Film-Tech Cinema Systems
Film-Tech Forum ARCHIVE


  
my profile | my password | search | faq & rules | forum home
  next oldest topic   next newest topic
» Film-Tech Forum ARCHIVE   » Operations   » Digital Cinema Forum   » Auto-update (Page 2)

 
This topic comprises 2 pages: 1  2 
 
Author Topic: Auto-update
Carsten Kurz
Film God

Posts: 4340
From: Cologne, NRW, Germany
Registered: Aug 2009


 - posted 10-09-2018 04:19 AM      Profile for Carsten Kurz   Email Carsten Kurz   Send New Private Message       Edit/Delete Post 
Having an automated update procedure is useless in the sense of the intention if it is NOT enabled by default. Those who care will and can disable it/opt-out if they feel it is necessary and have a strategy to keep an eye on these devices.

- Carsten

 |  IP: Logged

Marcel Birgelen
Film God

Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012


 - posted 10-09-2018 06:56 AM      Profile for Marcel Birgelen   Email Marcel Birgelen   Send New Private Message       Edit/Delete Post 
I don't necessarily agree on that one.

I manage quite a few machines with varying tasks. Those who act as backend infrastructure and are not exposed to the Internet, I'm certainly not deploying automatic updates on.

Whereas I also manage some virtualized Ubuntu and Windows workstations which I have enabled automatic updates on, simply because it's the lesser of two evils. Those machines are exposed to the Internet and I want them to be as patched as possible to withstand the common zero-day attacks that are out there as much as possible.

I certainly don't have the time and resources to vet all those updates and if an update might screw it, then it's an easy rollback to a previous snapshot, whereas on production backend machines, like a database machine, such a rollback would be potentially catastrophic.

But when I deploy something, I want to choose myself if the update process should be automatic or manual. A simple question during your setup wizard or a simple note in the initial setup instructions would be sufficient.

 |  IP: Logged

Bruce Cloutier
Expert Film Handler

Posts: 161
From: Gibsonia, PA, USA
Registered: Aug 2016


 - posted 10-09-2018 08:19 AM      Profile for Bruce Cloutier   Author's Homepage   Email Bruce Cloutier   Send New Private Message       Edit/Delete Post 
I think we would all agree that there are those who are comfortable with manufacturer's automatic updates and those who are dead set against it. Where you sit on that spectrum probably shifts from year to year. You can't decide if an update is good or bad until after it is done. We all hear about the disasters that get pushed out. We don't need to bicker about it. Skepticism in this case is always warranted.

INTEG hasn't considered automatic updates before as it had become our opinion that JNIORs in the cinema do not have access to the Internet. So an integrator needed to separately get an Update Project and once connected to the LAN (presumably through a secure VPN) or on-site run the Support Tool and update their JNIORs. That rarely happens unless a JNIOR encounters an issue.

The JNIOR is a very generic device and it is finding its way into more and more diverse applications. In some of those the lack of automatic update seems to reflect some amount of irresponsibility on our part. Customers in some real general average fail to check for and perform updates. This has become extremely obvious with vulnerabilities in standard routers that were identified many years ago and eliminated according to manufacturers but are now the focus of some of the most scary Internet botnets. The corrective updates having never been applied.

The JNIOR is not vulnerable in the same way as other computer systems simply because it is not a Windows or Linux system. It is unique to us and completely unknown to the hackers. That doesn't mean it can't be attacked. But that's not at all why we want to propagate updates.

In general when I fix a bug it is the last that I want to be concerned about it. The assumption is that it is fixed. The fact that we are unable to get that fix out into your units is a problem. That old glitch can still affect many of you today and impact your opinion of the product or worse cost you time and money. We don't find out until somebody gets grumpy. We do care. Everyone here at INTEG has a personal commitment to your satisfaction. That's not just big company bullshit. We are not a big company.

But I am not arguing for or against automatic updates. The capability needs to be there eventually. You are all providing me with helpful insight that will be considered during the implementation of this. I do appreciate it.

 |  IP: Logged

Carsten Kurz
Film God

Posts: 4340
From: Cologne, NRW, Germany
Registered: Aug 2009


 - posted 10-09-2018 10:38 AM      Profile for Carsten Kurz   Email Carsten Kurz   Send New Private Message       Edit/Delete Post 
It makes no sense at all to have automatic update option if it is disabled per default. Whoever is able to set the correct IP address in a specific device for his subnet(s) is also able to disable the auto update function. The whole idea of automatic updates is to prevent abuse of herds of IoT devices. If someone needs to activate auto update manually to make that happen, it is useless.

- Carsten

 |  IP: Logged

Marcel Birgelen
Film God

Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012


 - posted 10-09-2018 11:47 AM      Profile for Marcel Birgelen   Email Marcel Birgelen   Send New Private Message       Edit/Delete Post 
quote: Carsten Kurz
It makes no sense at all to have automatic update option if it is disabled per default. Whoever is able to set the correct IP address in a specific device for his subnet(s) is also able to disable the auto update function. The whole idea of automatic updates is to prevent abuse of herds of IoT devices. If someone needs to activate auto update manually to make that happen, it is useless.
Well, that's your opinion and not a fact.

Like I already mentioned, in my opinion, it greatly depends on what the default usage for a device is.

Is it a consumer device that's most likely being neglected by their users (and most likely their manufacturers too), then an automatic update function might be the only way from saving the device to become part of someones botnet later on.

But if it's a device that's targeted at a professional application, then I don't want the automatic update feature enabled by default, let me decide if it's required or not. You don't want your servers, routers, switches, firewalls, automation controllers or whatnot appliances to randomly reboot, because of god knows what update. But if the thing happens to be deployed in a largely unattended network, where a nightly reboot might not be a big deal and a failed update will not wreak potential havoc, maybe it's better to have it on automatic updates.

quote: Carsten Kurz
Whoever is able to set the correct IP address in a specific device for his subnet(s) is also able to disable the auto update function.
That's also not entirely true. If you're used to configure some device a certain way and have done it for years and suddenly some newer firmware activates automatic updates, you can also be in a world of hurt.

Yes, maybe you should've read the changelog (if there is any at all), because you've got all the time in the world... I for one, always read the complete Microsoft EULA after each and every update. [Razz]

 |  IP: Logged

Bruce Cloutier
Expert Film Handler

Posts: 161
From: Gibsonia, PA, USA
Registered: Aug 2016


 - posted 10-09-2018 03:04 PM      Profile for Bruce Cloutier   Author's Homepage   Email Bruce Cloutier   Send New Private Message       Edit/Delete Post 
Speaking of change notes... Here's a link to release notes for the JNIOR. It is very hard to make these clear for customers. If you have questions I can help.

http://jnior.com/janos-release-notes/

Relative to this topic you can see that our updates aren't massive rewrites with risk of disrupting existing applications.

I am working on JANOS v1.7.1 Beta which involves 4 bug fixes (so far) not yet in these release notes. We'll run v1.7.1 in here and probably release it by the end of the year. But if a customer is struggling with something related we can share it.

One involves an issue with watchdog operation when an application is started in the foreground in a command session. None of you do that.

Two correct the use of alternation in a Regex expression. Kevin ran into this with his application for MQTT and our AWS interface. IoT you know.

And the last we are calling a "Good Kill". Very rare and random glitches sometimes occur and we call those "Gremlins". Well we got what might be the last one this past week. This has to do with inter-process messages when a process terminates. Generally you are probably not affected by this. We have a honeypot unit directly on the open Internet and on that unit we've seen maybe a total of 4 glitches all year. But in testing the MQTT application on a separate demo unit Kevin managed to get the issue to repeat. So this one is worth a few victory laps and a big celebration.

Now shouldn't we show some interest in getting these kinds of corrections out to customers?

 |  IP: Logged

Marcel Birgelen
Film God

Posts: 3357
From: Maastricht, Limburg, Netherlands
Registered: Feb 2012


 - posted 10-10-2018 07:14 AM      Profile for Marcel Birgelen   Email Marcel Birgelen   Send New Private Message       Edit/Delete Post 
It's understandable that you try to get your bug-fixes out the door and in the hands of your customers. But if I'd encounter a bug with one of your devices, I would be the first to visit your website and check for a firmware update.

I've needed to work around bugs and I've needed to "work around" my workarounds, once those bugs got fixed. So, even fixing bugs might not be as harmful as it might seem.

Since you also target the JNIOR at more industrial process automation, it's my opinion it should follow the general practice of not automatically update the firmware, unless it's been explicitly told to do so. Even a random reboot can create quite some havoc.

As I told you, I did some stuff for e.g. theme parks. Nobody would appreciate a randomly rebooting show controller or PLC, because it was fetching the latest update. Sorry, we're temporarily not applying the brakes, because we're updating. Enjoy the ride anyway. [Wink]

 |  IP: Logged

Bruce Cloutier
Expert Film Handler

Posts: 161
From: Gibsonia, PA, USA
Registered: Aug 2016


 - posted 10-10-2018 08:09 AM      Profile for Bruce Cloutier   Author's Homepage   Email Bruce Cloutier   Send New Private Message       Edit/Delete Post 
There are JNIORs in use in Disney parks by the way. Just because Microsoft feels it is appropriate to ignore you and reboot under the pretense of an update doesn't mean that everyone does. Microsoft has been working for 35 years to perfect the Windows operating system and hasn't even come close. DHYB (Don't Hold Your Breath)

True that the JNIOR operating system updates upon reboot. I think the name of the game is in getting the new OS image in place ready and queued for that reboot in some automated fashion. Then when you turn off the JNIOR on purpose, it loses power for some other unavoidable reason, or it crashes again because of a bug that does need to be corrected, it would then update. This update adds about 4 seconds to the normal boot.

The Series 4 tracks record up times. We have seen units that have gone well over a year without a reboot. But when that next rare reboot does occur it would be great if the OS would bring itself up to date. Because someone manually performing the update appears to be even more rare.

If any of you have access to JNIORs check your OS level. We are shipping JANOS v1.7. It is displayed in the Beacon tab if you bring up the Support Tool on the local network. We are at v7.4 of the Support Tool by the way. I'd bet you are not. There are other ways to access your JNIORs.

If you open a Telnet session the version is in the banner and you need not log in. If you use your browser to bring up the DCP you will have to log in. The version is displayed at the top of the page. If you have a Series 4 and the old applet based configuration pages try to come up (browsers no longer allow it) then you should definitely get and run an update project on that unit. The DCP is soooo... much better. And configurations before the DCP are relatively unstable.

And if you have a Series 3, well, it is better left alone although slowly they are being replaced.

By the way, we don't have anyone running any kind of workaround for any bug. We can fix bugs the same day that they are identified. If you have a bug and you elect to work around it instead of informing us then that is a problem on its own. Those that have encountered bugs were quickly provided corrected firmware and/or application code. Someone can back me on this I am sure.

Workarounds are appropriate for products from companies that you cannot contact by phone and reach a live person or one that has any clue technically. Wait! That is probably the case with the rest of your equipment.

 |  IP: Logged



All times are Central (GMT -6:00)
This topic comprises 2 pages: 1  2 
 
   Close Topic    Move Topic    Delete Topic    next oldest topic   next newest topic
 - Printer-friendly view of this topic
Hop To:



Powered by Infopop Corporation
UBB.classicTM 6.3.1.2

The Film-Tech Forums are designed for various members related to the cinema industry to express their opinions, viewpoints and testimonials on various products, services and events based upon speculation, personal knowledge and factual information through use, therefore all views represented here allow no liability upon the publishers of this web site and the owners of said views assume no liability for any ill will resulting from these postings. The posts made here are for educational as well as entertainment purposes and as such anyone viewing this portion of the website must accept these views as statements of the author of that opinion and agrees to release the authors from any and all liability.

© 1999-2020 Film-Tech Cinema Systems, LLC. All rights reserved.