Log In

Reset Password
BERMUDA | RSS PODCAST

The importance of software patches

The Dutch hacker going by the name Dimitri who cracked into a Microsoft's computer in November through a well-known security hole sent a wake-up notice to system administrators, small businesses and home computer users everywhere.

He exposed one of the biggest flaws in computer security -- the constant need to update systems and software. The break-in occurred because some systems administrator at Microsoft had forgotten to put in a software patch for a vulnerability the company had warned users about back in August.

I'm going to make this reminder again because it's important: everyone should regularly run their machine through the latest update engines online for software patches. A twice a week update of your virus protection provider is also necessary. I know that many people, including myself, are lax about these tasks, because they are a bother and take time.

I also know people who aren't aware what they have to do to stay protected from hackers, either while they're surfing the Internet or opening up a file given to them by a friend on a floppy disk. Once you've set your bookmarks it's easy to establish a regular routine. Unfortunately many software patches require that you can't do other tasks while you're downloading the fix. With others you can work while you download the file to your hard disk.

You can then run the fix when it's more convenient.

You should also be aware that software is updated regularly and many new versions incorporate fixes without the companies involved explicitly saying so. Unfortunately these updates can also have their own new bugs and vulnerabilities as well. Stay away from `beta' or test versions unless you're a professional working in the software sector.

One of the quickest ways to find out about all the patches and updates that you might have missed is through the ZDNet update Internet site http://updates.zdnet.com. Click on the "My updates'' section to get an automatic scan of your computer. The process can take three to five minutes at the end of which you get a list of patches and updates to your software, and links to download all of them. The list you get will be fairly comprehensive.

I've just reloaded a new version of Word 2000, thus I have to go through the whole process of updating the software again. I ended up with 26 items to update, including some pretty key security patches.

Before you start downloading the updates from your ZDNet list first try doing a similar scan at the Microsoft site for Microsoft products. The updates for Windows can be found at http://windowsupdate.microsoft.com.

The Office update is at http://officeupdate.microsoft.com The advantage of first doing this before downloading from the ZDNet site is that you can get packages of updates as service packs which will bundle most of the fixes that had previously been released as individual patches. Downloading the package could save you some time.

You should go to Microsoft's security site at http://www.microsoft.com/security/to check on the latest bulletins and patch releases, which come these days at the rate of two a week. You can sign up to get automatic e-mails of the bulletins. There were nine bulletins in November and three so far in December. One December update fixes two problems in Internet Explorer, which allow a malicious Web operator to run code, or view files on your computer when you're visiting their site on the Internet. I'm installing that one as soon as I'm finished writing this article. Apple Computer software updates are available at http://asu.info.apple.com Once you've downloaded as many of the patches as you can at the Microsoft site, run the ZDNet update again to check what is left on the list of suggested updates. You'll probably find that you've missed many patches. The ZDNet site will also give you the updates to non-Microsoft products. To finish off this spate of downloading, which will surely add to your telephone bill, update your anti-virus software.

The software should have a method somewhere in the program to automatically download and install the most current virus protection files through the Internet. Norton AntiVirus has a ''Live Update'' button on its command bar.

If you don't have any anti-virus software, install one fast. You could be the next sad case whose hard drive, and the information it contains, has been destroyed. Oh, and don't forget to backup all your important files. You will at least have your files stored somewhere if you are unfortunate enough to be among the first people get broken into through an unreported vulnerability.

Tech Tattle deals with topics relating to technology. Contact Ahmed at editor yoffshoreon.com or (33) 467901474.