Archive notice: This article was originally published on January 14, 2008. Links and embedded videos are preserved as part of the historical record.
Fewer than five out of 100 computers on the internet have fully up-to-date software and are therefore protected as effectively as possible against security vulnerabilities in their programs. This is the result of statistics from around 20,000 computers that used the PSI test software https://psi.secunia.com/ provided by the IT security company for the first time over a one-week period in early January. Jakob Balle, IT Development Manager, reports this in Secunia’s “Security Watchdog” blog.
The statistics consider more than 5,000 common applications, from browsers and email clients to various media players. They determine whether the computers examined are running insecure, old versions for which newer patches exist that close known security vulnerabilities in the applications. The result for almost 1.8 million applications on the 20,000 computers is alarming: eleven or more insecure programs were discovered on almost 42 percent of the computers, whereas only around 4.5 percent of the computers had all applications at the latest security level.
“These are statistics from users who use Secunia’s website,” Secunia security expert Thomas Kristensen emphasises to the pressetext.de news service. As Balle also stresses in the blog post, they were probably more security-conscious than the average internet user. It therefore appeared likely that the general rate of use of insecure, unpatched program versions on the internet was even higher.
The importance of updated software versions can be seen, for example, in Apple’s QuickTime player. At the end of November 2007, it had an extremely critical security vulnerability that was actively exploited by hackers and for which an Apple patch had been available since December. Yet even fully up-to-date software does not always provide protection. On Friday, a new Quicktime vulnerability became known that also exploits an error in handling the RTSP streaming protocol. “I would be equally concerned this time,” Kristensen assesses the potential danger as similarly high as that of the November vulnerability. However, no active exploit for the newly discovered security risk was yet known.