Subscribe to Updates in Technology, Media & Telecom

RSS By Email

RSS By RSS

Add to Google Reader or Homepage

Subscribe in Bloglines


The Expertise Imperative and Compliance Technology
Access to a diverse array of specialized expert inputs drives superior decisions in every organizational context: within corporations, by investors and consultancies, and within nonprofits. When decision makers are confident of their decision inputs, they can respond more quickly and creatively to challenges and opportunities.Learn more about GLG's Compliance Framework


This page may include content provided by Council Members, your access to which is subject to the Terms of Use.
Find Out More

February 26, 2008

Spyware Problems - Users Are Only Partially To Blame

Analysis of: Spyware forum: Computer users often to blame for problems | www.computerworld.com
This analysis is solely the work of the author. It has not been edited or endorsed by GLG.
Analysis By:
Michael Schiff, Founder and Principal AnalystMichael Schiff
Founder and Principal Analyst, MAS Strategies
Implications: ● In a perfect world all users would immediately install any patches or upgrades that would enhance the security of their systems.  ● However, many users, especially in home or home office environments, are reluctant to change something that seems to work.  ● Of course, in a perfect world software patches and upgrades would not cause problems of their own; unfortunately, this is not always the case and a user who has been burned once may be hesitant about applying new fixes.

Analysis: While spyware is certainly a problem that many computer users underestimate or don't take the necessary steps to minimize their risk of exposure to, they are only partially to blame.  Many users have learned the hard way that the interactions among software programs can't always be completely anticipated and that sometimes a solution to one problem can lead to other problems.

Some users have had the negative experience of upgrading to a new browser, installing a Microsoft update, or upgrading to a new release of anti-virus or anti-spyware software only to soon discover that it has adversely affected the stability of their systems. This is especially true in home or home office environments where users usually don't have an in-house IT team to help them resolve unexpected problems.

In almost all large enterprises, and even in many small-to-medium sized organizations, software changes are first installed in a test environment to see if they cause problems prior to being released to the general user community. In a home or home office environment, many users simply take a "if it ain't broke, don't fix it" attitude and ignore upgrades and fixes.

This was not always the case, but has become more common as vendors like Microsoft have released operating system and browser patches that, in some cases, have created other system problems. Once users discover that, for example, a "fix" has disabled one of their devices or perhaps even curtailed their ability to access the internet, they become extremely cautious and may be reluctant to take chances with other patches or upgrades. Some users have even adopted an informal policy of delaying any patch for at least a week in order to see if any problems have been reported in the press.

Malware creators take advantage of this "user installation latency" to launch attacks as soon as a new area of vulnerability is exposed. The user community is caught in the middle; if they don't install a upgrade or critical patch they increase their risk of exposure to malware; if they install a patch that has a problem, they can temporarily disable their systems. While some might suggest that more thorough testing is needed prior to releasing a software update or fix, it is almost impossible to test for every possibility.  Software vendors need to build a protective wall around their software, malware perpetrators need only discover one loose brick.

Perhaps a reasonable tactic would be for users to take a complete system backup prior to installing a software patch so that they can restore their system to its former state in the event a problem is discovered, and then wait for a new patch to be delivered.

Other Analyses of the Same Source Article:
Computer Users are not the only ones to blame
February 29, 2008, Author: GLG Expert Contributor
It's not only change, it's the cost and hassle associated with it
February 11, 2008, Author: GLG Expert Contributor
Security Software and Services is Ripe for Budget Cuts
February 7, 2008, Author: Michael Cherry, President, Cherry Biometrics, Inc.
Got it dead wrong
February 5, 2008, Author: Scott Holcomb, Chief Executive Officer, HOLCOMB ENTERPRISES
Welcome to the wild, wild West
February 4, 2008, Author: GLG Expert Contributor
Blaming the users is like shooting the messenger: What's the Point...?
February 4, 2008, Author: GLG Expert Contributor
Clients ignorance on Spyware
February 4, 2008, Author: GLG Expert Contributor
Roqueware playing hide and seek
February 1, 2008, Author: GLG Expert Contributor

Report a Concern

GLG News: What Experts Think Is Important





Analytics


Generated at 2008-11-21T13:45:47.600