Showing posts with label update. Show all posts
Showing posts with label update. Show all posts

Thursday, July 13, 2023

The patches that never end

from here and here

Maybe you thought Internet Explorer would be ancient history by now, but unfortunately Microsoft is still making security updates for it.

Thursday, April 20, 2023

It'd be a shame if your flying computer crashed

from here and here

Apparently military helicopters are now just computers that happen to fly, and if you don't apply patches you're asking for trouble.

Wednesday, March 15, 2023

A digital snow day

from here and here

I imagine if you can still get Internet on your phone, a digital snow day while you wait for 83 patches to be applied to your PC might actually be a good thing. No work and all play. It's almost enough to make me wish I had a phone.

Wednesday, March 8, 2023

Too many attack surfaces, not enough hours

from here and here

The idea that you can be secure if you just keep everything up to date ignores how many things need to be kept up to date and how much more difficult it is for some things than others. So when people go around installing malware on routers there's a pretty good chance there won't be anything standing in their way most of the time.

Monday, February 27, 2023

Key In Absentia

from here and here

If Kia and Hyundai can put an end to the Kia Challenge with a software update, the question I have is why didn't they do it sooner? You know, before people died.

Friday, February 17, 2023

Give yourself to the update

from here and here

It's the update we've all been waiting for. The one that removes Internet Explorer.

Friday, December 30, 2022

Ask your lawyer if being lazy is right for you

from here and here

Well, this is an interesting development. Albanian IT staff get charged with negligence after a (supposedly) preventable cyberattack that they failed to prevent. Now, if it was really management's fault that things weren't kept up to date then I hope that comes out at trial and that the people who were really responsible are held accountable. This kind of legal action, combined with the uncertain future of cyber-insurance might just force businesses and organizations to finally start ponying up the funds to do security right. Or the decision-makers will find some other way to avoid accountability for not paying what should be the cost of doing business.

Tuesday, December 20, 2022

Maybe later

from here and here

I think the people who make updates need to put more thought into the user experience of applying updates. Otherwise the updates are just going to get delayed over and over again.

Wednesday, November 9, 2022

Maybe they have too many products

from here and here

Look, I know all software needs to be patched on occasion, and I know it's better that it gets patched than if it doesn't, but there are just soooooo many Microsoft patches! I can't be the only person who tires of hearing about them.

Wednesday, September 28, 2022

The future will be out of date

from here and here

The Internet of Things is going to be unmanageable if we keep building it out of general purpose computers.  If we must have smart devices, we should use special purpose computers with fixed, first order functionality. Not only would updates not be necessary, they wouldn't be possible.

One of the main reasons we use general purpose computers is because their generality allows us to use the same computer for pretty much any application, so we can benefit from an economy of scale by mass producing lots of them knowing we'll find a use for them. I think it might be possible to get similar benefits from special purpose computers used to build a set of fundamental controls - there are only a relatively small number of ways we control the devices around us (ex. toggle switches, dials, etc) and since each of those fundamental control types would be common across a number of different devices, a smaller economy of scale could still be achieved with special purpose computers that drive such controls but with the benefit of lower maintenance than can be achieved with general purpose computers.

You'd never be able to build a toaster that sings to you that way, but why would you want to?

Tuesday, September 6, 2022

It's now safe to turn off your lights

from here and here

I've seen this template so many times but finally we have an explanation for why the lights are still on.

Friday, August 19, 2022

A bug so nice they patched it twice

from here and here

If you have Zoom then you better get patching, again. The patch from earlier this week wasn't good enough but now they've got it for sure this time, honest. 

Wednesday, August 10, 2022

Attacks need to be kept up to date too

found on Izismile

I think the youth of today know better than to get into a strange van for some free candy. Funny pictures, on the other hand, might not trigger the same suspicion since it wasn't explicitly drilled into anyone's head.

Tuesday, June 21, 2022

No longer the best browser for downloading other browsers

from here and here (image source)

Internet Explorer is finally dead, sort of. There won't be any more updates so you better get rid of it, but the underlying engine is still embedded in the operating system and Edge will still use the IE rendering engine for it's IE mode for many years to come.

Wednesday, May 4, 2022

You're gonna need those hotfixes eventually

from here and here

You may think this is fine, but sooner or later you're gonna get burned.

Monday, September 13, 2021

OldYeller.exe has stopped working

found on Izismile

Yet another reason for people to be wary of or dislike updates. With "improvements" like that, who needs malware?

Friday, August 27, 2021

Security through nagging

found on Dump A Day

Just like there is no security through obscurity, there's no security through nagging either. If nagging worked, you'd still have the option to opt out of windows update.

Tuesday, May 25, 2021

Looks like everything is vulnerable, again

from here and here

Apparently billions of devices are vulnerable to a series of wifi vulnerabilities, and if you thought bitcoin consumed a lot of energy, just imagine how much would be used applying updates to billions of devices.

Friday, April 30, 2021

How much faith do you have in technoloogy?

found on Reddit

You're supposed to update the BIOS, but how many people actually do?

"Not many" would be my guess. In spite of the fact that they eliminate known bugs and vulnerabilities, few people want to take the chance that the update will brick their computer. That's a lot harder to fix with a BIOS update than it is with a Windows update.

Tuesday, January 5, 2021

How do you "accidentally" add hard-coded credentials?

from here and here

Believe me, I can imagine how this backdoor got added to the Zyxel firmware. In theory they may be developing the firmware with the built-in account for testing purposes and then they remove or disable that code in the final build that they intend for release. But if that's what they're doing then this mistake begs to happen over and over again.

Maybe they should make a product that's testable in it's final releasable form instead.