Why silent [browser] updates boost security
techzoom.net
techzoom.net
I'm currently hosting a series of meetings where we are certifying all of our existing IE 6 and IE 7 based applications for IE 8. Much is broken because of hacks necessary to make these sites work properly in older versions of the browser.
While I'll be the first to say that we apply the IE Cumulative Updates the day after release ... silently ... to every PC in our company, we wouldn't dream of deploying a major browser update without reviewing it. Anymore, 99% most of our applications are browser based. A major browser update (Firefox 2.0 -> 3.0 or IE x.0 to IE x+1.0) can be as impacting as upgrading the operating system silently.
Yes, yes, I know. We standardized on IE, bad us. It wasn't my call :o).
Really, Chrome is at an advantage here by only having a single version. Comparing other browsers' update cycles to it is hardly fair.
The recent stink with Adblock Plus and NoScript using my browser in their personal snowball fight makes me leery of auto-updates. Making the normative choice the default setting has an okay track record, but I'd like as many as eyes as possible helping me keep developers in line with my needs.
If a silent update misbehaves, how do we have a chance to -do- anything? The update was likely applied before we could even open an app to get the news. Should we go online in a VM to verify that it's safe to connect with our preferred OS/software?
The argument about third-party verification is a red herring. I feel somewhat qualified to argue that third parties will "verify" updates no matter how they're disseminated; reversing patches is a bread-and-butter part of security product development.