Risk
4/21/2009
08:52 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Secunia Pushes For Standard That Updates Consumer Apps

Danish security firm asks software vendors to help build common application that handles all third-party application updates and patching

SAN FRANCISCO -- RSA CONFERENCE 2009 -- Danish security firm Secunia is attempting to rally other software vendors to develop an industry-standard tool that automatically updates all applications on a consumer's PC.

Niels Henrik Rasmussen, CEO of Secunia, says it's time the industry built a common application that handles all third-party application updates and patching, rather than the separate, piecemeal approach used today.

Secunia points to new data from Microsoft's Security Incident Report, which revealed that 90 percent of vulnerabilities on Windows machines are in third-party applications. And many third-party application firms don't educate or alert consumers about security updates and how to install them, according to Secunia.

"I would not hesitate to say that the biggest threat to your PC probably is a program you installed yourself, simply because it is out of date and insecure," says Thomas Kristensen, CTO of Secunia, here at the RSA Conference. "Many software companies fail to properly inform their users about new security updates and how to apply them after you installed their software."

Secunia's Rasmussen says he's meeting with software vendors here this week to invite them to address this problem. Secunia is offering its Personal Software Inspector (PSI) tool, which handles updates on 7,000 different third-party applications, as a foundation for building out an integrated application for updating all of these apps. Rasmussen says Secunia would like the software community to take the solution to the next level, but the final product may or may not look anything like PSI, he says.

"We need one application that handles everything," Rasmussen says. "We're offering our technology, but it could [ultimately] be something completely different."

Secunia envisions an industry-standard app that runs when a laptop starts up, for example, scanning for unpatched or vulnerable apps and guiding the user with simple point-and-click options to update the machine. "Patching is not rocket science. Why hasn't [the industry] done this before?" says Rasmussen, who notes that Secunia would rather the industry take responsibility for fixing this problem than continue to invest in the development of its PSI tool to do so. Whether vendors will be willing to join Secunia in the effort is unclear. But if Secunia can't get vendors to commit to the project, Rasmussen says the company will go at it alone. "It's in the interest of the community to do this, and it makes sense," he says. "If they won't do it, we will."

Meanwhile, Secunia also announced here that it is offering U.S. financial institutions Online Software Inspector -- a tool it has been selling in Europe for securing online banking customers' systems. The software automatically scans a banking customer's machine for unpatched or vulnerable software when he or she logs into the online banking app.

"Patching third-party software is probably the most important thing a private user can do in relation to his or her IT security," says Mikkel Winther, partner manager at Secunia. "Many banks already have requirements about browser versions, operating systems, and service pack levels, but since the majority of attacks use third-party applications, this is where the banks should focus. This is where the lowest-hanging fruit is found."

Winther says the software will be priced around $1 per online banking customer user, and will include volume discounts. "It provides banks the real-time security situation of these users," he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-7839
Published: 2014-11-25
DocumentProvider in RESTEasy 2.3.7 and 3.0.9 does not configure the (1) external-general-entities or (2) external-parameter-entities features, which allows remote attackers to conduct XML external entity (XXE) attacks via unspecified vectors.

CVE-2014-8001
Published: 2014-11-25
Buffer overflow in decode.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

CVE-2014-8002
Published: 2014-11-25
Use-after-free vulnerability in decode_slice.cpp in Cisco OpenH264 1.2.0 and earlier allows remote attackers to execute arbitrary code via an encoded media file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?