You are here: silicon.com > Software > Applications

Applications

Microsoft's IE now most secure browser, says Microsoft

No laughing at the back, now

By Munir Kotadia

Published: 11 February 2004 09:00 GMT

Last week's Internet Explorer patch has made the browser at least as secure, if not more secure, than any other browser, according to Microsoft UK's chief security officer.

Microsoft released a security patch for Internet Explorer last Monday that fixed three critical vulnerabilities; unfortunately the patch altered the way in which the browser handles certain URLs and forced many companies to reprogram their systems in order to accommodate the change. However, Microsoft has said the update means that Internet Explorer is now safer than any of the other browsers on the market, which users may find ironic due to the sheer number of vulnerabilities discovered in the browser over the past year.

Stuart Okin, chief security officer at Microsoft UK, said that he knew "a proportion" of customers would have problems after the change, but because of the high risks involved, the company decided not to wait any longer and released the patch: "We don't actually know how many users or systems or web administrators have been affected by this, but we knew there was going to be some with only a week's notice," he said.

Okin said that the longer the vulnerability was around, the more chance it would be exploited, which may have caused even more damage, so a week's notice was a compromise: "There are always going to be people that are caught out and surprised because they haven't been working with us or didn't know there was a problem. If we had given people more notice, then the risk would have been higher that someone would have used that exploit. If we had given them no notice, then they would have had more of a problem trying to fix their systems," he said.

Now the vulnerability has been fixed, Okin said Internet Explorer is at least as secure as other browsers such as Opera and Mozilla, but in some ways it is more secure: "I don't think we have got any less security than any of the other browsers and we have added a layer of protection that could make it a little bit more obvious to users if a phishing attack is occurring. If you look at today's technology, absolutely the (IE) browser is as secure as the others," he said.

But Okin warned that the fight against attackers and virus writers is far from over: "Don't get me wrong, vulnerabilities will come out and we will patch them; vulnerabilities will come out for our competitors and they will patch them as well. That is not going to change. I keep telling people that phishing attacks will continue in the future and they will catch people out," he said.

Two years after launching its Trustworthy Computing Initiative, in which Microsoft made security its first priority, the company still has a lot of work to do; not just for Internet Explorer, but for most of its software portfolio, Okin said. "We feel we need to do a lot more in terms of the browser, Windows and basically the entire technology base. It requires us to move onto the next level of security as an industry," he said.

Munir Kotadia writes for ZDNet UK

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
PHP Developer, Online Design Agency, Basingstoke - 35k - 40k

Excellent internet skills in using various browsers and search engines Knowledge of browser quirks and variations PHP Developer, Online Design ...

Web Applications Vulnerability Tester

You will also have reasonable coding experience and be able to check code for vulnerabilities before it is released. You will conduct regular ...

Front End Development / JavaScript / 40k / City of London

Ideally you will have experience with the following: - DHTML (3 years) - JavaScript (3 years) - CSS (3 years) - Cross Browser Development (3 years) ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: