<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Krebs on Security &#187; thomas kristensen</title>
	<atom:link href="http://krebsonsecurity.com/tag/thomas-kristensen/feed/" rel="self" type="application/rss+xml" />
	<link>http://krebsonsecurity.com</link>
	<description>In-depth security news and investigation</description>
	<lastBuildDate>Thu, 09 Feb 2012 22:39:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Yep, There&#8217;s a Patch for That</title>
		<link>http://krebsonsecurity.com/2010/03/yep-theres-a-patch-for-that/</link>
		<comments>http://krebsonsecurity.com/2010/03/yep-theres-a-patch-for-that/#comments</comments>
		<pubDate>Fri, 05 Mar 2010 05:16:53 +0000</pubDate>
		<dc:creator>BrianKrebs</dc:creator>
				<category><![CDATA[Time to Patch]]></category>
		<category><![CDATA[patch madness]]></category>
		<category><![CDATA[secunia]]></category>
		<category><![CDATA[stefan frei]]></category>
		<category><![CDATA[thomas kristensen]]></category>

		<guid isPermaLink="false">http://www.krebsonsecurity.com/?p=1463</guid>
		<description><![CDATA[The average Microsoft Windows user has software from 22 vendors on her PC, and needs to install a new security update roughly every five days in order to use these programs safely, according to an insightful new study released this week. The figures come from security research firm Secunia, which looked at data gathered from [...]]]></description>
			<content:encoded><![CDATA[
<div class="topsy_widget_data topsy_theme_silver" style="float: left;margin-right: 0.75em; background: url(data:,%7B%20%22url%22%3A%20%22http%253A%252F%252Fkrebsonsecurity.com%252F2010%252F03%252Fyep-theres-a-patch-for-that%252F%22%2C%20%22style%22%3A%20%22big%22%2C%20%22title%22%3A%20%22Yep%2C%20There%27s%20a%20Patch%20for%20That%22%20%7D);"></div>
<p>The average <strong>Microsoft Windows</strong> user has software from 22 vendors on her PC, and needs to install a new security update roughly every five days in order to use these programs safely, according to an insightful new study released this week.</p>
<p>The figures come from security research firm <strong>Secunia</strong>, which looked at data gathered from more than two million users of its free Personal Software Inspector tool. The PSI is designed to alert users about outdated and insecure software that may be running on their machines, and it is an excellent application that I have recommended on several occasions.</p>
<p><strong>Stefan Frei</strong>, Secunia&#8217;s research analyst director, said the company found that about 50 percent of PSI users have more than 66 programs of installed.</p>
<p>&#8220;Those programs come from more than 22 vendors, so as a first order estimate the number of different vendors you have on your box is the number of different update mechanisms you have to master,&#8221; Frei said. &#8220;This is doomed to fail.&#8221;</p>
<p><span id="more-1463"></span></p>
<p>Secunia chief security officer <strong>Thomas Kristensen</strong> said his company is just a few months away from releasing a free, new tool that will <a href="http://secunia.com/blog/80/" target="_blank">automate the installation of software updates</a> for dozens of commonly-installed third party programs. Kristensen said the tool will allow users to exclude certain applications, in the event that they don&#8217;t want to automatically update specific programs.</p>
<p>Such an application, if done right, broadly adopted, and not resisted by third-party software vendors, could well reduce the number of Windows users whose machines get trashed by <a href="http://www.krebsonsecurity.com/2010/02/blade-hacking-away-at-drive-by-downloads/" target="_blank">drive-by downloads</a>, as all of these malicious or hacked sites try to silently install malware by targeting security holes in third-party software, such as <strong>Flash</strong> and <strong>Adobe Reader</strong>.</p>
<p>If I seem excited about the availability of a free meta-patching tool, it&#8217;s probably partly for selfish reasons. Such a tool would almost certainly spell relief for anyone who is unlucky enough to be the appointed tech support guy for their family and friends, since fewer vulnerable applications means fewer compromised PCs, and hopefully less frequent pitiful pleas for help.</p>
<p>A copy of the Secunia study is available <a href="http://secunia.com/gfx/pdf/Secunia_RSA_Software_Portfolio_Security_Exposure.pdf" target="_blank">here</a> (.pdf)</p>

]]></content:encoded>
			<wfw:commentRss>http://krebsonsecurity.com/2010/03/yep-theres-a-patch-for-that/feed/</wfw:commentRss>
		<slash:comments>61</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached (User agent is rejected)
Database Caching 1/14 queries in 0.006 seconds using memcached
Object Caching 355/372 objects using memcached

Served from: krebsonsecurity.com @ 2012-02-11 21:56:09 -->
