|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (12 bit)
Join Date: Oct 2003
Location: Manchester, UK
Posts: 2,374
|
Browser security
I was just thinking how people everywhere are telling each other to go with Firefox or other alternative browsers because of the many vulnerabilities of IE. But then it got me thinking, how long is it until the people who expose IE's problems notice people are using these other browsers? Won't that mean these people will find security holes in these alternative browsers instead?
|
|
|
|
|
|
#2 |
|
Got Privilege?
Join Date: Jun 2001
Location: IA go Hawks
Posts: 1,257
|
I don't think that would be anytime soon. I believe the hackers are actual after Microsoft not the users.
__________________
P4 2.8E | 1.5GB ddr400 VR dual channel | Sony CD-R/RW | Windows XP | ATI X1950pro | Viewsonic P95F | Intel D865PERLX | WD 36g Raptor | MCHSI 3mb Cable "Computers are useless. They can only give you answers." Pablo Picasso (1881 - 1973) "Absence of proof is not proof of absence." William Cowper (1731 - 1800) Wisdom Speaks: Have in your mind that which would constitute a miracle for you. Get the vision. Suspend disbelief and skepticism. Allow yourself to take the journey toward real magic. |
|
|
|
|
|
#3 | |
|
I am, in reality, a moose
Staff
Premium Member
Join Date: Aug 1999
Location: RTP, NC
Posts: 2,439
|
Re: Browser security
Quote:
every product has security holes in some manner shape or form. Lets look at it from a hacker's point of view: where can i obtain the deepest penetration across the widest number of targets? A) poke, prod & disassemble a product that is used by less than 2% of the computing population B) poke, prod & disassemble a product that is used by 80% of the computing population. People are people, they want to most bang for their buck (so to speak) and don't want to expend any more additional energy than is necessary. Plus, in many ways, MS does a lot of their work for them: MS ID's a security hole, issues a patch, hackers reverse engineer the patch to create an attack and rely on the intrinsic laziness of people not to patch their systems as recommended by the manufacturer. Patching is, unfortunately, basic maintenance for a PC, akin to chaning the oil, rotating the tires and getting tune ups for your car. |
|
|
|
|
|
|
#4 |
|
Member (10 bit)
Join Date: Jul 2002
Location: University of California, Santa Barbara
Posts: 800
|
http://www.w3schools.com/browsers/browsers_stats.asp
Mozilla's popularity for June is 11.4%, which is still significantly smaller than IE5/IE6's collective 81.4%, but still a good portion. In the next few years, depending on the success of the next IE, mozilla could well become a viable target. But with IE, it's already connected to other parts of windows, whereas Mozilla is an application that stands much more on its own, which makes it more secure. Also, any security flaw found is likely to have a fix sooner, and in my personal opinion, people who use Mozilla are not as much the "set it and forget it" type, they would get the updated version sooner. |
|
|
|
|
|
#5 |
|
Member (12 bit)
Join Date: Oct 2003
Location: Manchester, UK
Posts: 2,374
|
But what I'm saying is that with other browsers being recommended so much, it could soon become a much more viable candidate for attck, like mattg said. But I disagree where you say the security flaw will have a fix sooner, I seriously doubt the creators of these alternate browsers have the manpower of Microsoft's patch developers.
|
|
|
|
|
|
#6 | |
|
Registered User
Join Date: Nov 2001
Posts: 1,965
|
Quote:
Two vulnerabilities in IE have been around for 11 months now without any patches from MS, they allow attackers to to install malware when a web page is opened, nothing more. OTOH, Firefox, being Open Source, has plenty of developers reviewing the code, so security holes get fixed in no time, even before that attackers discover them. And IE is integrated into the OS, so vulnerabilities in IE allow attackers to do much more damage to the whole OS. IE runs unsafe VB scripts and ActiveX controls, the source of like 99% of malware. Firefox doesn't support any scripting language other than the sandboxed JavaScript, and its extensions aren't automatically installed, they are easy to uninstall, and the developers are working on a feature that makes Firefox refuse to install extensions from untrusted websites, by using a white list of trusted websites. The latest version of Firefox makes it very easy to install updates, updates are small in size and can be installed automatically while using the browser. To patch IE you need to use Windows Update, download no-so-small files, and in many cases, reboot the computer. I don't think that Firefox will be targeted when/if (hopefully when ) it becomes more popular. The Open Source Apache web server is more popular than MS IIS according to Netcraft, it runs 70% of the web, and still, IIS gets much more exploits and viruses than Apache, and Apache gets fixes faster.MS products are usually less secure than alternatives, because of this, they are targeted. |
|
|
|
|
|
|
#7 | |
|
Professional gadfly
|
Quote:
|
|
|
|
|
|
|
#8 | |
|
Certified Audio Nut
|
Quote:
__________________
"I'm not lying. I'm writing fiction with my mouth." - Homer Simpson My Miscelaneous Gallery ASUS P7P55D PRO / Intel Core i7 860 / 8GB Mushkin DDR3 1600 RAM / OCZ Vertex 2 120GB SSD / Seagate 1TB 7200.12 / Asus Radeon 5870 1GB / LG Super-Multi 22x SATA DVD-RW / Windows 7 Home Premium 64bit / Cable Modem / HT Omega Striker 7.1 Sound Card / FSP 700W PSU / Logitech MX1000 Wireless Laser Mouse / Asus 24" 16:9 LCD w/Webcam / Axiom Audiobyte 2.1 Speakers Last edited by Hi Ho; 07-02-2004 at 03:46 PM. |
|
|
|
|
|
|
#9 | |
|
Registered User
Join Date: Nov 2001
Posts: 1,965
|
Quote:
For example, without ActiveX, Windows Update won't work any more. |
|
|
|
|
|
|
#10 |
|
Certified Audio Nut
|
ZDnet - Microsoft posts work-around for IE flaw
Hmmm... Looks like they're already looking to change that. |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|