You are here: silicon.com > Software > Security Strategy

Security Strategy

US uni tells students to dump IE

IT dept 'strongly advises' students to look at alternatives...

Tags: bofra, penn state, flaws, holes

By Jim Hu

Published: 10 December 2004 10:00 GMT

Citing security risks, a US university is urging students to drop Internet Explorer in favor of alternative web browsers such as Firefox and Safari.

In a notice sent to students on Wednesday, Pennsylvania State University's Information Technology Services department recommended that students download other browsers to reduce attacks through vulnerabilities in the Microsoft software.

The university said "media reports" and a string of warnings by Carnegie Mellon University's Computer Emergency and Response Team led to its recommendation.

"We're not telling people to wipe off IE, because you need IE to do operating-system updates," Robin Anderson, a spokeswoman for Penn State's ITS department, said in an interview. "We're telling [students] there are alternatives - and for them to strongly look at those."

Microsoft said internet users have a choice in web browsers, adding that the company has invested heavily in online security.

"While Internet Explorer is the choice of hundreds of millions because of the unique value it provides, we respect that some customers will choose an alternative," a Microsoft representative wrote in an email statement.

Penn State's new policy highlights the many security vulnerabilities that have dogged IE over the past few months. Nearly two dozen holes in the web browser have been discovered during the fall, ranging in degrees of seriousness.

Malicious code writers have targeted security holes in the browser to launch attacks or install spyware. These attacks are often launched when a victim clicks on a specific web link, opening the door for criminals to take over the person's computer. Once the PC is compromised, the attacker could access account information, load other software and delete files.

Other attackers have targeted IE vulnerabilities to launch viruses. In November, security researchers discovered two viruses, Bofra.A and Bofra.B, loosely based on the MyDoom source code.

Security concerns have prompted a growing number of internet users to embrace different browsers, such as Firefox, Safari and Opera. While IE remains the undisputed leader for browsers, with nearly 90 per cent market share, Firefox continues to gain in popularity.

Firefox is approaching the ten million download mark while gaining five per centage points in May to 7.4 per cent, according to research firm OneStat.com. Microsoft has disputed these numbers, claiming that they do not represent corporate users.

Even though attackers target IE because of its near ubiquity, malicious code writers are widening their reach. Yesterday, a security company discovered an exploit in a feature common to most browsers, including IE, Firefox, Opera and Safari, that could be used to launch an attack.

Penn State's Anderson said the university has just completed a two-month information campaign for PC security, urging students to download firewalls and antivirus software, and to regularly install operating-system updates. She added that changing browsers is one of many ways to defend against attackers.

"What we're saying is, we're taking a hard stance on securing our computers," Anderson said.

Jim Hu writes for CNET News.com. CNET News.com 's Robert Lemos contributed to this report.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Web Tester - Penetration Tester - Staffordshire West Midlands

Candidates must have thorough experience of web application penetration testing which include both knowledge and experience in Man in the Middle ...

EPG/UI Business Analyst

We need to find an EPG / UI Business Analyst / Architect / Designer with a proven track record in delivering the design and navigation of TV based ...

Application Access Engineer

You MUST be SC cleared Skills mandatory: Enterprise scale Infrastructure Topologies and Architectures; Enterprise scale application deployment ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: