Home > Security Tips > Threat Monitor > Ditch IE?
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

THREAT MONITOR

Ditch IE?


Ed Skoudis, CISSP
08.05.2004
Rating: -4.03- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


It's been a rough summer for Internet Explorer. A rash of vulnerabilities in the most widely used browser has allowed attackers to spread particularly vicious malware at an unprecedented rate. From exploiting a gaping hole in order to load a keystroke logger from a Russian site to manipulating help features to run arbitrary code, the sheer number of these flaws is driving some people to consider dumping IE in favor of another browser. Organizations ranging from U.S. CERT to BusinessWeek magazine have advised people to consider using another browser to ride out this vulnerability storm. People often tell me that I should jump on a soapbox and advise folks to move off of IE to help improve their security. But is ditching IE a reasonable way to go?

Let's first consider the chances that the IE onslaught will relent in the near future. IE certainly has had numerous vulnerabilities, and they show no sign whatsoever of letting up. I'm not convinced this is because IE is inherently less secure than other browsers. Instead, it's just a much bigger target. Malware developers focus on IE, given its vast market share. With this motivation for the bad guys, I don't think we'll see a near-term decrease in the number of IE-based exploits. Microsoft has said that Windows XP Service Pack 2 will fix a lot of these problems. But, if we use history as our guide, we can easily foresee a bunch of new security holes ripe for the picking by clever attackers.

So, does that mean you should drop IE altogether? Before jumping to conclusions, you need to calculate carefully the cost of such a change. For home users surfing the Net for fun and e-commerce, switching from IE has virtually no cost. Both the free Firefox and the commercial Opera browsers are wonderful, and support all kinds of nifty functionality. So, if you have a home computer, go ahead and give an alternative browser a shot. You just might like what you see.


For more information on this topic, visit these SearchSecurity.com resources:
  • Read this recent news article on Microsoft's fix for IE.
  • Learn how to battle worms with a network-based IPS.
  • Keep your users up to date with the latest information about malicious code with this tip.

    Unfortunately, things are not quite so simple in the corporate space, where we face hundreds, thousands or tens of thousands of laptops and desktops, often using homegrown Web-based applications. IE is extremely entrenched in such companies and replacing it with another browser entails major costs, including:

    • Direct deployment costs: Installing software on thousands of systems could be a major time investment. Check to see whether your current software deployment tools can help deploy a browser other than IE.
    • Management costs: Many organizations are managing their browsers using Microsoft IE Admin Kit (IEAK) or Group Policy. Make sure you check on the flexibility of enterprise management capabilities of competing browsers. Generally, they are far less integrated into Windows and can be harder to manage.
    • Application porting costs: This is the big one. If you have any homegrown Web applications or Web services, check to see if they'll run on something other than IE. Many will not. I've seen several financial institutions and consulting firms that use specialized financial and time-reporting tools that could only work with IE. Tens of thousands of dollars would be required to make them compatible with another browser. Locked in? For many organizations, the answer is, "You betchya!"
    • User awareness costs: Some users can jump to a new browser and instantly adapt. Other users are so subservient to the swirling blue icon that they can't easily move to another browser without at least a small briefing on its capabilities. Make sure you price in the costs of preparing and delivering such a briefing.
    • Help desk and admin training: Beyond end users, your help desk and technical staff will have to support a new environment. Make sure you consider the costs of their training, which will likely be higher than end user training.
    These are the cost sides of this equation. The benefits? You'll be less of a bull's eye for much malware, of course. That could be a substantial benefit to organizations requiring high security. However, in many organizations, the losses from IE-inflicted malware are, in all honesty, quite low so far. Also, dumping IE doesn't make you impervious to attack, as we saw with the recent significant hole in the Mozilla browser running on Windows.

    Believe me, as a security guy, I wish I could say that security trumps all other issues. However, we've got to very carefully weigh the costs and benefits of ditching IE. If your cost-benefit analysis shows that a switch from IE is worth it, by all means make the switch. If not, batten down your hatches, because the storm doesn't appear to be letting up yet.

    About the author
    Ed Skoudis, CISSP, is cofounder of Intelguardians Network Intelligence, a security consulting firm, and author of Malware: Fighting Malicious Code (Prentice Hall, 2003).

    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Threat Monitor,   Application and Platform Security,   Application Attacks (Buffer Overflows, Cross-Site Scripting),   Web Security Tools and Best Practices,   Web Browser Security,   Malware, Viruses, Trojans and Spyware,   Information Security Threats,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Threat Monitor
    Server Message Block Version 2 security in question: Disable or patch?
    Preparing for future security threats, evolving malware
    Best practices for (small) botnets
    Cut down on calls to help desk with cybersecurity awareness training
    How to detect software tampering
    How to prevent phishing attacks with social engineering tests
    An enterprise strategy for Web application security threats
    How SSL-encrypted Web connections are intercepted
    How a corporate Twitter policy can combat social network threats
    Cyberwarfare and the enterprise: Is the threat real?

    Application Attacks (Buffer Overflows, Cross-Site Scripting)
    Latest zero-day attacks only target IE 6, Microsoft says
    Social networking security: Twitter, Facebook hacker attacks climbing
    Web application attacks security guide: Preventing attacks and flaws
    How to stop buffer-overflow attacks and find flaws, vulnerabilities
    Preventing and stopping SQL injection hack attacks
    Distributed denial-of-service protection: How to stop DDoS attacks
    Prevent cross-site scripting hacks with tools, testing
    Firefox, Opera, Safari browsers top list of high risk software
    Information security book excerpts and reviews
    Quiz: How to build secure applications
    Application Attacks (Buffer Overflows, Cross-Site Scripting) Research

    Web Browser Security
    Microsoft warns that IE zero-day vulnerability causes data leakage
    Browser exploit kit probe highlights need for patching, vigilance
    Google to pay for Chrome browser vulnerabilities
    Attackers continue barrage of SEO attacks
    Microsoft emergency IE update to block latest corporate attacks
    Facebook, McAfee partner to fix social network security issues
    Firefox, Opera, Safari browsers top list of high risk software
    Mozilla fixes Firefox critical memory corruption errors
    FBI estimates rogue antivirus losses exceeding $150 million
    Adobe updates Flash Player, fixes seven serious vulnerabilities
    Web Browser Security Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    buffer overflow  (SearchSecurity.com)
    cache poisoning  (SearchSecurity.com)
    cyberterrorism  (SearchSecurity.com)
    dictionary attack  (SearchSecurity.com)
    directory harvest attack  (SearchSecurity.com)
    distributed denial-of-service attack  (SearchSecurity.com)
    JavaScript hijacking  (SearchSecurity.com)
    ping of death  (SearchSecurity.com)
    stack smashing  (SearchSecurity.com)
    SYN flooding  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Research Solutions for Network Security, Access Control and Security Threats
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts