Welcome | Sign In
ECommerceTimes.com
Security

Experts Warn of Security Flaws in Alternative Browsers

Print Version
E-Mail Article
Reprints
Experts Warn of Security Flaws in Alternative Browsers

Secunia issued a warning that the so-called tabbed browsing function in many alternative Web browsers from Mozilla, Opera, Netscape, Avant, Camino and others leave users vulnerable to spoofed Web sites that seek to steal personal information. The firm said the flaws are moderately critical.


How Much is 'Free' Costing You?
Learn how DaveRamsey.com saw a 567% uplift in ROI with Omniture. This complimentary guide and webinar cover the most important factors in selecting an analytics solution. Download Now.

Security experts are warning of a newly discovered security flaw in several alternative Web browsers, some of which recently have begun to chip away at the dominance of Microsoft's (Nasdaq: MSFT) Internet Explorer as users seek more secure alternatives.

IT security services firm Secunia issued a warning that the so-called tabbed browsing function in a host of alternative Web browsers made and distributed by Mozilla, Opera, Netscape, Avant, Camino and others leave users vulnerable to spoofed Web sites that attempt to steal personal information. Secunia said the flaws are moderately critical.

Browser Vulnerabilities

Tabbed browsers allow users to have multiple pages open within a single browser window and to tab back and forth among them without having to close any. Secunia said the most serious flaw enables spoofed Web sites opened in those tabs to display dialogue boxes in other tabs, potentially making it appear that they originate from trusted sites, such as banks, when, in fact, they are spoofing attempts to gain personal data.

A second vulnerability could enable data that is being entered to a secure, trusted page to be intercepted by a page on another tab.

Secunia's chief technology officer, Thomas Kristensen, said the flaw is in the basic design of almost all tab browsers.

Alternative Web Style

"Because all the browser tabs are in a single application window, it's harder to tell which Web site is responsible for any given action," he said. "It's one of the drawbacks of having so much going on in the same window."

Ionically, the warnings come as security concerns about Internet Explorer (IE) have led many Web users to reconsider which browser they deploy to access the Internet, leading to the first serious challenge to Microsoft's browser since it overtook Netscape. The U.S. Computer Emergency Readiness Team (CERT) warned users to forgo the IE browser until a batch of vulnerabilities could be addressed.

Web analytics firm WebSideStory said IE use has dropped from more than 95 percent earlier this year to around 93 percent. While that still gives IE a dominant share of the market, it does show considerable adoption of alternatives.

Hoping to capitalize on that trend, supporters of the Mozilla foundation plan to launch a media campaign that includes ads in the New York Times designed to raise awareness of the Firefox 1.0 release.

Shut It Down?

However, alternative browser supporters could take solace in the fact that on the same day the tabbing vulnerability was announced, security experts were warnings that a persistent flaw in IE now appears to leave even machines that are loaded with the Windows XP Service Pack 2 security upgrade vulnerable.

Denmark-based Secunia said the IE vulnerability is "highly critical" and could leave machines open to remote attack.

Sophos antivirus consultant Graham Cluley said IE remains the favorite target of malicious code writers because it is so widely used and because new vulnerabilities are constantly being identified.

While alternative browsers offer a way to steer clear of IE-related flaws, they don't solve the Internet security risk, as the new vulnerabilities show, he added. Alternatives might, in fact, offer some users a false sense of security.

"Given that it looks likely that there will be more browser flaws and more exploits that take advantage of them -- in some cases before patches are even available -- some companies might want to consider whether it's prudent to give all the users on their network full Web access," Cluley said. "They have to weigh whether the risks are worth it in the long run."


Print Version E-Mail Article Reprints More by Keith Regan


More by Keith Regan

Yahoo Slaps Fresh Coat of Gloss on Microsoft Deal Defense
June 30, 2008
With its shareholders meeting set to take place in less than five weeks, Yahoo has put together a 32-page presentation, emphasizing why the investors should vote to keep the current board in place. The company also reiterated why it chose to partner with Google instead of letting Microsoft buy part of it.
French Court Stings eBay With $63M Judgment Over Knockoff Sales
June 30, 2008
eBay is planning to appeal a ruling by a French court that ordered it to pay $63 million to the luxury goods maker Louis Vuitton Moet Hennessey. The court also barred the online auctioneer from selling four brands of perfume on its Web sites accessible in France.
New Auto Loan Leads Marketplace Shifts Into Drive
June 30, 2008
Reply.com's move into the auto finance market is a logical one the company, as automotive advertising spending is moving online in increasingly greater amounts. The company is partnering with the Detroit Trading Company to create a massive repository of auto finance leads online.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network