Test System Security

cancel
Showing results for 
Search instead for 
Did you mean: 

Importance of Installing Security Updates

This is a message to the NI user community. I'll likely cross-post to a few different forums.

 

Earlier this month, NI issued a critical security update for NI-PAL, which is used in many NI drivers, including NI-VISA: Local Privilege Escalation in NI-PAL - NI. In addition to the web post, we also issued a security email to those subscribed to received security updates, and pushed messages out through NI Update Service (which shows pop ups on Windows systems). Unfortunately, our telemetry shows that not many users have actually installed the recommended patch.

 

The purpose of this post is two-fold:

  1. Hopefully everyone reading this forum goes and installs the recommended patch
  2. Feedback from you on why you think users aren't installing critical security patches, and what we could do differently to reach users.

 

Evan Cone

NI Director of Product Security

Evan Cone
NI Director of Product Security
Message 1 of 11
(427 Views)

The first NI screen we see is the LabVIEW launch screen and then either the project selection dialog or we just doubled the lvproj file and it opens directly.

 

3 suggestions from the top of my head:

1. Show the update status in the main project dialog and the project selection dialog.

 a. A never check for update could be shown clearly as bad idea

 

2. The update preferences should be front center in each main NI application instead of hidden away in a separate application

 

3. Important update should be announced in product as an extra dialog pop-up which should be harder to ignore than just clicking cancel or enter, to make people evaluate the message, ignoring will be willful then

 

NI package manager should also show the update and possibly highlight patches for high CVE scores

 

Also I think it's a good idea to publish a white paper on the NI architecture for update distribution from the NI Update Service all the way to the hardware firmware both in development and with deployed applications and targets. The current mention of the Securty Update is a one liner, we need to be able to plan and for that we would like more information on how updates are designed to flow down to the nooks and crannies of the Ni ecosystem.

andrebuurmancarya_0-1787915971801.pngandrebuurmancarya_0-1787915971801.png

 

Regards,
André (CLA, CLED)
Message 2 of 11
(362 Views)

Great idea, a notification in LabVIEW itself would be the right place. I would suggest a banner in the upper right corner of the getting started window. Security patches in red, bonus points for launching NIPM and a link to the release notes.

Message 3 of 11
(353 Views)

Hi Evan,

 

Many reasons that patch isn't applied :

 

1. Where I work, every updates are checked first by an internal security team. Therefore, the NI update service is disabled on every client computer.
Updates are packaged and distributed through our internal channel. Released pushed by NI are considered 'untrustable' until they are verified.
So users do NOT see these updates. And there is no notification that pops-up where it couldn't be missed (Windows notification, LV/TS/VS/MAX splash screen, ...)

2. First thing a user see when opening NIPM is that NIPM must be updated... Automatic updates are forbidden where I work. Therefore NIPM must  be audited first by an internal security team. So we're back at point 1. It is a nonsense that NIPM must be so frequently updated, many people told NI many times about this.

 

3. Since NI shifted to subscription schema, we didn't see any change regarding LV updates for example. Peole are still used to update their installation only twice a year, at most. If NI were regularly publishing updates on their major tools (LV, TS, VS), maybe people would get used to update their installations more regularly.

 

4. Release documentation is historically very poor with NI product, even on the major ones.
When an update is published, customers require the update to be well documented (list of all changes, dependencies, behavior changes expected, registry modifications, etc) and explained.

CLA, CTA, LV Champion
View Cyril Gambini's profile on LinkedIn
This post is made under CC BY 4.0 DEED licensing
0 Kudos
Message 4 of 11
(262 Views)

". Where I work, every updates are checked first by an internal security team. Therefore, the NI update service is disabled on every client computer.
Updates are packaged and distributed through our internal channel. Released pushed by NI are considered 'untrustable' until they are verified.
So users do NOT see these updates. And there is no notification that pops-up where it couldn't be missed (Windows notification, LV/TS/VS/MAX splash screen, ...)"

 

This is true for many companies, and it's understandable.

 

Another challenge, the teams responsible for reviewing software updates are not always familiar with NI products and may not be aware of NI-specific security issues. In those cases, the best we can do is make security information readily available and encourage users to work with their IT and security teams when updates are released.

 

I encourage everyone reading this to subscribe to NI security updates: Security - NI.

 

 

Message 5 of 11
(246 Views)

I've been looking into this for a couple of customers who contacted me, saying they have not been receiving the security updates. 

 

In some cases, the end user's email had changed since they signed up, and they needed to update their ni.com profile email address. In a couple of cases, people who thought they had signed up were not in the list. I asked them to sign up again.

 

In most cases so far, our records show that the emails were sent out. If you don't think you've been getting the security notifications, check:

- The last email was sent out on June 10, 2026.

- The email was from securitynotifications@direct.ni.com.

- The email was titled "NI Releases New Security Advisor for NI-PAL"

 

If you can't find the email, please email me at steve.summers@emerson.com.

 

You can subscribe to security notifications at https://landing.ni.com/en-us/email-subscriptions 

0 Kudos
Message 6 of 11
(181 Views)

One more suggestion reading the last post : 

I receive an average of a hundred email per day. Between work email and commercial emails, I sometimes do not take a deep look at all the emails.
I would suggest prefixing the email subject with 'NI SECURITY UPDATE' (or something similar). It would better catch the eye.

When I read 'NI Releases New...' I think first about a commercial email for some new product rather than a critical update that I should apply in no time.

CLA, CTA, LV Champion
View Cyril Gambini's profile on LinkedIn
This post is made under CC BY 4.0 DEED licensing
0 Kudos
Message 7 of 11
(156 Views)

Having the sender of those messages defined would help just as well.

Yet that would be convenience provided by NI 😉

Don't think we can make NI responsible for our Inbox-Mess 😀

0 Kudos
Message 8 of 11
(154 Views)
I'm not trying to make NI responsible for a crowded inbox 😊.
My suggestion is simply that the email subject should better reflect the importance of the message, rather than being perceived as a promotional or commercial email.
CLA, CTA, LV Champion
View Cyril Gambini's profile on LinkedIn
This post is made under CC BY 4.0 DEED licensing
0 Kudos
Message 9 of 11
(151 Views)

An email notification was sent out today. It was sent from securitynotifications@direct.ni.com on September 2 and was the subject was "Security Notification: NI Releases New Security Advisories – August 2026."

 

If you didn't receive it, but think you are signed up to receive these, let me know. steve.summers@emerson.com

0 Kudos
Message 10 of 11
(114 Views)