Welcome to City-Data.com Forum!
U.S. CitiesCity-Data Forum Index
Go Back   City-Data Forum > General Forums > Science and Technology > Internet
 [Register]
Please register to participate in our discussions with 2 million other members - it's free and quick! Some forums can only be seen by registered members. After you create your account, you'll be able to customize options and access all our 15,000 new posts/day with fewer ads.
View detailed profile (Advanced) or search
site with Google Custom Search

Search Forums  (Advanced)
 
Old 12-15-2020, 10:18 AM
 
23,597 posts, read 70,412,676 times
Reputation: 49263

Advertisements

Solar Wind is perhaps the biggest story in this area right now, but Red Hat is getting pushback on the way it wants to have more fluid updates on servers. Tom's has an article on how Firefox, Chrome, and Edge are being hacked with a type of background "update."

The potential for disaster with OS and browser automatic updates was obvious (at least to me) from the beginning.

I'm not quite sure what the best defensive strategy will be. My initial thought is read-only copies of critical software that cannot be changed by any outside code claiming to be an "update." It is hard (technically not impossible, though) to hack a brick wall.
Reply With Quote Quick reply to this message

 
Old 12-16-2020, 08:33 PM
 
Location: Berkeley Neighborhood, Denver, CO USA
17,711 posts, read 29,823,179 times
Reputation: 33301
I prefer ‘visible’ updates.
I want to be told of an update and the asked if I want to install it.
But, I am an alte kaker.
Reply With Quote Quick reply to this message
 
Old 12-16-2020, 08:49 PM
 
3,647 posts, read 1,600,968 times
Reputation: 5086
Use a safer browser like Opra and run it in a sandbox. You should run all browsers in a sandbox
Reply With Quote Quick reply to this message
 
Old 12-16-2020, 10:19 PM
 
23,597 posts, read 70,412,676 times
Reputation: 49263
The sandbox idea is great for browsers, a little harder for servers and the Red Hat issue. Many users don't have such options readily available, esp. if what they use is dictated by powers that be.

Dave - Nah, yer a mentsh. It is the way computers and software have been twisted that is fakakta.
Reply With Quote Quick reply to this message
 
Old 12-16-2020, 11:01 PM
 
8,299 posts, read 3,811,388 times
Reputation: 5919
Quote:
Originally Posted by harry chickpea View Post
The sandbox idea is great for browsers, a little harder for servers and the Red Hat issue. Many users don't have such options readily available, esp. if what they use is dictated by powers that be.

Dave - Nah, yer a mentsh. It is the way computers and software have been twisted that is fakakta.
Servers shouldn't be getting software or OS updates. This should be handled by simply updating the AMI (or equiv) and redeploying. Unless you're still using physical servers... which I doubt anyone is anymore.

Redhat must have thought this through for AMIs.

Worst case, you can just switch the Linux Distro. It's rather painless.

For browsers, if you're just talking about browsing the web, I'd just use an AWS Workspace.
Reply With Quote Quick reply to this message
 
Old 12-17-2020, 06:39 AM
 
666 posts, read 424,586 times
Reputation: 1029
This is a good opportunity to become familiar with how (and by whom) your browser is being packaged. That build of Firefox or Chromium has to be compiled somewhere and for most people, it is likely the official builds supplied by Mozilla, Google, etc.

One way to distance yourself from such updates is to run the long term support builds, as generally, new features and anti-features alike tend not to be implemented into these builds. At least not right away.

Or even better, there are lots of teams who take the time to declaw these anti features and release their own builds. I won't drop any names but any web search will yield several projects which reconfigure and rebrand Chromium or Firefox into more user-respecting downstream derivatives. Pick your poison.
Reply With Quote Quick reply to this message
 
Old 12-18-2020, 07:34 AM
 
Location: The DMV
6,590 posts, read 11,288,331 times
Reputation: 8653
Quote:
Originally Posted by harry chickpea View Post
Solar Wind is perhaps the biggest story in this area right now, but Red Hat is getting pushback on the way it wants to have more fluid updates on servers. Tom's has an article on how Firefox, Chrome, and Edge are being hacked with a type of background "update."

The potential for disaster with OS and browser automatic updates was obvious (at least to me) from the beginning.

I'm not quite sure what the best defensive strategy will be. My initial thought is read-only copies of critical software that cannot be changed by any outside code claiming to be an "update." It is hard (technically not impossible, though) to hack a brick wall.
So then any updates/enhancements requires a full removal and reinstallation of the product? What would that look like for companies that have thousands of servers?

Also - the Solarwinds issue (which is still being worked on) would make this even more of cluster. What happened is essentially the update you got was compromised (the engine itself, actually). So it matters little how you update your software. This is like buying a brand new software off the shelf. Except that the software vendor was compromised and their code was embedded with malicious software.

That said - this is a very valid point in that the supply chain was compromised.
Reply With Quote Quick reply to this message
 
Old 12-18-2020, 10:36 AM
 
23,597 posts, read 70,412,676 times
Reputation: 49263
Quote:
Originally Posted by macroy View Post
So then any updates/enhancements requires a full removal and reinstallation of the product? What would that look like for companies that have thousands of servers?

Also - the Solarwinds issue (which is still being worked on) would make this even more of cluster. What happened is essentially the update you got was compromised (the engine itself, actually). So it matters little how you update your software. This is like buying a brand new software off the shelf. Except that the software vendor was compromised and their code was embedded with malicious software.

That said - this is a very valid point in that the supply chain was compromised.
Valid points, and any minor knowledge I had on servers is long out of date, and what goes on now is beyond my pay scale.

Updates (a word worthy of politicians) are often bug fixes, feature creep, a hidden method of revenue generation - such as background data gathering to be sold, and marketing in a competitive arena.

If the program cannot be hacked because it is read-only, and a hack of any platform is similarly frustrated or short lived, much of the legit rationale behind constant updates is gone. Yeah, the "latest and greatest" mantra is screwed, but it may be getting time for that level of maturity in some areas. Or not. Again, above my pay scale.
Reply With Quote Quick reply to this message
Please register to post and access all features of our very popular forum. It is free and quick. Over $68,000 in prizes has already been given out to active posters on our forum. Additional giveaways are planned.

Detailed information about all U.S. cities, counties, and zip codes on our site: City-data.com.


Reply
Please update this thread with any new information or opinions. This open thread is still read by thousands of people, so we encourage all additional points of view.

Quick Reply
Message:


Over $104,000 in prizes was already given out to active posters on our forum and additional giveaways are planned!

Go Back   City-Data Forum > General Forums > Science and Technology > Internet

All times are GMT -6. The time now is 03:22 AM.

© 2005-2024, Advameg, Inc. · Please obey Forum Rules · Terms of Use and Privacy Policy · Bug Bounty

City-Data.com - Contact Us - Archive 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23, 24, 25, 26, 27, 28, 29, 30, 31, 32, 33, 34, 35, 36, 37 - Top