Microsoft's browser dominance at risk as experts warn of security holes
Monday 05 July 2004
Latest in Science
On Facebook
From the blogs
Manchester City top the ‘injury league’, with Manchester United bottom
The results of new research into every significant injury suffered by every Premier League footballe...
A Jubilee letter from a republican to royalists
With the Jubilee weekend edging ever nearer Rob Williams offers some help for those Royalists who ju...
Asylum seekers: When the questions tell us so much more than the answers
For the last four years I've been paying my karmic dues (I would say "contributing to the big societ...
GCSEs are a pointless waste of time
A few facts. Last year almost 70% of 16 year olds achieved at least 5 GCSE passes with grades A*-C. ...
Its curved blue "e" sits on almost every computer desktop in the world, but the global dominance of Microsoft's web browser could soon be over following a stark security warning from a senior panel of internet experts who say it opens the door to online criminals.
Its curved blue "e" sits on almost every computer desktop in the world, but the global dominance of Microsoft's web browser could soon be over following a stark security warning from a senior panel of internet experts who say it opens the door to online criminals.
They are urging all users of Internet Explorer (IE) to stop using the browser because they say it is vulnerable to hackers and credit card fraudsters.
The alert, from the US Computer Emergency Response Team, comes as a blow to the global giant Microsoft, which has fought successfully to retain its dominance of the browser market - 95 per cent of internet surfers currently use IE.
The team, which advises the US government and is a senior authority on Net weaknesses, said that flaws in the software expose users to criminals who can spy on their activities, steal their personal details or send junk e-mail from their computers without them knowing.
It said internet users should consider dumping the Microsoft software - which comes as standard installed on PCs - and switching to another web browser, such as the free Mozilla or commercial Opera products.
In its warning, under the technical title "Vulnerability Note 713878", the agency notes that IE has "significant vulnerabilities in technologies" but adds: "It is possible to reduce exposure to these vulnerabilities by using a different web browser."
The advice - which echoes rising concern in the internet security community - follows a continuing tide of attacks taking advantage of holes in IE.
In the past seven days, security experts have discovered criminals using two different "vulnerabilities" in IE to exploit Windows PCs. The first, called "Download.JECT", silently redirected the browser to a Russian website and made it download software that monitored key strokes and would send out spam.
Last week researchers at the Internet Storm Centre discovered a malicious program that used a flaw in the software to install itself on the user's PC when a particular pop-up ad appeared. It would then monitor the user's typing when they visited any of 50 bank sites, including Barclays Bank, Citibank and Deutsche Bank.
Neil Barrett, security consultant of Information Risk Management, which carries out internet security audits of companies and software, said: "The number and seriousness of the vulnerabilities is now getting past a joke.
"Some of things that can be done to it are really powerful from the hacker's point of view. There are presently more than 30 attacks that it's vulnerable to which haven't been fixed by Microsoft."
Johannes Ulrich, chief technology officer for the Sans Internet Security Centre in the US, said: "To keep on using IE is like playing the lottery. You're hoping the sites you visit aren't compromised." He said the most recent attacks were "a wake-up call for users to switch to another browser".
The problems with IE are symptomatic of Microsoft's difficulties with security, experts said. The arrival of the internet has led hackers to concentrate on the most widely used products searching for weaknesses, and scores of flaws have surfaced in Windows, as well as Microsoft's IIS web server software and its Outlook Express e-mail software. In January 2002 Bill Gates, founder of Microsoft, e-mailed all employees saying that the company should alter the way it wrote software to incorporate greater security against such threats.
But the damage may already have been done. Steve Linford, chief executive of the anti-spam organisation Spamhaus, said: "The problem is that Microsoft assumes its users are stupid, and it comes with everything wide open to attack.
"Microsoft seems to think that if it has things turned off, people will never discover how to turn them on."
Spamhaus estimates that more than 70 per cent of the 8 billion spam e-mails sent every day come from home and business PCs that have been subverted by programs downloaded over the Net.
VULNERABILITIES IN EXPLORER
¿ Pop-up ads can silently download software that will use your computer to send out spam or install "Trojans" that watch your typing.
¿ E-mails by "phishers" can grab bank details by using malicious internet addresses preceded by a real one. If you open it with IE, you will only be shown the first part of the address, with the rest hidden. Users may trust the address and give the criminals their details.
¿ Another "phishing" attack uses the "fake address" method above and puts a pop-up window with an image of a padlock on top of the window. This looks like a "secure" website. IE has no built-in means to block pop-up windows.
¿ Some pornography websites use IE to silently download software that changes the computer's internet settings to dial a premium-rate number.
¿ One pop-up ad installs software that monitors whether you visit any of 50 banking sites, including Barclays and Citibank. When you do, it monitors your keystrokes and sends them to a website in San Diego.
- 1 Brazil rocked by abortion for 9-year-old rape victim
- 2 News in pictures
- 3 Four Britons face death by firing squad after 'smuggling cocaine into Bali'
- 4 The 'suburban smuggler' facing death penalty in Indonesia
- 5 Vatileaks: Hunt is on to find Vatican moles
- 6 In pictures: The bewildering face of China
- 7 Help me decide future of press, Leveson asks Blair
- 8 Osborne's got it wrong on the economy, warns public
- 9 British housewife could face death penalty over Bali cocaine smuggling
- 10 Hague sent packing by Russia as Annan peace plan crumbles
- 1 Robert Fisk: Clinton's $33m raid on Pakistan shows that, in the end, hypocrisy will win
- 2 Brazil rocked by abortion for 9-year-old rape victim
- 3 Robert Fisk: The West is horrified by children's slaughter now. Soon we'll forget
- 4 Richard Benyon: The bird-brained minister
- 5 Sex in dressing rooms and Play School presenters 'stoned out of their minds' - inside BBC Television Centre
- 6 Fat? Really? Olympic hope laughs off official’s jibe – but others aren’t amused
- 7 'Hello mum, this is going to be hard for you to read ...'
- 8 Alien: The monster returns?
- 9 Coke reveals its secret: It may need to carry a cancer warning
- 10 French in uproar over oral sex anti-smoking posters
Experience the Heineken Hub
Get free wi-fi and exclusive i content while you enjoy a tasty pint of Heineken at participating pubs.
Can you imagine a career in teaching?
Be inspired to teach - let real teachers show you how rewarding the job can be.
Playing a game-changing role during the Games
Cisco is providing the solutions for London 2012's complex IT needs.
Enter the latest Independent competitions
Win anything from gadgets to five-star holidays on our competitions and offers page.
Business videos from commercial thought leaders
Watch the best in the business world give their insights into the world of business.
Career Services
Day In a Page



Comments