ANTenna Blog -- Hardware & Software
Why Are Software Updates Such A Pain In The Butt?
Posted by Matthew McKenzie Friday, Sep 18, 2009, 11:08 AM ET
Some recent Mozilla stats go a long way towards explaining a major problem with desktop software security. But maybe they don't go far enough.
Last week, Mozilla issued its latest set of Firefox browser updates. When the company notified users, it also alerted those running an outdated, and potentially dangerous, version of Adobe Flash. According to a Channel Register article, the results were not encouraging:
Of the 6 million or so people who upgraded to either 3.5.3 or 3.0.14 of Firefox on its debut last Thursday, slightly more than 3 million of them were found to be running an outdated Flash version, according to Mozilla's Ken Kovash. Sadly, only about 35 percent of those informed they had an insecure installation clicked on a link to upgrade to the latest version.
That suggests that some 2 million Firefox users remained vulnerable to remote exploit attacks even after Mozilla presented them with a warning that said "your current version of Flash Player can cause security and stability issues" and added "you should update Adobe Flash Player right now."
There is some good news here: According to Mozilla, the 30 percent click-through rate for the Flash update link was six times higher than the usual number who follow through on such alerts. Those figures, however, still leave millions of Firefox users running a version of Flash that could expose them to very serious security risks.
Why are do so many users, in spite of these warnings, leave their systems vulnerable to such exploits? I think a few other problems play a role here:
- Bloatware fatigue. Adobe, like so many other software vendors, appears to be more interested in pushing users towards major new releases than in keeping them secure with strict quality control and prompt, incremental bug-fix updates. And Adobe, like so many other vendors, loves to pack its new releases with dubious "improvements" that impose a noticeable performance hit on users' systems. Many of us, given the choice, decide to take our chances with the current version.
- Paranoia. How many of us have seen popup boxes that scream warnings at us about malware, security holes, and dire risk to life and limb? How many of those popups are actually attempts to trick users into installing malware? At this point, such ploys are so common, and so potentially damaging, that users assume -- not without good reason -- they should avoid installing unsolicited "updates" no matter who recommends them.
But maybe the biggest problem here involves the process or checking for and installing software updates on a Windows PC. Or perhaps I should say the lack of a process.
Microsoft, of course, alerts users to patches and software updates on a weekly basis. With very few exceptions, these updates deal only with the Windows OS and integrated applications such as Internet Explorer.
Most other desktop applications offer their own, completely independent, software update alerts. Some of these only work when a user starts the application and actually checks for updates; others install updaters that start up with the user's system. The former are often not very effective, for obvious reasons. The latter tend to pile up, one at a time, until the cumulative weight of this nagware drives users to disable them en masse.
An alternative approach to software update management does exist. Once you try it, you'll wonder why Windows users don't take this problem far more seriously.
Most Linux distros provide desktop software through online repositories. These provide one-stop shopping for a huge number of applications, drivers and system utilities. They also provide a single point of access for software updates and security patches.
Keep in mind that while some repositories contain only free and open-source software, others are less restrictive. Ubuntu, for example, maintains four sub-repositories that divide available software based upon its open-source status and whether Canonical provides support. The Ubuntu "universe" repository includes third-party software distributed under more restrictive licenses -- including Adobe Flash and Reader.
While it is up to the software developer, and not Canonical, to provide security fixes and support for such software, the repository offers a quick and easy way to install updates as soon as they become available. A Linux desktop system will check the repository on a regular basis; when updates are available for installed applications, it will either alert the user or, if desired, install the updates automatically.
Not every desktop Linux application is installed from a repository, but the vast majority are. And while some distros' repositories are better than others at keeping software updates as current as possible, most of them do a pretty good job.
Actually, they do a fantastic job compared to the spotty, inconsistent, hit-or-miss approach that Windows users are forced to accept.
Software update management does not make or break a company's desktop OS decision. But if the process of staying one step ahead of the latest desktop software exploits is turning into more trouble than it's worth, then I think you have one more very good reason to try desktop Linux.
Hardware & Software
Company Size: 1-49
| Linux
| Open Source
| Security
This is a public forum. CMP Media and its affiliates are not responsible for and do not control what is posted herein. CMP Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.
Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of CMP Media LLC and may be edited and republished in print or electronic format as outlined in CMP Media's Terms of Service.
Important Note: This comment area is NOT intended for commercial messages or solicitations of business.
- Phone Systems Guide - What kind of phone system is right for your business
- Web Design Guide - What to look for in a Web designer
- Merchant Services Guide - Credit card processing and more
- Online Marketing Guide - Leverage the Net to market your business
- Alternative Financing Guide - How to find the cash your business needs
- View all guides
Explore ANTenna Blog
Most Recent Posts
- Twilight's Latest Hacking: Vampire Byte Scam Targets Stephanie Meyer Fans
- Great Tips For Getting The Most Out Of Ubuntu Linux
- SAN Vs. NAS: From No Contest To Fair Fight?
- Quark Promote Enters Web-To-Print Market
- Yes, Virginia -- There IS A Google Phone
ANTenna Blog Topics
- Apple
- Backup
- bMighty
- Business & E-Business
- Business Continuity
- Cloud Computing
- Company Size: 1,100-1,500
- Company Size: 250-999
- Company Size: 50-249
- Company Size: 1-49
- Disaster Recovery
- Economics
- Education
- Entrepreneurs
- Finance/Accounting
- Finance/Banking/Insurance
- Government
- Green Business
- Hardware & Software
- Healthcare
- Hospitality
- How-To
- HR
- Imaging How-To
- International
- Internet/Web
- iPhone
- IT
- Linux
- Management
- Manufacturing/Mining
- Messaging
- Mobile
- Networking & Communications
- Non-Profit
- Open Source
- Operations
- Piracy
- Printers/Printing
- Professional/Creative Services
- Retail
- Unified Communications
- Sales/Marketing
- Start-Ups
- Security
- Server How-To
- Services
- Social Networking
- Software-as-a-Service
- Storage
- Strategy/Analysis/Biz Dev
- Technology/Telecom
- The rANT
- Transportation
- Travel
- Windows
- Web 2.0
- Women in Business
ANTenna Bloggers
ANTenna Blog Roll
- ANTenna Archive
- Ars Technica
- Business Know-How
- ChannelWeb Hot Topics
- ChannelWeb The Chart
- Datamation
- Duct Tape Marketing
- The Entrepreneurial Mind
- Freakonomics
- GigaOmNet
- Guy Kawasaki
- Inc.com
- IT Organization Management
- IT Manager's Journal
- IT Toolbox
- LifeHacker
- Mashable
- MonkeyBrains
- Network Computing Blog
- Scott Berkun
- Search Engine Land
- Search Engine Watch
- SmallBizResource
- SmallBizTechnology.com
- SmallBusinessHub
- Small Business Trends
- TechCrunch
- Technologizer
- Tech Republic
- The Secret Diary of Steve Jobs
- USA Today Small Biz Connection
- Valleywag
- Walt Mossberg Feed - All Things Digital
- Web Worker Daily
- WorkHappy.net
- WSJ's Business Technology
bMighty email newsletter!
Browse by Category
bMighty Tech
Term Of Day:
Boost your tech
vocabulary!
bMighty's SMB
TechEncyclopedia
defines more than
20,000 IT terms.
FREE Technology Services Locator!
Search our database of 200,000 solution- provider locations by business activity, technology, vertical market, and customer size. Find a technology partner NOW.
go



