topics that matter; ideas worth sharing

share a tip, submit a link, add something new

Internet Explorer most dangerous web browser; Other browsers not far behind

March 22, 2005, 10:41 AM —  ITworld.com, Ecommerce in Action — 

In the last six months, Microsoft has lost a significant percentage of the browser market, with users switching primarily to Mozilla's Firefox. A new security study suggests that, while there may be good reasons to switch web browsers, browsers like Mozilla and Firefox have their own risks.

Symantec's recent Internet Security Threat Report compares the number and severity of vulnerabilities among various browsers. Their finding? That "as security-conscious users have migrated away from Internet Explorer, attackers have followed suit."

The report looks at vulnerabilities between July 1st and December 31st, 2004. During this time, there were 13 vulnerabilities documented that affected Microsoft Internet Explorer, while there were 21 vulnerabilities affecting each of the Mozilla browsers. Six vulnerabilities were reported in Opera.

Users wanting a browser with an unblemished security record may have to switch platforms; no vulnerabilities were cited for Apple's Safari browser.

Mozilla Browsers Have More Bugs; IE's More Dangerous

While Mozilla's security problems seem to be growing, the report still makes special note of Microsoft's security vulnerabilities: "Though the share of vulnerabilities affecting the Mozilla browsers has increased, Microsoft Internet Explorer still has a greater proportion of high-severity vulnerabilities. Of the 13 vulnerabilities affecting Microsoft Internet Explorer documented by Symantec this period, nine were considered high severity." In comparison, seven vulnerabilities affecting Firefox were highly severe.

While vulnerabilities have been discovered in IE's competitors, few if any credible reports of attacks against them have been reported. The report notes, "It remains to be seen whether these browsers will live up to the expectations that many have for them."

Summary

The rise in vulnerabilities in alternate browsers suggests that they may have benefited from "security through obscurity". While IE alternates currently appear to be much safer, this may change, as they become more attractive targets.

ADDITIONAL RESOURCES

Symantec Internet Security Threat Report Highlights Rise In Threats To Confidential Information



ITworld.com, Ecommerce in Action

I like it!
Post a comment
The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff
Featured Sponsor

Get a broad understanding of important regulations and how you can make sure your site is in adherence.





Learn how VeriSign SGC-enabled SSL Certificates can help improve site security and customer confidence in the free white paper, "How to Offer the Strongest SSL Encryption." In this paper you will learn the differences between weak and strong encryption and what they mean for your site's performance.

Get VeriSign's free white paper: "The Latest Advancements in SSL Technology" and learn about the benefits of strong SSL encryption, Extended Validation (EV) SSL and security trust marks and what these SSL offerings can do for your site.

Now with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in this free VeriSign white paper.

More Resources