ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

2004: Internet Explorer's year of shame

Munir Kotadia ZDNet.co.uk

Published: 09 Jul 2004 10:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Internet Explorer has had a year to forget. IE owns around 95 percent of the browser market and is relied upon by the majority of computer users as their primary interface with the Web.

However, since the start of the year, around a dozen new security vulnerabilities have been found in either the browser itself or in the browser's interface with Windows.

Some of the most important problems have included: a flaw that allowed phishers to fool the address bar into displaying a false URL; a way of disguising malicious executable files as "safe" documents; numerous vulnerabilities that could allow an MSBlast-type worm to spread quickly; a flaw that allowed Web sites to install a toolbar on the victims' computers and triggers pop-up adverts; a vulnerability that enabled pop-up adverts to read keystrokes and steal passwords; and most recently, the discovery of a method of bypassing the computer's security in order to run malicious programs on a Web surfer's computer.

Despite the long list of security flaws, Microsoft insists its browser is safe to use -- with certain precautions -- and is, unsurprisingly, adamant that users should not be tempted to switch over to an alternative browser.

Stuart Okin, chief security officer at Microsoft UK, said IE is a "very strong" browser and reiterated that there isn't a magic solution to fixing all the security vulnerabilities in complex code -- no matter who has written it.

"There are always going to be vulnerabilities in software. It doesn't matter what browser, application or operating system you use," said Okin.

According to Okin, all known vulnerabilities in IE will be addressed in the forthcoming Service Pack 2 for Windows XP, which is expected before the end of this summer.

However, numerous organisations -- including The Computer Emergency Response Team, the official US body responsible for defending against online threats -- are advising companies to seriously consider alternative browser technologies.

Among the proponents for change is Simon Perry, the vice president of security at Computer Associates. According to Perry, larger companies are less vulnerable to IE's security problems but small firms should be using an alternative.

"Medium to large businesses have the capability to look at vulnerability and patch management systems. The difficulty for these firms is a move away from IE will pretty much outweigh the security advantages," Perry said.

However, Perry advises smaller companies to switch over to an alternative.

"Small businesses should be seriously looking at alternatives because they are less likely to be able to maintain very good security around the browser with vulnerability management. Smaller businesses should seriously be looking at changing browsers," said Perry.

Browser alternatives include Mozilla, Firefox, Opera and Nestcape -- although no browser is immune to security problems. Today, developers of Mozilla released a fix for a vulnerability that affected PCs running Windows XP that use the Mozilla browser.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
78 out of 160 people found this useful



Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS,

Technical Support Engineer Windows XP 2003, Microsoft Outlook, LANs, WANs, DNS, - Lambeth - 2198 RM helps to push the boundaries of technology to ...

3rd Line Support (Windows Server 2003, Windows XP, MS Exchange, AD)

I am looking for a 3rd Line Support Engineer for a contract role in Southampton, Hampshire. To be considered for this opportunity you must be able to ...

TWS Scheduling Specialist - UNIX AIX/TRU64, Windows O/S, MS Office, Shell - St Davids Park, Ewloe, Deeside

Provide 2nd level infrastructure support as required - Undertake the diagnosis and completion of Root Cause Analyses to enable Problem Management as ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments