Adobe May Change To Monthly Patch Cycle
Trailrunner7 writes "Adobe, which has been under fire for the security of its flagship products, Flash and Reader, for some time now, may be on the verge of changing its patching process to push fixes out on a monthly schedule, which would coincide with Microsoft's monthly Patch Tuesday releases. The change would be the second major adjustment to Adobe's patching process in the last year or so. In 2009 the company moved to a scheduled quarterly patch release process in an effort to give its customers a better chance to plan for testing and deployment. That change was generally well-received. Now Adobe may change the schedule again in order to get patches out more quickly. The company is considering releasing its security fixes for Reader on a monthly schedule, the same day that Microsoft releases its patches."
look at what others do to avoid that pitfall.
http://www.appdeploy.com/packages/detail.asp?id=1328
Obama's legacy: (N)othing (S)ecure (A)nywhere and (T)error (S)imulation (A)dministration
Well, Adobe could release plugins for the new version of WSUS and admins can simply approve them like they do MS patches in WSUS. Or at least change their updaters so they make some sense. I just installed Acrobat 8.0. The updated proceeded to install:
8.0.1
8.0.2
8.0.3
8.1.0
8.1.1
etc
Almost each asking for a reboot.
Instead it should have downloaded the update straight to 8.2 or whatever the current version is and then done the incremental to 8.2.3.
Lastly, they need to disable javascript by default in reader. Users can just press the "run scripting" button if they trust the publisher. Adobe is pretty much where MS was in 1998 or so. It really needs to grow up and smarten up regarding security.
Go download virtualbox, put your images into that and test the apps. If you do not have system images, go get fog and make some. This will all make your life much easier.