Computing Comment
Computing Comment

Microsoft faces up to browser flaws

Mass migration to Windows XP could raise serious security questions for users

Written by Chris Green

Another week, another security patch! Microsoft has been pressed into action to release yet another patch to plug a hole in its Internet Explorer 6 web browser, which has accumulated an impressive record of holes: over 150 since 18 April 2001. What is more, it is not even a final solution to the latest in a catalogue of security compromises and back doors created by what should be a harmless, albeit essential, piece of PC software.

At Microsoft's TechEd developer conference in Amsterdam earlier this month, I took time out to have a frank discussion with Detlef Eckert, senior director of trustworthy computing at Microsoft about the continuing security problems that are blighting the world's biggest software developer.

Right now the company is almost fanatically committed to completing service pack 2 for Windows XP, the most security-focused update the company has ever released for one of its products. The new service pack will introduce a new, more powerful firewall, with basic predictive scanning capabilities, it will enable almost every security feature by default, including the firewall and will also address many existing security glitches in the operating system through a combined patch install, which providing users actually install the service pack, will address any lax patching over the last year.

'Service pack 2 is going to add significant new security to Windows XP, which will help stop a great deal of viruses, worms and other illegal code from attacking the browser. It won't fix security vulnerabilities in the browser itself, but will add an important barrier between the browser and security attacks' said Eckert.

The concern is that this year will see massive new rollouts of Windows XP on the desktop in US businesses. For many, this will also see a mass migration from the unstable, but safe IE 5 to the stable, but inherently insecure IE 6.

While the move will provide access to a robust operating system (compared to previous versions of Windows), it is likely to bring new patching headaches to businesses, and leave organisations vulnerable that were not previously.

This sudden growth in IE 6 deployment will leave companies with the heavy burden of mass legacy patch deployment from the start, and a continuing security headache, as they rush to keep their patching regime ahead, or at least in step with the hackers and virus writers.

With business mass-adoption of Windows XP set to peak this year, the need for a new, trustworthy browser is paramount, especially as IE 6 is an elderly product in software terms - it's nearly three years old.

Eckert conceded that this is not a new suggestion to Microsoft, and several users have expressed similar concerns about the ageing IE6 browser. He added that the replacement for Windows XP, code-named Longhorn and due for release in 2006 will have a new browser release, though no decision has been made on whether that will be a new version of IE or a whole new browser technology.

Last year Microsoft finally admitted defeat and axed its ailing IIS (Internet Information Server) 5 web server. IIS has been a constant pain for both Microsoft and Windows server users. having suffered from stability and serious security issues for years. The run of emergency patches released during 2002 and 2003 to fend off a barrage of hacker, virus and worm attacks forced Microsoft to kill the current product and completely rewrite it in time for the release of Windows 2003 Server.

The IIS6 web server within 2003 is a completely new piece of code, and the time, cost and effort needed to redevelop its web server from scratch has been rewarded with the news that 116 has not suffered a single breach thus far.

Having addressed the single biggest security problem on the server platform, it is time Microsoft did the same thing on the desktop and put Internet Explorer, and its millions of users worldwide, out of their collective misery.

For now, it seems that companies and users looking to escape from the security problems that dog IE will have to think the unthinkable and look at switching to the likes of Netscape Navigator and Mozilla, or the highly regarded Opera.

Tags:

reader comments

related articles

Critical IE flaws

Microsoft warns of three critical IE flaws

Hackers could take complete control of an affected system 02 Aug 2004

 

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation