7 March Turn On Auto-Updates Everywhere You Can March 7, 2019 General, Privacy, Security Google announced that it had patched a wicked vulnerability in Chrome, by far the most popular browser in the world. Not only that, the search giant also confirmed that hackers had been actively exploiting the bug, in tandem with one found in Windows. Soon after came a wave of reports imploring people to update Chrome right now. But thanks to Google’s embrace of auto-updating its software, for most people it was already taken care of. Software updates are a pain no matter how you shake it. The MacOS prompts never leave you alone. Automatic Windows 10 updates ask you to restart your PC at the least convenient times. And fresh versions of iOS seem to brick phones every couple of years. You’d be forgiven for wanting to just forget the whole thing. Don’t! Keeping your software up to date is the easiest way to protect yourself from hackers, and letting it happen automatically is the best way to guarantee that it actually happens. “As a security practitioner, I am a strong advocate for auto-updates, especially when it comes to consumers,” says Jérôme Segura, head of threat intelligence at security firm Malwarebytes. Take the case of the recent Chrome zero-day vulnerability. Rather than forcing a pop-up on however many millions of open browsers, prompting all of those users to install a patch, which many of them would likely have put off or ignored, Google’s security team just pushed the fix. Done. Well, almost done: In this case, because the attack targets actual Chrome code and not that of a plug-in like Flash, you still have to restart the browser to effect the change. It’s a significantly lower bar, though, and one that’s going to keep substantially more people safe than an elective update would have. “My impression is that most people don’t want to think about security. It’s more of a burden than anything,” says Josiah Dykstra, technical director at the National Security Agency. “Even if they say they want to be secure, they either don’t have the expertise or the desire to do a lot of work.” Nor should you have to. There are some clear exceptions here. Plenty of medical and industrial systems can’t apply updates blindly; any unintentional bugs could result in catastrophe. And people who tinker with their software—security researchers, hobbyists, and so on—are rightly careful about any changes they introduce to their devices. Those are cases in which the cure can genuinely be worse than the disease. But for your average smartphone or laptop owner? Go auto-update all the way. Yes, you’ll run into some performance hiccups, but they’re worth it for the overall peace of mind. In fact, thinking of it in terms of those trade-offs puts the onus on you rather than the companies that push out faulty patches. Spend that energy demanding more from Apple and Microsoft and Google and whoever else is responsible for shaping your digital experience. “The vendors need to do a better job of vetting the patches before they go out and providing an emergency rollback on the end-user side,” says Gene Spafford, a computer scientist at Purdue University and prominent cybersecurity researcher who cowrote an essay last year with Dykstra about so-called disappearing cybersecurity. A mechanism like that would help quickly undo any worst-case scenarios versus forcing you to wait for the fix to the fix. Which, it should be noted, also needs a fix sometimes. Fortunately, Windows 10 auto-updates by default. Apple offered it as an option for the first time in iOS 12, but you have to opt in. To do so, head to Settings > General > Software Update > Automatic Updates and toggle over to turn them on. As for Android—and as with all things on Android—it depends on what device you’ve got, but generally speaking you have to wait until you get a notification that an update is ready for you in order to install it. And then there’s the Wild West of the internet of things. Many IoT devices lack not only automatic updates but any way to update software at all. That especially is a shame, because there’s no category of device that would benefit more from constant, hands-off improvement than those that have no real interface to speak of. The last thing you should have to worry about is your webcam shouting bomb threats at you. “That’s an area of concern. If IoT devices have vulnerabilities, they’re going to be widespread,” Spafford says. “We don’t have a climate yet that really holds [manufacturers] responsible to better behavior.” The good news is, the wider consumer-tech industry is starting to embrace auto-updates more. If there’s a silver lining to security meltdowns like the Chrome bug, it's that it draws attention to the upsides of a set-it-and-forget-it approach for most casual consumers of technology that goes beyond just getting the latest bells and whistles first. “If people see the value in auto-updates, they generally tend to see the value in product stability for features more than security,” Dykstra says. “The security benefit is a very hard thing for consumers to see.” All the more reason to make the whole process as invisible—and painless—as possible. Related Posts 2019 UI and UX Design Trends It feels like we’re getting somewhere with all the tools, advancements in technology, and growth of our understanding of how user-facing products really have to work. Sooner than later, we’ll develop the mindset for universal design that encompasses everything we produce, and not just sell. The way we do things for ourselves needs better design choices. The way we even sound as nations can be designed in a better way. Still, a far cry from where we could be in the future, let’s get into the interface and experience design trends of 2019. The Five Inconvenient Truths of Web Design Being a web designer isn't easy. Depending on your niche, it requires a combination of finely-tuned technical and visual skills. And it takes a major commitment in order to keep those skills relevant in an ever-changing industry. What's more, the proverbial rug can be pulled out from under us at any moment. Tried-and-true methods can turn to dust and great tools can disappear without a trace. Even industry-related legislation can throw everything into a tizzy. Taken together, it can all be very difficult to deal with - let alone thrive in such an environment. But it's not impossible. Part of the path to maintaining both success and sanity comes from embracing the things we learn from experience: the inconvenient truths. Over my 11+ years as a designer, I'd like to think that I've experienced quite a wild ride. In that spirit, I've put together a list of “truths” that, once understood, can help to make for a smoother journey. Limit How Long Google Keeps Your Data With This Overdue Setting GOOGLE PUT SECURITY and privacy features front and center as it kicked off this year's I/O developer conference in Mountain View, California, on Tuesday. The company went so far as to say that “security and privacy are the central theme” of its upcoming Android Q release. But let’s say you want to take some control over what data Google has about you right now. As of today, anyone with a Google account can start limiting how long their data gets stored using new settings the company announced last week. Grumpy Monkey: These Are a Few of My Least Favorite Things After 10+ years in the web design and development industry, I’ve found that the web is still far from perfect. There are a number of things I’d love to see change for the better. So, today I’m wearing my “Grumpy Designer” cap once again. It will put me in the proper frame of mind as I take you through some things that I’d like to see either evolve or just go away. Losing Motivation as a Designer and What You Can Do Sometimes, you just don’t want to do your work. It can be such a hassle to get up, start up the computer, fire up the software, and do what needs to be done. You feel tired and bored, having lost sight of why you chose a career in design in the first place, and you find yourself wondering whether you should just give it all up and become a dental hygienist. It can be really demoralizing to lose your motivation part of the way through a project, but what do you do if you absolutely have to get something done regardless of how you feel about it? I’m going to tell you about a technique you can use when you’re feeling burnt out and you simply can’t bear to think about taking one more step to complete that big, hairy project staring you in the face. A Look at the Proper Usage of the alt Attribute By now, most of the web design industry knows the importance of accessibility. We talk about it incessantly and implore our clients to take it seriously. There is no denying the impact it has on the web and those who use it. But sometimes the finer points get lost in the shuffle. For instance, we often hear screams from the virtual mountaintop of “Use alternative text on your images!”. This is good and well-intentioned advice. Still, it’s also a bit vague. While it’s good to know that the alt attribute can be beneficial in terms of accessibility, what we really need is context. What is the right way to use them? Are there times when we shouldn’t use them? These questions were inspired by a Twitter conversation I followed between designers and developers. It helped me realise that I’m not the only one out there who sometimes struggles with how to build websites that do right by users. Today, we’ll attempt to clarify the proper usage of this vital attribute.