Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Latest News
    • Reviews

    Time, Money and the Lies Others Tell You

    Written by

    Andrew Garcia
    Published January 9, 2008
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Securitywatch’s Ryan Naraine notes that new Secunia users are finding their computers insecure, as applications have fallen out of date. As a Secunia user, I can say there are a lot of causes for my inability to keep my primary system up-to-date (by Secunia’s standards).

      For instance, on my work PC at this moment, Secunia’s PSI is telling me that I currently have four insecure applications, one end-of-life application with 76 up-to-date apps. Better than most, but hardly perfect. Five of 81 are not secure– a 6.2 percent failure rate.

      Basically, I can be hacked via known vulnerabilities.

      Of the four vulnerable applications, two are Adobe Flash. I’ve tried upgrading to the latest version. I’ve tried uninstalling, then reinstalling. I’ve tried uninstalling completely. None of these steps have gotten PSI to recognize any difference. I guess I can figure out how to manually remove Flash for good–but it may be a lot of work.

      Another vulnerable application is my anti-virus program. Work provides and manages this software, so there’s not much I can do (other than badgering IT, and I am sure they are sick of my badgering) unless I decide to fully manage my own AV solution. Looking through the release notes of the current and recent iterations of the software, there are no mentions of patched vulnerabilities jumping out at me. Lots of bug fixes and improvements, but maybe not any plugged security holes. But the free version of PSI does not make that distinction.

      The other vulnerable application is QuickTime. I’ve got QuickTime Player installed because I need iTunes to sync my iPhone to my Outlook calendar. I‘ve covered my dismay with this setup plenty in the past, but it is the only reliable way I’ve been able to sync the data I need.

      When I upgraded to iTunes 7.5, the installation package included QuickTime 7.3. Since then, QuickTime moved to 7.3.1, but iTunes stayed at 7.5. So the Apple Software Update application tells me I am up-to-date, but a check of the QuickTime Web site tells me I am ever so slightly behind.

      Essentially, one of the many tools I am forced to rely on to keep my system up-to-date is lying to me.

      The end of life program is a prior version of WinZip. I guess my company actually paid for the WinZip license. (I never see that annoying expiration notice on this PC.) I can see why the company may not want to pay for the new version, since the old one does everything that our users want it to do, presumably. But to get security updates, we’re beholden to pay for licensing upgrades to get the new version, chock full of features we don’t need?

      Yes, of course. This is one of the costs of security that everyone must face. But personally, this case is out of my hands. Or I suppose I could install the latest WinRAR.

      Secunia’s PSI is a means to an end. People downloading these kinds of tools are presumably wanting to check their status, likely knowing something is out of date. So they can fix it–if they are allowed to, and it is relatively easy.

      Given the Apple and WinZip anecdotes above, I’d say perhaps the numbers Ryan notes are really a larger indictment of the software makers and their crappy update applications and up-sell tactics used in the name of security.

      Andrew Garcia
      Andrew Garcia
      Andrew cut his teeth as a systems administrator at the University of California, learning the ins and outs of server migration, Windows desktop management, Unix and Novell administration. After a tour of duty as a team leader for PC Magazine's Labs, Andrew turned to system integration - providing network, server, and desktop consulting services for small businesses throughout the Bay Area. With eWEEK Labs since 2003, Andrew concentrates on wireless networking technologies while moonlighting with Microsoft Windows, mobile devices and management, and unified communications. He produces product reviews, technology analysis and opinion pieces for eWEEK.com, eWEEK magazine, and the Labs' Release Notes blog. Follow Andrew on Twitter at andrewrgarcia, or reach him by email at agarcia@eweek.com.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×