests have found issues.</p><p>Should Microsoft leave those bugs open for people to exploit? Or should they patch them?</p><p>Security patches aren't a big deal. They're just fixing up bugs that have been found.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/70568fc42f104164a59aa10501251c42#70568fc42f104164a59aa10501251c42</link>
		<pubDate>Sat, 10 Nov 2012 17:47:10 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/70568fc42f104164a59aa10501251c42#70568fc42f104164a59aa10501251c42</guid>
		<dc:creator>evildictaitor</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/evildictaitor/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/security-patch-win8/cf63b7628f564caa9e78a105011f26a0">21 minutes&nbsp;ago</a>, <a href="/Niners/magicalclick">magicalclick</a> wrote</p><p>Because it should be future proof for a little while.</p><p></p></div></blockquote><p></p><p>Why? It's not been rewritten from scratch. Something that affects previous versions could reflect in the latest version. (Note, I don't know what the vulnerability is). Of course brand new code isn't safer. Sure, there's more mitigations in each version, DEP, ASLR etc. so the risk might be lesser on later OSes, but expecting it to be future proof is, in my opinion, unreasonable.</p><p>&nbsp;</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/3c5d09ed2ced44fa92d7a1050125c635#3c5d09ed2ced44fa92d7a1050125c635</link>
		<pubDate>Sat, 10 Nov 2012 17:49:35 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/3c5d09ed2ced44fa92d7a1050125c635#3c5d09ed2ced44fa92d7a1050125c635</guid>
		<dc:creator>blowdart</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/blowdart/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p>This is one of the most cryptic threads ever. Are you advocating applying patches to Windows 8, creating patches for Windows 8, or something even crazier, not creating or applying patches for Windows 8?</p><p>In any case, none of this makes sense.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/d7bf7342ee2a4baf8ca1a10501265f9a#d7bf7342ee2a4baf8ca1a10501265f9a</link>
		<pubDate>Sat, 10 Nov 2012 17:51:46 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/d7bf7342ee2a4baf8ca1a10501265f9a#d7bf7342ee2a4baf8ca1a10501265f9a</guid>
		<dc:creator>Joshua Ross</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Jsoh/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/security-patch-win8/3c5d09ed2ced44fa92d7a1050125c635">3 minutes&nbsp;ago</a>, <a href="/Niners/blowdart">blowdart</a> wrote</p><p>*snip*</p><p>Why? It's not been rewritten from scratch. Something that affects previous versions could reflect in the latest version. (Note, I don't know what the vulnerability is).&nbsp;</p><p></p></div></blockquote><p></p><p>The bug in question is in Microsoft XML Core Services - code that was written and deployed in Windows XP SP3.</p><p>A remote code execution vulnerability exists in the way that Microsoft XML Core Services handles objects in memory. The vulnerability could allow remote code execution if a user views a website that contains specially crafted content. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</p><p><a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-043">http&#58;&#47;&#47;technet.microsoft.com&#47;en-us&#47;security&#47;bulletin&#47;ms12-043</a></p><p>My vote is that Microsoft was right to patch it. I'd prefer to have to install patches (annoying as that is), than to allow remote attackers to gain access to my Windows8 device.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/e49f2f3319624f2baa9fa10501288f41#e49f2f3319624f2baa9fa10501288f41</link>
		<pubDate>Sat, 10 Nov 2012 17:59:44 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/e49f2f3319624f2baa9fa10501288f41#e49f2f3319624f2baa9fa10501288f41</guid>
		<dc:creator>evildictaitor</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/evildictaitor/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p>@<a href="/Forums/Coffeehouse/security-patch-win8#ce49f2f3319624f2baa9fa10501288f41">evildictaitor</a>: How do you even know what magicalclick is even talking about? At any given point, there are multiple critical remote execution vulnerabilities for Windows or some component there of.</p><p>edit: Just for clarification, I&nbsp;believe&nbsp;that the latest versions of Windows are very secure, and are getter more secure as time elapses.</p><p>-Josh</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/2af307acd1fd4fe18c27a105012c091e#2af307acd1fd4fe18c27a105012c091e</link>
		<pubDate>Sat, 10 Nov 2012 18:12:23 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/2af307acd1fd4fe18c27a105012c091e#2af307acd1fd4fe18c27a105012c091e</guid>
		<dc:creator>Joshua Ross</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Jsoh/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/security-patch-win8/2af307acd1fd4fe18c27a105012c091e">1 hour&nbsp;ago</a>, <a href="/Niners/JoshRoss">JoshRoss</a> wrote</p><p>@<a href="/Forums/Coffeehouse/security-patch-win8#ce49f2f3319624f2baa9fa10501288f41">evildictaitor</a>: How do you even know what magicalclick is even talking about? At any given point, there are multiple critical remote execution vulnerabilities for Windows or some component there of.</p><p></p></div></blockquote><p></p><p>Because that is the critical bug that was patched this month for Windows8. I assumed Magicalclick didn't find an 0-day in Windows8 himself, and there aren't many other Windows8 patches to choose from :/</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/cff0cffc86444a1f9516a10501440566#cff0cffc86444a1f9516a10501440566</link>
		<pubDate>Sat, 10 Nov 2012 19:39:43 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/cff0cffc86444a1f9516a10501440566#cff0cffc86444a1f9516a10501440566</guid>
		<dc:creator>evildictaitor</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/evildictaitor/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p>@<a href="/Forums/Coffeehouse/security-patch-win8#ccff0cffc86444a1f9516a10501440566">evildictaitor</a>:</p><p>Yeah, I think that's what you found. I only know it is about remote code execution, but, not knowing it is as serious as you described. I don't mind frequent security patches. But, I really prefer to have new OS not open to big attacks like this.</p><p>At least make it hard enough for people to find security holes slower.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/81d93623cd3347119dbea105015c63ac#81d93623cd3347119dbea105015c63ac</link>
		<pubDate>Sat, 10 Nov 2012 21:08:26 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/81d93623cd3347119dbea105015c63ac#81d93623cd3347119dbea105015c63ac</guid>
		<dc:creator>magicalclick</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/magicalclick/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/security-patch-win8/81d93623cd3347119dbea105015c63ac">1 hour&nbsp;ago</a>, <a href="/Niners/magicalclick">magicalclick</a> wrote</p><p>@<a href="/Forums/Coffeehouse/security-patch-win8#ccff0cffc86444a1f9516a10501440566">evildictaitor</a>:</p><p>At least make it hard enough for people to find security holes slower.</p><p></p></div></blockquote><p></p><p>It's a whole lot harder to find security bugs in Windows8 than against most other commercial products that I've seen.</p><p>I would put $200 on you having written a bug that would be marked by Microsoft's security team as being &quot;remote code execution&quot; at some point in your career - it's just you probably wouldn't know to classify it as such, and probably aren't looking for those bugs.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/37d47778918245e18684a10501725c1c#37d47778918245e18684a10501725c1c</link>
		<pubDate>Sat, 10 Nov 2012 22:28:26 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/37d47778918245e18684a10501725c1c#37d47778918245e18684a10501725c1c</guid>
		<dc:creator>evildictaitor</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/evildictaitor/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/security-patch-win8/81d93623cd3347119dbea105015c63ac">1 day&nbsp;ago</a>, <a href="/Niners/magicalclick">magicalclick</a> wrote</p><p>@<a href="/Forums/Coffeehouse/security-patch-win8#ccff0cffc86444a1f9516a10501440566">evildictaitor</a>:</p><p>Yeah, I think that's what you found. I only know it is about remote code execution, but, not knowing it is as serious as you described. I don't mind frequent security patches. But, I really prefer to have new OS not open to big attacks like this.</p><p>At least make it hard enough for people to find security holes slower.</p><p></p></div></blockquote><p></p><p>Your expectations are unreasonable. Maybe you don't understand that the hole was found in existing code, not code new to Win8? That's the only way I can interpret &quot;make it hard enough for people to find security holes slower.&quot; In any case, it is what it is. Microsoft is doing at least as well as everyone else here, and patching rapidly is a good thing that should give you more confidence, not less.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/654221a4fbe2486d8021a1070105c174#654221a4fbe2486d8021a1070105c174</link>
		<pubDate>Mon, 12 Nov 2012 15:53:01 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/654221a4fbe2486d8021a1070105c174#654221a4fbe2486d8021a1070105c174</guid>
		<dc:creator>William Kempf</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/wkempf/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p>Look, it's pretty simple. If Microsoft <em>could</em> make a version of Windows that wouldn't need to patched for several months on end, they would do it. Unfortunately, they can't. And for as long as software is written by humans, no one will be able to accomplish such a feat.</p><p>MS has insane security standards in place since the security push of XPSP2. This is literally as good as they can make it, and they're already at least as good, if not better, than anyone else. It's simply not possible to do better with current software engineering techniques.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/b60b462c042d432c9271a107010a9671#b60b462c042d432c9271a107010a9671</link>
		<pubDate>Mon, 12 Nov 2012 16:10:36 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/b60b462c042d432c9271a107010a9671#b60b462c042d432c9271a107010a9671</guid>
		<dc:creator>Sven Groot</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Sven Groot/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p>The only future proof device is a rock.</p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/4117451e23aa4897a6f5a107010aab01#4117451e23aa4897a6f5a107010aab01</link>
		<pubDate>Mon, 12 Nov 2012 16:10:54 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/4117451e23aa4897a6f5a107010aab01#4117451e23aa4897a6f5a107010aab01</guid>
		<dc:creator>ScanIAm</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/ScanIAm/Discussions/RSS</wfw:commentRss>
	</item>
	<item>
		<title>Coffeehouse - security patch win8</title>
		<description><![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Post Permalink" href="/Forums/Coffeehouse/security-patch-win8/4117451e23aa4897a6f5a107010aab01">30 minutes&nbsp;ago</a>, <a href="/Niners/ScanIAm">ScanIAm</a> wrote</p><p>The only future proof device is a rock.</p><p></p></div></blockquote><p></p><p>Yep. That's city building 101 <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /></p>]]></description>
		<link>http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/522453b6e1194e6cadd2a10701132da3#522453b6e1194e6cadd2a10701132da3</link>
		<pubDate>Mon, 12 Nov 2012 16:41:53 GMT</pubDate>
		<guid isPermaLink="false">http://channel9.msdn.com/Forums/Coffeehouse/security-patch-win8/522453b6e1194e6cadd2a10701132da3#522453b6e1194e6cadd2a10701132da3</guid>
		<dc:creator>Blue Ink</dc:creator>
		<slash:comments>16</slash:comments>
		<wfw:commentRss>http://channel9.msdn.com/Niners/Blue Ink/Discussions/RSS</wfw:commentRss>
	</item>
</channel>
</rss>