Should Adobe auto-update Flash and PDF Reader?
By Asavin Wattanajantra,
Adobe needs to find a way to make sure that all of the users of its software are updated automatically, according to a leading security researcher.
Mikko Hypponen, chief security researcher for F-Secure, said that users were not typically found vulnerable through their operating systems, but rather through plugins and add-ons found inside internet browsers.
This means software such as Adobe PDF Reader and Flash, Java or Quicktime. While Windows is updated automatically, these are still left unpatched and therefore vulnerable to new exploits.
This is especially dangerous as Adobe Flash has a bigger market share than even Windows, and Mac and Linux users often had it on their systems. Of these users, 80 per cent ran old Flash.
It is also problematic that users aren't required to click on a Flash or PDF file, as you can get infected by simply browsing a website.
“That’s the way that attackers gain way, and if you look at the market share of things like Adobe Flash or the PDF reader plugin, they are huge," said Hyponnen.
“Most of them are not up to date. Microsoft can do this, so Adobe should be able to do this as well.”
Security exploits against QuickTime plugins were also an issue, which users often didn’t install but found in their systems.
“It’s because I have an iPod,” Hyponnen said. “And because I have an iPod I have to install iTunes. When I install it will, without asking me, install QuickTime automatically."
QuickTime automatically installs a plugin inside a web browser, which means that if there is a flaw, it could be exploited.
“I’m not concerned with updating QuickTime. I’ve never even installed it,” he added.
Adobe had not responded to request for comment at the time of publication.
You may also like...
advertisement
Latest Industry & Public Sector Features
What impact will the browser ballot screen have?
The browser ballot screen is rolling out across Windows Update. Simon Brew charts its problems, the road to here, and what impact it’s likely to have.
- Q&A: Mark Kingdon on Second Life for business
- Q&A: The ID card commissioner talks cards and controversy
- The past, present and future of the Digital Economy Bill
- Google’s fight for its book deal
- MWC 2010: Top 10 show tech
- FreeBSD and the GPL
- Top 10 technologies for SMBs
- How much is space worth to Britain?
- Smartphones vs netbooks vs tablets - which is best for you?
Latest Industry & Public Sector Reviews
NEC MultiSync LCD4215 review
Rating: ![]()
advertisement
Most popular
- App market will be worth $17.5 billion by 2012
- Open source developers ditch iPhone for Android
- Report: Macs cost less to run than Windows PCs
- Why is Microsoft accelerating Service Pack 1?
- Head to Head: Office 2010 vs Open Office 3.1
- Symantec Backup Exec 2010 review
- Q&A: Conrad Wolfram on communicating with apps in Web 3.0
- Fraudsters focus on ID theft, not stealing cash
- Google Nexus One review: A week with the superphone
- HTC Legend review
Latest News Videos in Industry & Public Sector
Video: What a connected classroom looks like
Dell unveils its vision for the classroom of the future, with netbooks, video conferencing and pub quiz-style handsets.
Whitepapers
Want more background on today's hottest IT trends?
Visit IT PRO's whitepaper library for more on virtualisation, encryption and other topics.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.






