Don't need it? Don't install it.

Apple may have recently shoved an unsafe update down your PC's throat, but the broader problem is Apple, or anyone else, installing any unnecessary program on your PC.

By sjvn  11 comments

If you use any Apple program on Windows you may have noticed recently a rather odd Apple Software Update dialog box telling you under the Updates heading that you need the iPhone Configuration Utility 2.1. I did, and my reaction was: "I do?" After all, I use an iPod Touch, not an iPhone, and iTunes does just fine with managing it. Then, I found I was also getting the notice on Windows PCs that I've never used with my Touch. What is this?

A little investigation revealed that the iPhone Configuration Utility is actually a tool for business system administrators to set up and administer corporate iPhones . Even if I were using an iPhone, I'd need that program like I'd need season tickets to the Detroit Lions. So, I haven't installed it-and I really wish Apple would stop bugging about it.

I didn't think anything more about it. I don't install programs I don't need or plan on testing. Others though did and they discovered that this completely unneeded Apple shovelware for 99.9999% of all users installs not just a configuration program, but the Apache Web server as well. For the tiny number of people who do need it, this lets corporate iPhone users 'phone' in to the business Web server for updates.

For the millions of everyone else having a Web server on your PC is horrible security risk. It's hard enough keeping Windows secure, but adding a totally unregulated Web server to the mix is like throwing matches at a pool of gasoline.

What was Apple thinking!? Actually, I rather doubt they were thinking. As Windows expert Ed Bott pointed out, Apple has long used "its automatic update process to deliver massive amounts of new software to users." That's often software you don't need, and in the case of the iPhone Configuration Utility it's actively making securing your Windows PC harder.

In general, I like Apple products, but I don't like anyone forcing software on me. In fact, I recommend that people only install the programs they need on their PCs. Every last program you install on PC potentially adds what security experts call an 'attack surface' to your computer. By this they mean that you may be adding a new weak spot in your PC defenses.

A Web server, like the one Apple adding to you PC isn't a weak spot though. It's a gateway just asking to be hammered on by an attacker. Managed properly Apache is as safe a Web server as you'll ever find, but ordinary PC users shouldn't try to manage it, and even an expert can't do anything with it if they don't know it's there.

If you haven't installed this program yet, don't. You don't need it, and you don't want it. If you have installed it, uninstall it with Windows' control panel uninstall utility. On XP, that the Change or Remove Program applet. So long as you're at it, you might want to get rid of other programs that you never use. Unused programs make be completely harmless, but they may also be security time-bombs. Stick with just the programs you need and use, and you'll be a better off.

Finally, Apple? Stop pushing software on people! If we want it, we'll download it ourselves. Thank you. Thank you very much.

11 comments

    Anonymous 44 weeks ago
    yer comment about the Lions was just wrong!!!! Get better examples than attackin like that...
    Anonymous 2 years ago
    I thank you so much for the info on this unecessary download..update..that i had to install for the ipod someone gave me..I got rid of it after reading your post and hope that this is the reason my computer has been acting strangel; we'll see, and thanks for being there for us uneducated comp. users..now I wish someone like you was around to save my 401k!!
    Anonymous 2 years ago
    I don't think it's apple that's the problem but bloggers that write before they think. Reporting unsubstantiated stuff, just because they think it's true. Maybe a little research first?-you don't need to install it. it's offered. just like windows update.-it doesn't install a running webserver.
    Anonymous 2 years ago
    @sjvn: did anyone ever tell you you look like John Malkovich?
    Anonymous 2 years ago
    "Those of us on real operating systems". You people should be sterilized. And I am not kidding.
    Anonymous 2 years ago
    Those of us on real operating systems don't worry about Apache, as it's already installed but not active.Compare and contrast this small hypothetical vulnerability with the story sitting in the sidebar, "Microsoft says turn off Windows feature to protect Windows". There's an example of "shovelware" - a protocol added SOLELY to snipe at open competitors, which in turn opens the system up to complete takeover.
    Anonymous 2 years ago
    The link you use to demonstrate that the iPhone Configuration Utility installs Apache merely mentions a Ruby web service listening on localhost:3000. That's not Apache. Additionally, the most recent version of the utility (which would have been distributed via automatic updates) is a stand-alone executable, you do not use a browser for configuration and there's no process listening on port 3000.Do you have anything to back up your claim of an Apache installation?
    sjvn
    sjvn 2 years ago
    Miracles happen. Hours after I, and lots of other people, wrote about Apple's mis-step, it appears they've pulled iPhone Configuration Utility from Software Update for Windows.See: http://www.computerworld.com/s/article/9138620/Apple_pushes_unnecessary_software_to_Windows_PCsfor the details.Steven
    Anonymous 2 years ago
    A while ago I noticed a program on my PC called Bonjour. I had no clue what this was, so looking it up, I find:"Bonjour is Apple's implementation of the Zero Configuration Networking Standard. Bonjour for Windows includes a System Service that helps applications discover shared services on the local network, printer discovery wizard, and IE plug-in for discovering local Web servers."Do I need this to detect my iPod or something? Apparently not:"iTunes uses Bonjour to find shared music libraries, to find AirPort Express devices for streaming music to, and to find Apple TVs."I don't use anything like this, I only use iTunes to add/remove files on my iPod, I don't even sync my play lists, as I hate using iTunes for listening to music. But I still haven't removed it because I don't know if it will cause massive problems running iTunes, or just disable those features.
    Anonymous 2 years ago in reply to Anonymous
    iTunes will work just fine without bonjour, go ahead and uninstall it. It's actually an interesting DNS related technology but yes highly annoying that apple forces it down peoples's throats.
    Anonymous 2 years ago in reply to Anonymous
    You can uninstall Bonjour safely without impacting any major iTunes functionality. You'll notice that some tabs in the preferences screen will display the text, "The Bonjour service wasn't properly installed. Bonjour is required to share music with others. Please uninstall iTunes, then install iTunes again to use this feature." Presumably the corresponding functionality is disabled. I haven't had any issues.

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Aberdeen Analyst Insight: Does Your Enterprise Have a Dropbox Problem?

      Without policies, awareness and supported alternatives for sharing files securely, end-users will often overlook security and compliance in favor of getting the job done. Read this whitepaper to determine if your enterprise has a "Dropbox Problem" and ways successful organizations address this problem.

      White Paper

      BYOD: How to Design Secure Usage

      With employee mobile devices springing up throughout your workplace, how can you establish an individual liable usage policy? Use these questions from Good Technology to help prepare your organization.

      White Paper

      Good Technology State of BYOD Report

      New data finds Finance and Healthcare industries dominate BYOD picture and that users are willing to pay device and service plan costs if they can use their own devices. Read More>>

      White Paper

      A Proactive Approach to Server Security

      Learn why security-conscious organizations are taking a more proactive approach to server security. Download this Spire Research whitepaper to understand how you can eliminate the threat caused by today's more advanced threats and protect your organization's most valuable data.

      White Paper

      Protection Against Modern Cybersecurity Threats

      Download this case study to learn how this accounting and consulting giant uses Bit9's adaptive application whitelisting to offer employees flexibility without jeopardizing enterprise safety.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question