Craig Peterson's Tech Talk
Nobody Is Checking Whether Your Software Needs Updating — So Craig Wrote the Software
- Autor: Vários
- Narrador: Vários
- Editor: Podcast
- Duración: 0:10:55
- Mas informaciones
Informações:
Sinopsis
Craig explains how attacks used to work, because the change is the story. A flaw gets found. The bad guys write code aimed at that one specific hole — say, a version of Microsoft Excel. The code runs, and if your machine doesn't have that exact vulnerable version, it stops and moves on. That took six months to a year to build, and that year was your slack. What's different now is that the attack doesn't target one hole. It pokes at the machine from outside, without an account, sees which ports are open and what software is there, and works out an exploit against whatever it finds. Which lands on the part most people get wrong. Ask anyone about patching and they'll tell you it's turned on. What that means is Windows patches most of Microsoft's own software — not all of it, and nothing else. The dozens of other programs on the machine are untouched. Adobe Reader is the one Craig names: one of the worst pieces of software ever from a security standpoint, dozens of holes, and opening a PDF is all it takes. So he