Automatic Update Hell Must End
asserttrue.blogspot.com
asserttrue.blogspot.com
In any case it was my experience from assisting family and friends that anti-virus software did a pretty poor job in the main - plus there were at least two occasions when I had to assist in major problems actually caused by anti-virus software deleting key system files.
Sure, a single point of updates would be nice, but when asking that reboots not be necessary, or that people just write better software in the first place he's just making himself look ignorant.
Companies don't put auto-update functionality in for fun - they're there because there _are_ security issues that need to be patched.
As for asking the developers to write better software in the first place, it's quite reasonable. It's extremely difficult (maybe even impossible) to catch all the bugs and vulnerabilities in a complex piece of software before publishing it, but having to update as frequently as we're usually expected indicates a lack of proper care for security issues in the first place. And that is what the author is complaining about. In a way, it's just like it often happens with videogames: release in time to catch an important date and then ship patches.
I understand that the updates are annoying, but all of the alternatives are worse. Silent updating? I want control. Manual updating? People won't do it. No updates at all? The botnet lords love this idea.
So the only real solution is to default systems to patch themselves, and hopefully get the experience right for the confirmation dialog.
If you have a PC that is not connected to the Internet and runs the same software all the time, from a supplier you trust. Then yes automatic updates and virus checking is a waste of time.
Otherwise if you follow this advice you are asking to join a botnet.
I haven't used Linux in a while, but from what I remember it was rare to have a program itself tell me there were updates necessary, but the package manager globally managed those things for me on its own schedule.
The Mac application community has the fantastic Sparkle framework that lets individual applications poll for updates. This isn't nearly as bad as it sounds: generally speaking, applications have preferences to opt-out of automatic updates, and the updates include complete changelogs. It's gotten to the point where if an application doesn't include Sparkle, I get annoyed.
In short, the posters issues aren't with Automatic Updates, they're with an environment that doesn't respect users.
But, on the other hand, why not just use a better operating system? Linux, of course, but even Vista is going to have better lockdown of administrative privileges.
One of the things I really couldn't stand about Windows was how every program had to have its own stupid little updater, with its own rules, taking up resources and system tray space. This is the worst part of automatic updates -- somehow most Windows developers are totally incompetent at writing them.
2. I notice that firefox has downloaded updates only when I restart/start firefox. Again no trouble there.
Of course, I say Ubuntu because that's what I know. I would not be the least bit surprised if other linux distros/mac os had similar package managers.
It seems like even windows could form some kind of agreement with various software vendors allowing them to push updates through the windows updater. Opt-in of course.
Some offer granularity of what types of updates to do (Mint classifies updates by riskiness to stability) and most offer some method of holding back updates on some packages (although not in the GUI in the distros I have used).
One for the internet, one for development.
Guess which one has virus protection?
At work, where I manage a few hundred Windows machines with virus protection and updates (managed through WSUS), I'm able to see whenever our virus scanner gets a hit. It's almost always the same users doing the same stupid things. (They are all running in limited user accounts though, so it's usually only their own accounts they damage).
Linux machines are generally taken over through ssh key attacks, cgi vulnerabilities, or social engineering (this happens more than Windows machine takeovers at my workplace, unfortunately).