Why NOT upgrading tech will cost you dearly
Ever wonder how all the big tech companies manage to anticipate all the different ways their products could be hacked? The truth is they canโt. Not 100% of the time. Which is why security researchers are always announcing new vulnerabilities, leaving businesses scrambling to patch them.
Once theyโre available, the next bit is to get them on your machine. So how does that work?
Big wigs and high rollers from can have whole IT departments running this โ often reporting to a Chief Technology Wonk who coordinates the whole shebang with the other higher ups.
But in the home office? Youโve neither these resources nor this leadership in charge of it for you. You might have an IT tech lined up – but itโs likely still on you to call them in. Your saving grace is that your situation is way less hardcore.
Enterprise IT involves client/server networks with sprawling IP addressing schemes, custom software and one-of-a-kind hardware configurations, and documentation approaches that veer all the way from arcane runes written on vellum through to oral traditions handed down from shaman to shaman.
And more often than many people wants to talk about, thereโs a slap dash shell script written in a rush by a hateful alcoholic having a bad day in 1993 that now holds up an entire department.
You update on this with no testing or planning? Maybe itโs no problem, and maybe something holding the whole thing together disappears and itโs all cactus.
Itโs delicate and itโs fiddly task. One wrong click can be a disaster; even getting it perfect can be a pain in the proverbial.
As freelancer, you likely just need to browse the web, handle email, write documents, back things up to the cloud, do the books, that sort of thing – hopefully without the inconvenience of hacking, scams or malware. Itโs all stuff that Silicon Valleyโs had in their crystal ball for yonks.
Still, you gotta actually do it.
Ok. Letโs get down to brass tacks.
There are two kinds of security vulnerabilities out there: known and unknown. The unknown vulnerabilities are usually the most effective – because nobody has had a chance to defend against them yet.
But finding them is really hard. You have to trawl endlessly through code and notes and weird hunches for a thing that the entire rest of humanity has missed and that you canโt be sure is even there until you find it. Itโs galaxy brain stuff.
On the other hand, itโs easy to let someone else do all this work. And letโs be clear, very few out there are genius supervillains โ theyโre generally just creeps looking for an easy way to avoid honest work.
If youโre not applying security updates, you run so much more risk.
Did you know the two most damaging ransomware attacks of all time each targeted a vulnerability in Windows that Microsoft had already fixed?
These billion dollar disasters happened because so many users just hadnโt applied the patch.
How do you avoid being caught up in that?
Microsoft has stopped releasing security updates for operating systems older than Windows 7.
This means if youโre using Windows Vista, XP, ME, 98 or 95 anywhere in your office, this computer is wide open to hackers and ought to be upgraded as a matter of urgency.
Windows 7 is on the way out too. Security patches stop in January 2020; thatโs not all that long away.
Look, Iโm not going to make excuses for what a horrible user experience you get from the current round of Windows updates. Theyโre especially obnoxious in home environments, where no IT team patrols the perimeter between you and Microsoft to dive and take the bullet.
They arrive out of nowhere to totally take over your machine with all the politeness and none of the excitement of a bank robbery, so very often at the worst possible time.
But hereโs the thing โ these updates also protect you against the bad guys.
Even if you disable feature updates, make sure youโre applying security patches.
Mac OS is mostly a nicer experience with updates – It feels less like a bank robbery, anyway. You can apply them manually or automatically, and theyโre never forced.
Where Apple arses you about most majestically is by not telling you how long they intend to support each version – or even letting you know when support is dropped. Theyโll just quietly stop releasing patches.
Linux, overall, has the nicest user experience of all with updates. Theyโre super quick โ and you can even get on with other things while theyโre running โ you usually donโt even have to reboot. Itโs also entirely up to you when they run. That last bit though is a double edged sword because it leaves it completely on you to do it.
Different Linux distributions will be supported for different lengths of time. Obscure hobby projects are occasionally abandoned just out of nowhere because something happened in the maintainerโs life. Mainstream distributions publish schedules that are quite reliable.
Anti virus and malware removal tools should also be kept updated against the latest attacks.
Now hereโs a doozy. Iโm not sure many people outside of IT have even heard of firmware, let alone know to update it. As an industry weโve just done a terrible job of communicating this.
Firmware is the low level software that runs embedded devices like your router and wireless access points. You donโt want these compromised โ they sit between you and the whole internet.
If youโve got a wireless router thatโs more than a couple of years old, and youโve never touched the firmware thereโs a big vulnerability there leaving you wide open.
You can find the instructions for updating a deviceโs firmware in the manual. If youโve lost the copy that came in the box (who hasnโt?) then just Google it. As a rough rule, check for any patches when daylight saving changes.
If you donโt update your website, itโs just a matter of time before it gets hacked. Keep your content management system, themes and plugins up to date.
Now is also a really good time to add SSL encryption to your website if you donโt have it already. With an unencrypted website, every time you log in to the dashboard, your username and password is transmitted across the internet in plain text where anyone who intercepts the traffic can just read what youโve typed.
Migrating a website to SSL used to be a difficult and expensive process. Services like Letโs Encrypt now offer SSL certificates for free, and in a way that makes things easy for you or your tech to implement.
While weโre talking updates, how long has it been since you changed your passwords?
Because encryption algorithms change to keep up with processing power, passwords found in older databases are that much more vulnerable to password cracking techniques.ย
On top of that, not many of us were really all that on top of our game five years ago for what a strong password even looks like.
Click here for more on how to choose a new password.
Dealing with updates is boring and itโs a chore โ but itโs way less of a pain than losing your work or getting scammed. Get this out of the way so you can get on with the stuff that actually makes you money.
Comments