|
|
This topic comprises 2 pages: 1 2
|
|
Author
|
Topic: What the Hell is with Microsoft Update?
|
|
|
|
|
Frank Angel
Film God

Posts: 5305
From: Brooklyn NY USA
Registered: Dec 1999
|
posted 05-02-2016 02:11 AM
I have what might be a stupid question, but one which so far I have not gotten a satisfactory answer to: these companies that install update paths to your PC that is running their software, e.g., Adobe, Brother, HP, Oracle, and on and on, they seem to have a direct access or "in" to the PC by way of those popups that say they have updates for you to install.
Everyone knows of the admonitions to not open unknown links or not to click on that email invite, but there doesn't seem to be any serious worry about that popup that says "your HP LaserJet needs to be updated...click to install."
My question is, how do you know who is on the other end of that request to allow an update? Why do we assume that it is in, fact, HP or Brother or MS or whomever? Seems like that would be the FIRST place a hacker would try to attack to install a trojan, disguising himself as a trusted company, one the user is already disposed to agree to without giving it a second thought; no one says, wait a minute, how do I know this is HP requesting permission to install stuff on my PC? Why couldn't it just as easily be someone who has hacked the port that HP seems to have such easy access to and is about to install disastrous malware instead of a printer update? How is this route to the taskbar dialog icons protected? You KNOW 90% of all PC owners are going to click on OK for those requests without question. This seems like a super high risk issue.
| IP: Logged
|
|
Bill Brandenstein
Master Film Handler
Posts: 413
From: Santa Clarita, CA
Registered: Jul 2013
|
posted 05-02-2016 10:04 PM
I think that's a really great question, and my answer will be a lot less definitive than someone who's expertise lies in computer security.
The main reason it's safe is because the update happens through dedicated processes created by each software company. These are installed when you initially put the software on your computer. Most importantly, it appears that the installed software, process, and remote server all have to handshake on an update before it proceeds.
You can see the evidence of this by opening Task Manager, opening the Processes tab, and (as administrator) clicking at the bottom for showing processes from all users. Among the dozens of pieces of gobbletygook there, you're likely to see update processes for Adobe, Apple, Java, HP, and who knows what else.
If these were easy to exploit, believe me, they would be. You know that.
| IP: Logged
|
|
|
|
All times are Central (GMT -6:00)
|
This topic comprises 2 pages: 1 2
|
Powered by Infopop Corporation
UBB.classicTM
6.3.1.2
The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion
and agrees to release the authors from any and all liability.
|