Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Weekly Brief
Daily Downloads
Daily Technology News
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides

Programs in Peril

Popular apps have more security flaws than Windows does.

Andrew Sullivan

Monday, January 30, 2006 1:00 AM PST
Recommend this story?
Illustration by Stuart Bradford.
Illustration: Stuart Bradford

With a spiking number of security flaws, the programs you run every day are now a more enticing hacker target than your operating system.

The Windows OS has become battle-hardened over years of trial by fire, enduring relentless hacker attacks. Although sometimes-critical flaws continue to surface, security patches applied via automatic updates have made Windows a tougher nut to crack.

If hackers were still just kids out to cause trouble and make a name for themselves, this might be enough to divert them to less destructive pursuits. But these days money, not mayhem, motivates a determined core of Internet attackers. (See the exclusive PCWorld.com series "Web of Crime" for more on this new and unsettling trend.)

These hackers are looking for easier ways to break into your computer--and they're finding your applications.

Porous Programs

It could be your antivirus application that leaves you exposed to online threats. It could be the media player software that opens the door to your unsuspecting PC. Even playing a CD on your computer could prove dangerous, should the disc contain slipshod anticopying software.

And Mac users, wipe that smug look off your faces: Because these security flaws are found in applications rather than operating systems, you are at risk as well.

Desktop programs such as iTunes, RealPlayer, and even the security-conscious Firefox now account for more than 60 percent of serious vulnerabilities, according to the British security firm Qualys. See the chart "Keep an Eye on These Apps" for a tally of flaws in popular applications.

The trend has offset years of painstaking progress in improving Internet security, says Allan Paller of the SANS Institute, a Maryland cybersecurity research organization. "We're back to where we were six years ago," he warns.

Windows remains a popular hacker target simply because it's so prevalent on both consumer and corporate computers, and new, sometimes critical vulnerabilities still surface on a regular basis. One recent major Windows flaw involving .wmf image file handling could have given attackers remote control of your machine (Microsoft quickly released a patch, however).

Despite new holes, though, Microsoft products are still notably more secure than they used to be, according to John Pescatore, a security analyst at Gartner Research. The majority of security risks now surface in everyday apps like Web browsers, media players, and even must-have antivirus applications, according to SANS's recent report, "The Twenty Most Critical Internet Security Vulnerabilities."


Next page: Browse With Care
Recommend this story?

Comments
Latest News
The Guinness Book of Records confirms Grand Theft Auto IV takes the crown for debut entertainment sales. 17-May-2008
The malware continues to grow, hitting the dubious distinction of biggest spammer. 17-May-2008
A strong showing in April means Nintendo's console will likely surpass Xbox 360 sales sooner than expected. 17-May-2008
Hewlett-Packard's acquisition of Electronic Data Systems won't hurt Dell in the next few years, but it could affect Dell's... 16-May-2008
Microsoft confirms that it has yanked parts of a backup feature from a major upgrade to its Windows Home Server. 16-May-2008
HP confirms that some users of its AMD-based desktops have had problems after installing Windows XP Service Pack 3. 16-May-2008
The days of imagining Wi-Fi blanketing a city are over with the exit of the last major municipally focused Wi-Fi service provider. 16-May-2008
In its continued attempt to convince business customers to adopt Vista, Microsoft has outlined and tried to explain some of... 16-May-2008
Sony Friday revealed a list of 15 upcoming games for the PlayStation 3, PS2 and PSP. 16-May-2008
This was a big IT news week, with the massive earthquake in China on Monday showing once again the role that the Internet... 16-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)