Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

4/21/2009
08:52 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Secunia Pushes For Standard That Updates Consumer Apps

Danish security firm asks software vendors to help build common application that handles all third-party application updates and patching

SAN FRANCISCO -- RSA CONFERENCE 2009 -- Danish security firm Secunia is attempting to rally other software vendors to develop an industry-standard tool that automatically updates all applications on a consumer's PC.

Niels Henrik Rasmussen, CEO of Secunia, says it's time the industry built a common application that handles all third-party application updates and patching, rather than the separate, piecemeal approach used today.

Secunia points to new data from Microsoft's Security Incident Report, which revealed that 90 percent of vulnerabilities on Windows machines are in third-party applications. And many third-party application firms don't educate or alert consumers about security updates and how to install them, according to Secunia.

"I would not hesitate to say that the biggest threat to your PC probably is a program you installed yourself, simply because it is out of date and insecure," says Thomas Kristensen, CTO of Secunia, here at the RSA Conference. "Many software companies fail to properly inform their users about new security updates and how to apply them after you installed their software."

Secunia's Rasmussen says he's meeting with software vendors here this week to invite them to address this problem. Secunia is offering its Personal Software Inspector (PSI) tool, which handles updates on 7,000 different third-party applications, as a foundation for building out an integrated application for updating all of these apps. Rasmussen says Secunia would like the software community to take the solution to the next level, but the final product may or may not look anything like PSI, he says.

"We need one application that handles everything," Rasmussen says. "We're offering our technology, but it could [ultimately] be something completely different."

Secunia envisions an industry-standard app that runs when a laptop starts up, for example, scanning for unpatched or vulnerable apps and guiding the user with simple point-and-click options to update the machine. "Patching is not rocket science. Why hasn't [the industry] done this before?" says Rasmussen, who notes that Secunia would rather the industry take responsibility for fixing this problem than continue to invest in the development of its PSI tool to do so. Whether vendors will be willing to join Secunia in the effort is unclear. But if Secunia can't get vendors to commit to the project, Rasmussen says the company will go at it alone. "It's in the interest of the community to do this, and it makes sense," he says. "If they won't do it, we will."

Meanwhile, Secunia also announced here that it is offering U.S. financial institutions Online Software Inspector -- a tool it has been selling in Europe for securing online banking customers' systems. The software automatically scans a banking customer's machine for unpatched or vulnerable software when he or she logs into the online banking app.

"Patching third-party software is probably the most important thing a private user can do in relation to his or her IT security," says Mikkel Winther, partner manager at Secunia. "Many banks already have requirements about browser versions, operating systems, and service pack levels, but since the majority of attacks use third-party applications, this is where the banks should focus. This is where the lowest-hanging fruit is found."

Winther says the software will be priced around $1 per online banking customer user, and will include volume discounts. "It provides banks the real-time security situation of these users," he says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message. Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19551
PUBLISHED: 2019-12-06
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the User Management screen of the Administrator web site. An attacker with access to the User Control Panel application can submit malicious values in some of the time/date formatting and time-zone fields. These fields are not b...
CVE-2019-19552
PUBLISHED: 2019-12-06
In userman 13.0.76.43 through 15.0.20 in Sangoma FreePBX, XSS exists in the user management screen of the Administrator web site, i.e., the/admin/config.php?display=userman URI. An attacker with sufficient privileges can edit the Display Name of a user and embed malicious XSS code. When another user...
CVE-2019-19620
PUBLISHED: 2019-12-06
In SecureWorks Red Cloak Windows Agent before 2.0.7.9, a local user can bypass the generation of telemetry alerts by removing NT AUTHORITY\SYSTEM permissions from a malicious file.
CVE-2019-19625
PUBLISHED: 2019-12-06
SROS 2 0.8.1 (which provides the tools that generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2) leaks node information due to a leaky default configuration as indicated in the policy/defaults/dds/governance.xml document.
CVE-2019-19627
PUBLISHED: 2019-12-06
SROS 2 0.8.1 (after CVE-2019-19625 is mitigated) leaks ROS 2 node-related information regardless of the rtps_protection_kind configuration. (SROS2 provides the tools to generate and distribute keys for Robot Operating System 2 and uses the underlying security plugins of DDS from ROS 2.)