# Security patch for Outlook -- why bother?

**URL:** https://boards.straightdope.com/t/security-patch-for-outlook-why-bother/21368
**Category:** Great Debates
**Created:** [June 4, 2000, 3:27pm UTC](https://boards.straightdope.com/t/security-patch-for-outlook-why-bother/21368 "2000-06-04T15:27:34Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Akatsukami](https://avatars.discourse-cdn.com/v4/letter/a/ea666f/32.png) [@Akatsukami](https://boards.straightdope.com/u/Akatsukami)
#### Post date: [June 4, 2000, 3:27pm UTC](https://boards.straightdope.com/t/security-patch-for-outlook-why-bother/21368/1 "2000-06-04T15:27:34Z")

</div>

Tom Syroid of [Syroid Manor](http://www.syroidmanor.com/syroid/) wrote on his Insights page for the week of 22 May 2000:

> [@](#):
>
> Speaking of Outlook, recent reports indicate that MS has delayed the announced security patch [to block malware like the “Love Bug” from infecting and propagating] until “sometime the week of June 6”. Apparently, outcries from the user community have reached some listening ears in Redmond and they’re rethinking initial plans to “smash anything that moves with a large hammer”. Early reports indicated that engineers were designing the patch with hard-coding that would forcibly deny users any access whatsoever to _.exe_ or _.vbs_ file attachments, and make it near impossible (or at the very least, enormously inconvenient) for external applications like Palm’s HotSync to gain access to Outlook’s address book. Back-peddling is in progress. As I understand it, the user will now actually be able to configure the patch to selectively include/exclude programs and file extensions from the “no-way” list. Imagine that. Letting users actually configure the software they bought and paid for.

Now, the consensus (at least on the SDMB) seems to have been that the revised patch will be almost totally useless, as:  
[ul]  
[li]The overwhelming majority of users will not bother to learn how to configure the software[/li][li]The users who _will_ learn how to configure the software generally know better than to blindly run executables from unknown sources[/li][li]Corporate users with sufficient clout who find the patch inconvenient will order their tech support teams to disable security[/li][li]Other users who find the patch inconvenient will complain to tech support at the retailers/distributors/etc. until someone tells them how to disable security[/li][li]Anyone (or at least very, very, few) who disables security will never bother to enable it again.[/li][/ul]  
Does this seem to be a fair summarization of opinion?

---

<div class="post-metadata">

### Author: ![Duck\_Duck\_Goose](https://avatars.discourse-cdn.com/v4/letter/d/50afbb/32.png) [@Duck\_Duck\_Goose](https://boards.straightdope.com/u/Duck_Duck_Goose)
#### Post date: [June 4, 2000, 5:38pm UTC](https://boards.straightdope.com/t/security-patch-for-outlook-why-bother/21368/2 "2000-06-04T17:38:54Z")

</div>

I’m not a tech person, but it sounds an awful lot like Microsoft’s out there nailing the barn door shut several weeks after the horse was stolen. “Look! We’re making sure this will NEVER HAPPEN AGAIN! Aren’t you proud of us? Please buy more of our software! Especially you big-time corporate users with large budgets!”

I don’t remember what the exact numbers were, but I think I read somewhere that Microsoft gets a lot of their software income from big corporate accounts, with custom-designed software. Joe Blow from Kokomo, who gets his Win98 upgrade down at Best Buy, is only a drop in the bucket.
