Welcome to MSDN Blogs Sign in | Join | Help

Michael Howard's Web Log

A Simple Software Security Guy at Microsoft!
Insecure 3rd party software updaters
Gotta love Robert's sarcasm.. but he's right.
Posted: Tuesday, July 29, 2008 12:51 PM by michael_HOWARD
Filed under:

Comments

Marc said:

And you should blame Microsoft to not open auto-updates to other products than Microsoft ones.

Why isn't Winzip (I do not speak about competing products like OpenOffice) allowed to use a secure and robust update mechanism instead of using a home made one ?

Responsibility is not an answer; we are used to click on disclaimers when installing stuff, aren't we. One more disclaimer to accept an update from an "untrusted" (read non MS) source wouldn't be a problem.

# July 30, 2008 7:04 AM

Marc said:

And you should blame Microsoft to not open auto-updates to other products than Microsoft ones.

Why isn't Winzip (I do not speak about competing products like OpenOffice) allowed to use a secure and robust update mechanism instead of using a home made one ?

Responsibility is not an answer; we are used to click on disclaimers when installing stuff, aren't we. One more disclaimer to accept an update from an "untrusted" (read non MS) source wouldn't be a problem.

# July 31, 2008 5:36 AM

securology said:

Hmm.  Robert may be correct, but digital signatures by themselves do not make a secure update mechanism, unless there is a time-bound sensitivity associated with the signatures (and it would have to be a very finite amount of time at that).  Read more <a href="http://securology.blogspot.com/2008/08/package-managers.html">here</a>.

# August 9, 2008 9:46 AM
New Comments to this post are disabled
Page view tracker