In examining users of Adobe Flash (
Figure 42),
we found that, within the first week of an update release, nearly 80
percent of users install the software’s latest version. In other words,
it takes only about one week for the user population to get up to speed
with the latest version. This one-week “recovery” period represents
hackers’ window of opportunity.
In looking at late Q4 2015 in the
Adobe Flash graphic, we see a sharp drop in the number of users on the
newest version of the solution. In the time period we examined, Adobe
released five versions of Flash in quick succession, representing a mix
of functionality additions, bug fixes, and security updates. Such a
flurry of updates may confuse users. They may question whether they need
to download so many updates; they can become fatigued by the number of
upgrade notifications; and they may think they’ve already downloaded a
crucial update and can ignore new notifications. No matter what drives
their lack of interest in installing an update, it’s bad news for
defenders.