Skip the navigation
)
News

Adobe pushes Reader silent updates

Tells users it will update PDF viewer in the background, but lets them opt-out

June 15, 2011 03:59 PM ET

Computerworld - Adobe has switched on silent updating for its popular Reader PDF viewer, the company announced Tuesday.

"[We're] turning the automatic update option on by default for all Adobe Reader users on Windows," said Brad Arkin, senior director of product security and privacy at Adobe, in a post to a company blog yesterday.

The next time an update is detected by Reader, Adobe will present a dialog box asking users to allow silent updating. In the dialog, the box "Install updates automatically" will be checked by default.

Reader X Auto Update Screen
Windows users will see this dialog asking them to authorize silent updating for Adobe Reader. (Graphic: Adobe.)

Users can decline to switch to silent, in-the-background updating, added Arkin,

Adobe debuted silent updating for Reader in April 2010 when it revamped the update tool bundled with the free PDF viewer, and with Acrobat, the for-a-fee PDF creation tool.

At the time, however, Adobe retained users' previous settings -- which defaulted to a semi-automatic mode that notified users before beginning to download an update -- and required them to manually set the new tool for silent updating.

With the Tuesday release of Reader 10.1 -- part of a massive multi-product security update that also patched Flash, ColdFusion and Shockwave -- Adobe flipped the "on-by-default" silent update mode for Windows users.

If users accept the change, Reader will download any future security updates automatically, then install them in the background. The only thing users will see is a message posted to the Windows system tray that their software has been updated.

Reader pings Adobe's servers every three days to determine whether an update is available.

The updater included with Reader 10.1 largely bypasses the UAC (user account control) warnings that typically prompt Windows Vista and Windows 7 users for an administrator password before allowing a program to install.

"If you run with an administrator account on your machine, we can now perform the fully automatic update for full installers and updates to the updater," said an Adobe spokeswoman in response to questions today. "We do this with the addition of our own Windows service."

Windows Vista and Windows 7 users running with a "standard" account -- which is most popular in the workplace, where IT staff want to lock down the company's PC -- will see the UAC query in some situations, such as when the update requires a full installer or an update for the updater itself is available.

Mac users do not have the option of using silent updating because Mac OS X demands the user's password before installing new software.

Adobe is following in Google's footsteps on silent updating. Chrome, the browser Google launched in 2008, has always relied on silent updates to keep itself up-to-date.

Last year, Mozilla discussed adding silent updating to Firefox, but then backed away from the plan before it wrapped up Firefox 4. Firefox 5, which is slated to ship next week, does not support silent updating.

Silent updates are meant to keep more users' software up-to-date and safer from the newest attacks. Adobe has struggled in the past to keep up with hackers who exploit unpatched PDF document vulnerabilities.

So far this year, Adobe has issued two regularly-scheduled security updates for Reader -- one in February, another this month -- but also delivered three emergency, or "out-of-band" patches for the program.

Reader 10.1 can be downloaded from Adobe's Web site. Alternately, users can run the program's update tool or wait for the software to prompt them that a new version is available.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer or subscribe to Gregg's RSS feed Keizer RSS. His e-mail address is gkeizer@computerworld.com.

Read more about Security in Computerworld's Security Topic Center.



What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
Additional Resources
Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Security White Papers
Driving Secure Enterprise File Sharing and Syncing in the Enterprise
GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
The Enterprise File Sharing Option
Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
Security Strategies to Virtualizing Internet-Facing Applications
The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
Cloud Security Planning Guide
Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
Cloud Security Vendor Round Table
This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions...
All Security White Papers
Security Webcasts
Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT

In a recent study conducted by Ponemon Institute, fifty-five percent of respondents...
Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
BlackBerry PlayBook OS 2.0 Security Overview
The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
BlackBerry NFC Security Overview
The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
Playing Defense: Staying on Top of Your Disaster Recovery Game
When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
All Security Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs