ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

2004: Internet Explorer's year of shame

Munir Kotadia ZDNet.co.uk

Published: 09 Jul 2004 10:45 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Internet Explorer has had a year to forget. IE owns around 95 percent of the browser market and is relied upon by the majority of computer users as their primary interface with the Web.

However, since the start of the year, around a dozen new security vulnerabilities have been found in either the browser itself or in the browser's interface with Windows.

Some of the most important problems have included: a flaw that allowed phishers to fool the address bar into displaying a false URL; a way of disguising malicious executable files as "safe" documents; numerous vulnerabilities that could allow an MSBlast-type worm to spread quickly; a flaw that allowed Web sites to install a toolbar on the victims' computers and triggers pop-up adverts; a vulnerability that enabled pop-up adverts to read keystrokes and steal passwords; and most recently, the discovery of a method of bypassing the computer's security in order to run malicious programs on a Web surfer's computer.

Despite the long list of security flaws, Microsoft insists its browser is safe to use -- with certain precautions -- and is, unsurprisingly, adamant that users should not be tempted to switch over to an alternative browser.

Stuart Okin, chief security officer at Microsoft UK, said IE is a "very strong" browser and reiterated that there isn't a magic solution to fixing all the security vulnerabilities in complex code -- no matter who has written it.

"There are always going to be vulnerabilities in software. It doesn't matter what browser, application or operating system you use," said Okin.

According to Okin, all known vulnerabilities in IE will be addressed in the forthcoming Service Pack 2 for Windows XP, which is expected before the end of this summer.

However, numerous organisations -- including The Computer Emergency Response Team, the official US body responsible for defending against online threats -- are advising companies to seriously consider alternative browser technologies.

Among the proponents for change is Simon Perry, the vice president of security at Computer Associates. According to Perry, larger companies are less vulnerable to IE's security problems but small firms should be using an alternative.

"Medium to large businesses have the capability to look at vulnerability and patch management systems. The difficulty for these firms is a move away from IE will pretty much outweigh the security advantages," Perry said.

However, Perry advises smaller companies to switch over to an alternative.

"Small businesses should be seriously looking at alternatives because they are less likely to be able to maintain very good security around the browser with vulnerability management. Smaller businesses should seriously be looking at changing browsers," said Perry.

Browser alternatives include Mozilla, Firefox, Opera and Nestcape -- although no browser is immune to security problems. Today, developers of Mozilla released a fix for a vulnerability that affected PCs running Windows XP that use the Mozilla browser.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
78 out of 160 people found this useful


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Linux Systems Administrator - Linux Windows XP, Network Connectivity

Linux Administrator - Linux Redhat Systems Administrator Windows XP, Network Connectivity, Backup, DR, Market Data (not essential Reuters / Icap). ...

3rd Line Support (Windows Server 2003, Windows XP, MS Exchange, AD)

I am looking for a 3rd Line Support Engineer for a contract role in Southampton, Hampshire. To be considered for this opportunity you must be able to ...

Support Analyst - 2nd line - Windows XP - ITIL - 175-200/day

Windows XP / Blackberry / ITIL / Excel / Poweerpoint / Asset Mgmt. Urgent requirement - 2nd line support role. The client are a global asset ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment