Risk
4/21/2009
08:52 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Secunia Pushes For Standard That Updates Consumer Apps

Danish security firm asks software vendors to help build common application that handles all third-party application updates and patching

SAN FRANCISCO -- RSA CONFERENCE 2009 -- Danish security firm Secunia is attempting to rally other software vendors to develop an industry-standard tool that automatically updates all applications on a consumer's PC.

Niels Henrik Rasmussen, CEO of Secunia, says it's time the industry built a common application that handles all third-party application updates and patching, rather than the separate, piecemeal approach used today.

Secunia points to new data from Microsoft's Security Incident Report, which revealed that 90 percent of vulnerabilities on Windows machines are in third-party applications. And many third-party application firms don't educate or alert consumers about security updates and how to install them, according to Secunia.

"I would not hesitate to say that the biggest threat to your PC probably is a program you installed yourself, simply because it is out of date and insecure," says Thomas Kristensen, CTO of Secunia, here at the RSA Conference. "Many software companies fail to properly inform their users about new security updates and how to apply them after you installed their software."

Secunia's Rasmussen says he's meeting with software vendors here this week to invite them to address this problem. Secunia is offering its Personal Software Inspector (PSI) tool, which handles updates on 7,000 different third-party applications, as a foundation for building out an integrated application for updating all of these apps. Rasmussen says Secunia would like the software community to take the solution to the next level, but the final product may or may not look anything like PSI, he says.

"We need one application that handles everything," Rasmussen says. "We're offering our technology, but it could [ultimately] be something completely different."

Secunia envisions an industry-standard app that runs when a laptop starts up, for example, scanning for unpatched or vulnerable apps and guiding the user with simple point-and-click options to update the machine. "Patching is not rocket science. Why hasn't [the industry] done this before?" says Rasmussen, who notes that Secunia would rather the industry take responsibility for fixing this problem than continue to invest in the development of its PSI tool to do so. Whether vendors will be willing to join Secunia in the effort is unclear. But if Secunia can't get vendors to commit to the project, Rasmussen says the company will go at it alone. "It's in the interest of the community to do this, and it makes sense," he says. "If they won't do it, we will."

Meanwhile, Secunia also announced here that it is offering U.S. financial institutions Online Software Inspector -- a tool it has been selling in Europe for securing online banking customers' systems. The software automatically scans a banking customer's machine for unpatched or vulnerable software when he or she logs into the online banking app.

"Patching third-party software is probably the most important thing a private user can do in relation to his or her IT security," says Mikkel Winther, partner manager at Secunia. "Many banks already have requirements about browser versions, operating systems, and service pack levels, but since the majority of attacks use third-party applications, this is where the banks should focus. This is where the lowest-hanging fruit is found."

Winther says the software will be priced around $1 per online banking customer user, and will include volume discounts. "It provides banks the real-time security situation of these users," he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7402
Published: 2014-12-17
Multiple unspecified vulnerabilities in request.c in c-icap 0.2.x allow remote attackers to cause a denial of service (crash) via a crafted ICAP request.

CVE-2014-5437
Published: 2014-12-17
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php,...

CVE-2014-5438
Published: 2014-12-17
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.

CVE-2014-7170
Published: 2014-12-17
Race condition in Puppet Server 0.2.0 allows local users to obtain sensitive information by accessing it in between package installation or upgrade and the start of the service.

CVE-2014-7285
Published: 2014-12-17
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to execute arbitrary OS commands by injecting command strings into unspecified PHP scripts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.