Please show me, I'll see. There are several serious web pages demonstrating exploits, f.e.:
Please show me, I'll see. There are several serious web pages demonstrating exploits, f.e.:
Not only: Internet Explorer is the explorer of the internet, is there anything beyond (read the so called "internet options" :-/ of the IE a.s.o.)?
Wolfgang
Is there an actual list of them? Thor Larholms's is closed, umbrella's?
asks Wolfgang
Wolfgang
Again:
Yes, I have to update my lists again.
A good starting point today is
A browser works with content. You can browse networks, applications, resources, ... and a browser designed for processing untrustworthy HTML content is usually called a webbrowser.
This is an HTML based application.
Well, IE hardly understands anything but a very small subset of HTML and has certain mechanisms that are inherently insecure on untrusted environments (like the internet).
So far, we have:
- 60+ unpatched vulnerabilities
- non-working cross-domain security
- impossibly to disable ActiveX behaviour
- very lousy parsing and rendering of HTML content
This makes it totally unsuitable and dangerous to (mis)use as a webbrowser.
Nah, it's a documented design.
This could happen to every website, even when driven by competent people
- as you simply don't have much, if any control about the advertisement resell business. As we've seen, a seemingly trustworthy company was founded, bought some ad space, but it's exploit on there, infected some
10000 machines and then was shut down.This is an inherent fact and has nothing to do with internet safety.
These are all data. Beside that, it seems like some simply HTML tags and/or CSS description is already sufficient to make IE misbehave.
And ActiveX cannot be fully disabled.
Yes. I read the German version of
The point is that there were 50+ vulnerabilities between Firefox 1.0 and
1.5.0.5 that existed but were fixed. How many vulnerabilites still exist in 1.5.0.5 that will get fixed in 2.0? How many will exist in 2.0? You just don't know until they're exploited and/or fixed.
And for IE, you have 50+ vulnerabilities known with Microsoft refusing to submit patches, and there are some inherent design decisions (you may call them flaws) that are unfixable without a complete rewrite.
I guess you understand the difference between random and systematic errors.
I'm not disputing the fact that IE has vulnerabilities (because we all know it does and MS takes its time fixing them), I'm disputing that Firefox is so "internet-safe" as people claim it to be. No browser can be 100% "internet-safe".
Yeah, I know, but again: Firefox isn't as safe as you claim it to be. They have also bugs/flaw/vulnerabilities.
btw: I'm using Firefox most of the time and IE when Firefox can't handle. I admit that Firefox is more safe than IE, but I don't think it's internet-proof.
I don't care what you think of McAfee: I don't use their products.
Peter
More than 3 years?
Maybe you're still unaware of what "internet-safe" means: not having systematic errors, being theoretically secure and only falling at random errors. Get your updates in time and you've achieved the maximum possible.
The difference is what are systematic errors in IE: side-effects in ActiveX implementation, non-working cross-domain security model, non-working policies on graphical contexts and MIME type confusion. Things you can't simply patch away, things that require a rewrite.
I've never claimed that it doesn't.
Talking about safety of IE is like talking about safety of granting remote shells...
Actually it's pretty internet-proof when carefully analyzing the conditions and impacts of previous vulnerabilities, and taking into account how a pro-active security configuration could limit impact.
But you should know who you cite. The claims of McAfee aren't worth any consideration.
Here is no difference between the policies of the developer (or security) teams of mozilla.org and microsoft.com f.e.
Yes, I can read bugzilla.mozilla.org/show_bug.cgi?... or
How many of them were exploitable in the wild and how long did it took the developers to fix them after they were known for all?
How many of them will be known before they'll get fixed?
I wrote above: It's due to the non disclosure policy and it's not good.
But have a look about the design flaw of the IE (Thor Larholm (who also actually found some of the new vulnerabilities of firefox) posted these problems several years before) Sebastian wrote about in his answer and how long did it took the developers to fix them? There are poles apart IMO.
Wolfgang
Sebastian Gottschalk:
source browser too, McAfee said.
Is it true or not, regardless of who said it?
Geo
The ShellExecute MIME type confusion problem was turned into a group policy with explicit blacklisting (rather than the required whitelisting) solely on Windows Server 2003. The JavaScript domain security has a hidden policy, also just blacklisting instead of required whitelisting.
Of course, the real issues behind were not fixed, apart that Microsoft promissed a nearby complete rewrite at least two times (IE6SP2 and IE7).
source browser too, McAfee said.
It is true, but it is a wrong conclusion. A flaw doesn't have a nearby great effect if it has already been fixed and delivered with an automatic update functionality. And it has no relation to yet unfixed flaws and unfixable design flaws.
BTW, you're a dirty address faker.
As I said, nothing about Firefox or Opera. At least nothing concrete.
Yours, VB.
And what does to do with the subject? Or should posters start making comments on your English?
Geo
Have something to add? Share your thoughts — no account required.
Ask the community — no account required