Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Virus - Spyware Protection / Detection » Built-in browser expiry proposed to fight botnet menace
Closed Thread
Old 07-03-2008, 08:07 AM   #1 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,077

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Built-in browser expiry proposed to fight botnet menace

Nearly half (45.2 per cent) of all internet surfers neglect to regularly update their browser software. Slackness in applying updates in a timely fashion leaves an estimated 637 million surfers vulnerable to drive-by download attacks, according to a new survey.
Figures in the survey come from a study of user-agent data collected by Google’s web search and application servers and analyzed by security researchers from IBM's ISS security division, Google and ETH Zurich University.

The study found that Firefox users were the most diligent in applying security updates, with 83.3 per cent using the latest version. Less than half (47.6 per cent) of IE users used a fully patched version. Part of the problem with IE users could be down to compatibility with older enterprise applications, notes IBM security researcher Gunter Ollmann.
"I think it may be a little unfair for many IE users to be grouped in the “less diligent” bucket because they’re stuck to using IE5 or IE6 for compatibility issues with their corporate applications but, quite frankly, in this climate of commercial mass-defacements, 'unfair' isn’t going to keep them safe," Ollmann writes.
Unsurprisingly the study concluded that update features within different browsers played a key role in determining how quickly users update their software. Firefox users "typically updated" within three days of the availability of a new security update. Opera users averaged around 11 days before patching their browser while some IE users are still stuck on IE6 a year and a half after the release of IE7.
The security researchers reckon browser makers could improve internet security by taking a leaf from the book of food manufactures and applying a "best before" date to browser and plug-in software. The theory is that a built-in expiry date would ensure that more users update in a timely fashion. Ollmann concedes that opponents may argue that the concept would simply confuse less web-savvy users without having the desired effect.
A white paper on the study, Understanding the Web browser threat, can be found here.

Built-in browser expiry proposed to fight botnet menace | The Register
__________________
Osiris is online now  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On