Adobe drags Google into Microsoft's Patch Tuesday
Adobe's decision to fix Flash on Patch Tuesday forces Google to update Chrome the same day
Computerworld - Google has been dragged into adopting rival Microsoft's Patch Tuesday, fallout from an Adobe move last month.
Earlier this week, Google updated its Chrome browser, quashing six bugs and as it often does, also updating Adobe's Flash Player. That same day, Microsoft shipped seven security updates to patch 12 vulnerabilities, and Adobe released a new version of Flash to address three critical bugs.
It was the Flash patches that triggered Chrome's copycat update: In November, Adobe announced it would synchronize Flash updates with long-time-partner Microsoft's Patch Tuesday. Most security experts applauded the decision, which they said was prompted by the bundling of Flash with Internet Explorer 10 (IE10) on Windows 8 and Windows RT.
Those same experts said Adobe's hand was probably forced by Microsoft, which had bumbled this fall when it failed to sync IE10 updates with those shipped by Adobe for Flash.
But because Google also bakes Flash Player into Chrome, Adobe's Patch Tuesday adoption also requires Google to ship updates the same day or put its users at risk.
Chrome has included Flash since April 2010, and is regularly updated whenever Adobe patches the popular media player.
Security professionals praised the three-vendor synchronization on the month's most important patch day.
"We already knew that Microsoft was the leader in security patch cadence, so for others to fall in line was inevitable," said Andrew Storms, director of security operations, in an instant message interview. "I suspect the more this happens, the more vendors will want to coordinate. It really is better for both them and customers if everyone knows a patch is imminent."
Jason Miller, manager of research and development at VMware, concurred. "It's good to see vendors coordinate like this," he said in an interview earlier this week.
But even more could be done.
"The biggest win [for users] is if all the vendors provided an advance notification so security teams could plan accordingly," he said. "Without proper notice, we are really in the same boat as before, where the surprise updates catch you off guard."
Adobe does not offer pre-patch notifications for Flash -- it does for Adobe Reader and Acrobat, however -- and neither does Google for Chrome.
Although Google patched Chrome on Tuesday -- and also on last month's Patch Tuesday of Nov. 13 -- it does not hew to a Patch Tuesday-only schedule, as Microsoft and Adobe do for all but emergency updates. Typically, Chrome is patched several times each month, on no set schedule. In the month between the last two Patch Tuesdays, for instance, Google updated Chrome twice.
The six Chrome patches Google provided Dec. 11 included three reported by independent researchers, who were awarded a total of $4,500 in bounty payments. So far this year, Google has paid more than $380,000 in Chrome bounties.
Chrome is automatically updated in the background each time Google patches the browser. The newest version can also be downloaded from Google's website for Windows, OS X and Linux.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed . His email address is email@example.com.
- Feds declare big win over Cryptolocker ransomware
- Hackers hit more businesses through remote access accounts
- P.F. Chang's post-breach move to manual processing is telling
- Microsoft withholds monster IE update from Windows 8.1 dawdlers
- In baffling move, TrueCrypt open-source crypto project shuts down
- 'Oleg Pliss' hack makes for a perfect teachable IT moment
- Give IE the heave-ho until Microsoft patches zero-day
- Hackers find first post-retirement Windows XP-related vulnerability
- Researcher claims two hacker gangs exploiting unpatched IE bug
- Update: Third of Internet Explorer users at risk from attacks
Read more about Security in Computerworld's Security Topic Center.
- Top 10 Reasons to Strengthen Information Security with Desktop Virtualization Regain control and reduce risk without sacrificing business productivity and growth
- Preventing Sophisticated Attacks: Anti-Evasion & Advanced Evasion Techniques McAfee Next Generation Firewall applies sophisticated analysis techniques specifically to detect advanced evasion techniques (AET).
- The Security Industry's Dirty Little Secret The debate over advanced evasion techniques (AETs) This report summarizes the findings of a McAfee commissioned research group to determine the level of understanding IT security professionals have about AETs...
- Demand More, Get the Most from the Move to a Next-Generation Firewall Beyond the basics in a next generation firewall, to protect your investment you should demand other valuable features: intrusion prevention, contextual rules, advanced...
- What should I look for in a Next Generation Firewall? SANS Provides Guidance With so many vendors claiming to have a Next Generation Firewall (NGFW), it can be difficult to tell what makes each one different....
- Responding to New SSL Cybersecurity Threat The featured Gartner research examines current strategies to address new SSL cybersecurity threats and vulnerabilities. All Security White Papers | Webcasts
Our new bimonthly Internet of Things newsletter helps you keep pace with the rapidly evolving technologies, trends and developments related to the IoT. Subscribe now and stay up to date!