The problem of extra software

A compelling reason for getting rid of the programs that you don’t use or need.

01/11/2013


Old joke: A man goes to the doctor and complains, “I feel good most of the time, but it hurts when I do this.” (Let your imagination fill in what “this” is.) The doctor replies, “Then don’t do that.”

Java, the software, has been in the news lately. There are cyber security problems connected with it, and it has the ability to run on a wide variety of systems, so it is a preferred port of entry for hackers. Most recently, there have been reports that if you have it on your computer and visit compromised web sites, the site can exploit Java vulnerabilities and dump malware on your computer.

IT security analyst Dan Kaplan recommends, “Java has been hard hit in recent years and represents arguably the most common attack vector, prompting a number of security experts to advise users to simply remove the software for good.”

The point of this discussion is that you may have Java and not realize it. It might be on your computer even though there are no applications that need it. You can see if you have it. Bottom line, if there is no compelling reason to have Java, you should uninstall it. Follow the doctor’s advice and don’t do that.

The same advice applies to more than Java. If you are responsible for your industrial networks, you should know all the programs on your systems, including the latest revision levels, and why you have them. The nightmare scenario is that you have an old program with assorted unpatched vulnerabilities that you don’t even know are there. A hacker finds that vulnerability and you’re in trouble.

The fewer programs on your system, the fewer you have to update and protect. Some platforms are very necessary and critical to your operation, so you have to keep a close watch on them. Get rid of all the others.

Peter Welander, pwelander@cfemedia.com



Consulting-Specifying Engineer's Product of the Year (POY) contest is the premier award for new products in the HVAC, fire, electrical, and...
Consulting-Specifying Engineer magazine is dedicated to encouraging and recognizing the most talented young individuals...
The MEP Giants program lists the top mechanical, electrical, plumbing, and fire protection engineering firms in the United States.
2017 MEP Giants; Mergers and acquisitions report; ASHRAE 62.1; LEED v4 updates and tips; Understanding overcurrent protection
Integrating electrical and HVAC for energy efficiency; Mixed-use buildings; ASHRAE 90.4; Wireless fire alarms assessment and challenges
Integrated building networks, NFPA 99, recover waste heat, chilled water systems, Internet of Things, BAS controls
Transformers; Electrical system design; Selecting and sizing transformers; Grounded and ungrounded system design, Paralleling generator systems
Commissioning electrical systems; Designing emergency and standby generator systems; VFDs in high-performance buildings
Tying a microgrid to the smart grid; Paralleling generator systems; Previewing NEC 2017 changes
As brand protection manager for Eaton’s Electrical Sector, Tom Grace oversees counterfeit awareness...
Amara Rozgus is chief editor and content manager of Consulting-Specifier Engineer magazine.
IEEE power industry experts bring their combined experience in the electrical power industry...
Michael Heinsdorf, P.E., LEED AP, CDT is an Engineering Specification Writer at ARCOM MasterSpec.
Automation Engineer; Wood Group
System Integrator; Cross Integrated Systems Group
Fire & Life Safety Engineer; Technip USA Inc.
This course focuses on climate analysis, appropriateness of cooling system selection, and combining cooling systems.
This course will help identify and reveal electrical hazards and identify the solutions to implementing and maintaining a safe work environment.
This course explains how maintaining power and communication systems through emergency power-generation systems is critical.
click me