back to article vCenter's phone-home 'customer improvement' feature opened remote code execution hole

Ever worried that software phoning home application performance data so vendors can learn from real-world users might become an attack vector? If so, your nightmare just came true: VMware's vCenter has just that problem, thanks to its use of the Adobe-derived open source BlazeDS messaging tool to process messages. VMware's …

  1. GrumpyOldMan
    Facepalm

    Never ever opt in.

    I never ever ever opt in to these things. I don't trust them.

    1. joed

      Re: Never ever opt in.

      You don't have to. You are opted in (usually) and have to opt out (often not trivial and sometimes impossible - e.g. Windows 10)

  2. Korev Silver badge
    Holmes

    Why are vendors so keen on this?

    Time and time again, vendors (software, hardware & scientific equipment) try to push a phone home or we dial into our network when they want system and seem very surprised when we're not keen. Maybe events like this will explain to them why companies like mine regard it as a Very Bad Idea™

    1. Trigonoceps occipitalis

      Re: Why are vendors so keen on this?

      "Maybe events like this will explain to them ... "

      I doubt it.

    2. Field Commander A9

      Re: Why are vendors so keen on this?

      How else are vendors supposed to get real world usage data? Listening to a few whinnies on web forums?

  3. Flakk

    To Paraphrase Blackadder...

    "If you want something done right, kill Adobe first."

    1. Field Commander A9

      Re: To Paraphrase Blackadder...

      You have clearly never worked with anyone who's in the art/media/creativity front.

  4. jamesb2147

    Patches

    Simon, I don't know why you think it's a good idea to keep your ESXi patches up to date. Doing exactly that will cause you nothing but heartache, as your beloved VMware lets you down almost every time.

    Frankly, that's some bad advice, bro. I know why you say it. I would agree with regards to most other vendors, but VMware has a special knack for somehow messing up their updates.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like