back to article Samsung PC, laptop owner? Better update the update tool

Users ought to upgrade following the discovery of a flaw in Samsung’s software update tool that opens the door to man-in-the-middle attacks. Security shortcomings in Samsung SW Update Tool, which analyses the system drivers of a computer, were discovered by Core Security. Following the discovery of this vulnerability, Core …

  1. tiggity Silver badge

    uninstall

    Surely everyone uninstalls all the dubious vendor software "tools" & assorted crud that comes preinstalled on a PC anyway?

    1. adnim
      Happy

      Re: uninstall

      Yup first thing I do... Un-install all the manufacturers software. And all the trial version software. I visit the device vendor site for updates.

      Still loving my NP900X4C.... Awesome bit of kit. Boots into Mint desktop in 10-15 seconds. Windows 7 takes an awful lot longer

    2. regadpellagru

      Re: uninstall

      "Surely everyone uninstalls all the dubious vendor software "tools" & assorted crud that comes preinstalled on a PC anyway?"

      Joe User is not doing that ever ... A high percentage of users I support are not even aware you can launch applications without an icon of app/document being on the desktop.

  2. CAPS LOCK

    I had a Samsung laptop once...

    ...it caught fire. A reflection of Samsung quality to be sure.

    1. David 132 Silver badge
      Coat

      Re: I had a Samsung laptop once...

      So I bought another one.

      That caught fire.

      So I bought another one.

      That caught fire, sank into the ground, and exploded.

      So I bought another one.

      That one's stil working.

      I proved them all wrong.

      (with apologies to Holy Grail)

      1. joed

        Re: I had a Samsung laptop once...

        did it come with a fire extinguisher?

  3. timnich

    ..not to mention their out of date certs

    Last time I tried to update the updater(within the last month), as per their instructions, it failed due to being signed with a 2 year out of date cert.

    When I queried this with them, they could give me no timeframe for when they might actually renew their certs, so I am not convinced they take security very seriouly at all.

    1. David 132 Silver badge

      Re: ..not to mention their out of date certs

      I am not convinced they take security very seriouly at all.

      I don't think any of the mass-market vendors, outside of the security industry itself, take security seriously. Security isn't sexy. Security isn't shiny. People will buy a product that's "50% faster than last generation!" but let's face it, "50% more secure than last generation!" isn't going to pull in the crowds.

      The IT industry is at the same stage that the automobile industry was in the 50s and 60s, regarding safety. Despite a few weirdos (step forward Volvo, Bricklin among others) pushing safety as a feature, the other manufacturers preferred to make their engines bigger, and their chrome shinier, instead.

      What changed matters in the car world was a combination of growing public awareness, plus regulatory intervention and a few high-profile and grisly accidents.

      See the parallels with IT?

      Normally I'd be the last person to argue for more government intervention, but I think it's the only way we'll get acceptable standards of designed-in security - for everything from smart thermostats to datacenter clusters.

      1. Weeble

        Re: 50% Improvement

        "People will buy a product that's "50% faster than last generation!" but let's face it, "50% more secure than last generation!" isn't going to pull in the crowds."

        Perhaps that's because "50% faster than last generation!" can be a genuine improvement,

        while "50% more secure than last generation!" means it's still shot through with vulnerabilities and still leaks like a sieve.

  4. emdeedee

    SWUpdate download page isn't even on a secure connection!

    Just went to download the latest version from their support site. Neither the page itself or the download package is from a secure site so the whole thing can be spoofed!

    Shheesh

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like