Most Insecure Browser?

Status
Not open for further replies.
Joined
Feb 9, 2008
Messages
6,366
Location
Midwest
Cenzic (web app security company) found the following:

"Of Web browser vulnerabilities, Firefox had the largest percentage, at 44 percent. Safari vulnerabilities came in at 35 percent, significantly higher than even Internet Explorer."

"Popular vendors including Sun, IBM, and Apache continue to be among the top 10 most vulnerable Web applications named."

Cenzic Web App Security
 
Wasn't there something released in the last 6 months that said Firefox was the best ?
I'll try and find it.
 
Internet Explorer's ActiveX is the most insecure web technology ever developed.

Any "developer" willing to pay Microsoft's fees can get a digital signature and run any code they want on your machine. Spyware City.
 
I've seen multiple articles stating that Firefox is the most vulnerable browser right now. I have been a long time Firefox user, but I have been having more problems (hangs, not closing down properly, etc) withe the 3.5.x versions. It seems to work pretty well on XP yet, but it hangs more with Windows 7. Hopefully the new version that is supposed to come out soon will fix some of these issues.
 
The browser is only as vulnerable as the operating system under it (Windows is still more wide open than Linux or Mac OSX). But its also important to remember that *no* browser can prevent the operator from dropping his own pants, so to speak, by clicking on questionable web links or links embedded in E-mails from unknown senders.

As firewalls and anti-virus software have improved, even on Windows, it has forced the spammers and virus writers to depend more and more on YOU to open the door to them using your computer! Most spyware, adware, and viruses these days are self-inflicted, unfortunately.
 
One thing to remember with regards to Windows is that browsers work differently among the current flavors of XP, Vista and Win7. Of those, XP seems to be the most vulnerable based off of all my friends who got malicious software using IE, FF, and Chrome.
 
I agree, if most folks would just run as a non-privileged user instead of with admin rights, there would be fewer issues, even in XP.

Don't give your user account admin rights, even if it does make life easier.

That way, you can't install that malware via your browser, etc.

My family complains they don't have admin rights, but since I've done that on the Windows boxes, my fixing of problems has gone to ZERO in the past 3-4 years.
 
Firefox is nothing special once a user 'enables' everything and installs all the 'needed' plug-ins for their questionable website habits.

Firefox, with Noscript, is the way to surf.
http://noscript.net/

But, noscript can be annoying to use. If you don't like Vista's UAC, then you probably won't like noscript.

In this society, you can't force everyone to be responsible for their actions when surfing the web or downloading garbage. They are just too incompetent.
 
Originally Posted By: javacontour
I agree, if most folks would just run as a non-privileged user instead of with admin rights, there would be fewer issues, even in XP.

Don't give your user account admin rights, even if it does make life easier.

That way, you can't install that malware via your browser, etc.

My family complains they don't have admin rights, but since I've done that on the Windows boxes, my fixing of problems has gone to ZERO in the past 3-4 years.

I agree, but unfortunately many programs, especially games, don't even run without admin rights.
 
Originally Posted By: tmorris1
Originally Posted By: javacontour
I agree, if most folks would just run as a non-privileged user instead of with admin rights, there would be fewer issues, even in XP.

Don't give your user account admin rights, even if it does make life easier.

That way, you can't install that malware via your browser, etc.

My family complains they don't have admin rights, but since I've done that on the Windows boxes, my fixing of problems has gone to ZERO in the past 3-4 years.

I agree, but unfortunately many programs, especially games, don't even run without admin rights.


Is that really true, or will they run if you change the permissions in the directories to allow normal users write access?

I.E. install the game as Admin, then open up the perms in that directory and all children for the user community.

Then non-root, sorry, non-admin users should be able to run the game.


It's more sloppy permissions management on the part of the game vendor than anything else. They should install in such a fashion that allows non-admin users to play the game.
 
Originally Posted By: tmorris1

I agree, but unfortunately many programs, especially games, don't even run without admin rights.


My wife, a high school teacher, uses some school board supplied report card and class management programs that actually *keep the user configuration data* in C:\Program Files\$program_name! As I understand it, many games do this, too... It's such a bad decision, with so many pitfalls and no real benefits that I can see; and I wonder why on earth software makers continue to do this.

I try to make a practice of sending companies that make software that keeps config or user data in locations other than user space (or otherwise requires admin rights to run it) a long lecture via email; and their responses, not counting the dismissive form responses I get from 75% of them, all harken back to a backward-compatibility excuse: They've been making this software and licensing it to the board since 199x, and to modify user permissions, config file locations and such-and-such would bugger up the whole thing. (Translation: We're too lazy to re-write the program the way it shoulda been done in the first place. We'd rather burden a school's IT person.)

When setting up a WinXP system, I used to rename the Administrator account to "NoNetwork" or something to that effect; hoping that intruders would not opt to try to get into that (seemingly useless) account, and bots would not bother with it. I would then create an "Administrator" account with *zero* priviledges and an absurdly long password; hoping that the decline in morale after hacking into a fake account would drive script kiddies to greener pastures. The users would run the system under their user account with normal user priviledges. (Games and report card programs not withstanding!) My hope was that with proper backups, even if a hacker wiped the whole account, the OS would remain untouched, or at least reparable, and a quick restore of the user's data would put us right back in the ring.
 
Originally Posted By: 440Magnum
The browser is only as vulnerable as the operating system under it (Windows is still more wide open than Linux or Mac OSX). But its also important to remember that *no* browser can prevent the operator from dropping his own pants, so to speak, by clicking on questionable web links or links embedded in E-mails from unknown senders.

As firewalls and anti-virus software have improved, even on Windows, it has forced the spammers and virus writers to depend more and more on YOU to open the door to them using your computer! Most spyware, adware, and viruses these days are self-inflicted, unfortunately.


There is a lot of truth here. The user is the biggest weak link some of the time.
 
My experience with non-admin role is that it makes your life a living [censored] while you are trying to use your computer. The only easy thing that happens in guest mode is catching a virus or some other malware.
 
This news just appeared on Slashdot, and I found this comment to be enlightening (emphasis mine):

Quote:

So in other words, this isn't a count of how many vulnerabilities there are, it's a count of how many vulnerabilities are found and fixed.

Something tells me their methodology is a bit flawed. Of course, that's by design, given Cenzic's financial ties to Microsoft.


Man, oh, man... Between the FUD spread by open source zealots and corporate Kool-Aid drinkers, it's like trying to get the truth about something, and your only sources of information are Fox News and MSNBC.
29.gif
 
Originally Posted By: CivicFan
My experience with non-admin role is that it makes your life a living [censored] while you are trying to use your computer. The only easy thing that happens in guest mode is catching a virus or some other malware.


We're talking about normal user accounts, not guest mode.
 
First of all it depends on the computer user's behavior. If somebody visits all kinds of dangerous websites and downloads all kinds of unknown applications and other trash on the internet it is only a matter of time before the computer is infected with scumware. I know a guy at work who always has his personal computers infected with trash and unuseable. He likes to visit porn sites.

When Safari for Windows came out it was very insecure. It may have improved since that time but I would certainly not use it.

I have mixed feelings about Firefox. A long time ago an anti-trojan program called A-Squared found a possible backdoor in a version of Firefox I was using at the time.

In the new version of Firefox I would use NoScript AND set the cache to ZERO! Don't think you are going to be safe just using NoScript. And of course it still depends on what websites a person goes to and how much trash a person is willing to download to their computer. Once again, don't think that just because you are using Firefox with NoScript that you are safe! I think I will leave it at that other than to say that the Firefox people need to do really good scans of proposed add-ons for Firefox.

Watch out for some of these Firefox add-ons! Some reduce the security of Firefox. And there was scumware discovered in a Vietnamese language add-on. Don't think that just because Firefox is open source and not Microsoft that there cannot be scumware placed in add-ons. It has already happened. Therefore it can and probably will happen again. In fact I predicted a long time ago that scumware could potentially be placed in open source software. People here attacked me for saying that. Well, it happened.

There was a study done fairly recently where it was discovered that Internet Explorer 8 is actually the most secure web browser. People immediately attacked the study saying that it was funded by Microsoft. But nobody has disproved the results of the study. Without a doubt Internet Explorer 8 is light years different from the trashy Internet Explorer 6. I think the least secure web browser in the study was Google Chrome-if I remember correctly.

I would like to use Firefox at least when exploring areas of the internet unknown to me but whenever I do start using Firefox it seems like issues keep coming up. I am therefore tempted to just use IE8 with InPrivate Browsing and InPrivate Filtering selected. Inspite of all the hatred directed at Microsoft I find I can trust Microsoft better.
 
Status
Not open for further replies.
Back
Top Bottom