What can be done for programs that have auto updates? I don't expect to analyze Microsoft updates, but our firewalls, antispyware and AV programs sometimes install upgraded engines in addition to their signature files.
Would you suggest altering the configuration so that the program only notifies of an update rather than automatically installs it?
In some cases, this would necessitate going to their website and manually downloading/installing the update files.
My feeling is that when it comes it security programs, further installation analysis would be too time consuming.
If we can't trust those programs, what can we trust?!
