Macworld Forums: First security flaw signaled in IE7 - Macworld Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

First security flaw signaled in IE7

#1 User is offline   MW Forums Icon

  • Power User
  • PipPipPipPip
  • Group: Members
  • Posts: 12,220
  • Joined: 02-August 04

Posted 19 October 2006 - 05:40 AM

Less than 24 hours after the launch of Internet Explorer 7, security researchers have found a flaw in the new browser. more
0

#2 User is offline   sparky67 Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 148
  • Joined: 10-December 05

Posted 19 October 2006 - 09:51 AM

I find this "news" to be non-news. "M$ product full of security holes"... you're kidding, really?
What does surprise me is M$'s inability to do things differently after opening the door in their faces hundreds of times.
Here's an idea... how about pre-releasing the software to these security companies. Then pay them an incentive for finding the problems. If they don't want to participate by M$ rules, then find other security companies willing to make some cash.
At least it might save them a little embarrassment.
How many of these stories are we going to read the day after Vista is released? No, wait, we're reading them now.
0

#3 User is offline   griffman Icon

  • Advanced Member
  • Icon
  • Group: Moderators
  • Posts: 8,605
  • Joined: 09-January 01

Posted 19 October 2006 - 10:08 AM

IE 7 was available as a free public beta for many months; I've had it running on XP under Parallels for quite a while now.
-rob.

#4 User is offline   sparky67 Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 148
  • Joined: 10-December 05

Posted 19 October 2006 - 10:20 AM

Quote:

IE 7 was available as a free public beta for many months; I've had it running on XP under Parallels for quite a while now.
-rob.


I don't dispute that.
I'm just thinking that M$ could enter into contractual agreements with various worldwide security firms and then pay them to find these problems before the official release date.
It's amazing that after all these years M$ is still too large and stupid to at least hire others to do what it constantly fails to do... find the holes before the release.
Corporate image must not be a concern for them, I guess.
0

#5 User is offline   vfx2k4 Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 360
  • Joined: 29-September 04

Posted 19 October 2006 - 10:26 AM

Or maybe an even uglier truth: the MS realizes there is too much of an infrastructure existing in these security firms or maybe even gets a significant cut of the anti-virus software needed to combat these flaws. Plus there's always good old FUD. Why release a secure product when not releasing one has kept MS at the top for years?
0

#6 User is offline   macFanDave Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 777
  • Joined: 04-March 04

Posted 19 October 2006 - 10:52 AM

Do this affect the Mac OS X version of IE7?
Wait, there is no Mac version of IE7 !!!!
Hallelujah!
Hallelujah!
Hallelujah! Hallelujah! Hallelujah!
Schadenfreude party at my house!
0

#7 User is offline   HardToExploit Icon

  • Newbie
  • Pip
  • Group: Members
  • Posts: 2
  • Joined: 19-October 06

Posted 19 October 2006 - 11:00 AM

It is hard to exploit the flaw because it requires the attacker to lure someone to a malicious site, and for the attacker to know what other secure site the visitor might simultaneously have open
0

#8 User is offline   VidPro Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 312
  • Joined: 20-December 02

Posted 19 October 2006 - 11:22 AM

Quote:

It is hard to exploit the flaw because it requires the attacker to lure someone to a malicious site, and for the attacker to know what other secure site the visitor might simultaneously have open


I would agree with this if the malicious site had one and only one chance at guessing the other site. Remember, though, that we're dealing with computers here that can attempt various websites' information in quick succession that may fail until finding a valid one before you have a chance to back out.
I don't think this is a difficult exploit at all.
Editor's note: Please use the "quote" tag, not the "code" tag to quote comments. The code tag will not line break, leading to very wide posts.
0

#9 User is offline   sefton Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 73
  • Joined: 24-March 05

Posted 19 October 2006 - 11:29 AM

Microsofts efforts to stop phishing in IE7 may have a few flaws as it warned me that I was on a potential phishing site.
That site was one of Microsofts own as I checked on our Schools License Agreement.
0

#10 User is offline   MacTechAspen Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 393
  • Joined: 15-October 04

Posted 19 October 2006 - 11:31 AM

Quote:

It is hard to exploit the flaw because it requires the attacker to lure someone to a malicious site, and for the attacker to know what other secure site the visitor might simultaneously have open

Yes. And while you may seem to be defending Windows by tacitly implying that the threat is overblown, know this. The attack works great as a Phishing scam. You simply open the bank log-in in a separate window. So... you send an email that says your bank account is in danger at a known national institution, such as Bank of America. The reader panics, clicks on the link and a quick blank, and small innocuous window appears and then the bank window appears over top of it. Since pop ups are not unheard of on the Windows side of things, it is easily ignored. The poor dupe now logs into their account, and their password pair is stolen.
Not only does this sounds plausible, I get what I can only assume to be these very emails, on a regular basis.
IE7 was supposed to reduce vulnerability to Phishing by at least patching the hole they have known about for months. It failed to do so.
If Microsoft want's Apple not to make jokes at Microsoft's expense, regarding viruses and security, they should stop making stupid mistakes and facetious claims.
0

#11 User is offline   ice_cold_irony Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 120
  • Joined: 02-October 06

Posted 19 October 2006 - 11:57 AM

Isn't the point of this article not that the security flaw is a minor one or that it is hard to exploit, but that IE7 has been released to the wider public for less than 24 hours and someone already has found one security flaw? To me this just signals that security and virus issues will be as, if not more, prevalent in IE7. Also, does this raise anyones hopes for the security of Vista? I mean if this is Microsofts new fancy tabbed browser released in anticipation of Vista, what will stupid problems like this mean for Vista?
0

#12 User is online   DJRizzo Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 63
  • Joined: 18-November 05

Posted 19 October 2006 - 12:44 PM

Quote:

Schadenfreude party at my house!


I'm nearing my first anniversary as a Mac user after using PCs for over a decade. Every time one of these articles come out Schadenfreude is exactly what I feel. Today that's especially true after reading on the same day that Apple is increasing market share.
0

#13 User is offline   Rugby Icon

  • Veteran
  • PipPipPip
  • Group: Members
  • Posts: 1,325
  • Joined: 28-August 04

Posted 19 October 2006 - 01:20 PM

OK hands up all those surprised... hey guys you could at least pretend to be surprised /forums/ubbthreads/images/graemlins/tongue.gif
0

#14 User is offline   nelson92 Icon

  • Member
  • PipPip
  • Group: Members
  • Posts: 354
  • Joined: 30-September 03

Posted 19 October 2006 - 02:21 PM

Quote:

OK hands up all those surprised... hey guys you could at least pretend to be surprised


I'm surprised it took so long as a day. /forums/ubbthreads/images/graemlins/grin.gif
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

2 User(s) are reading this topic
0 members, 2 guests, 0 anonymous users