German government warns IE users

The German government consider this is so important that, in an unprecedented move has warned web users to find an alternative browser to Internet Explorer to protect security. This warning applies to versions 6, 7 and 8 of Internet Explorer  [ there are alternatives... see below ].

The warning from the Federal Office for Information Security comes  after Microsoft admitted IE was the weak link in recent attacks on  Google's systems.

Microsoft rejected the warning, saying that the risk to users was low and that the browsers' increased security setting would prevent any serious risk.

However, German authorities say that even this would not make IE fully  safe.

Thomas Baumgaertner, a spokesman for Microsoft in Germany, said that  while they were aware of the warning, they did not agree with it, saying that the attacks on Google were by "highly motivated people with a very specific agenda".

"These were not attacks against general users or consumers," said Mr  Baumgaertner.

"There is no threat to the general user, consequently we do not   support this warning," he added.

Microsoft says the security hole can be shut by setting the browser's security zone to "high", although this limits functionality and blocks many websites.

However, Graham Cluley of anti-virus firm Sophos, told BBC News  that  not only did the warning apply to 6, 7 and 8 of the browser, but the instructions on how to exploit the flaw had been posted on the internet.

"This is a vulnerability that was announced in the last couple of  days. Microsoft have no patch yet and the implication is that this is  the same one that exploited on the attacks on Google earlier this  week," he said.

Computer expert Alan Stevens: "It's like having a window left open in your house and people have published a map to where the window is, and  have even put up a ladder to let people get in."

"The way to exploit this flaw has now appeared on the internet, so it is quite possible that everyone is now going to have a go,"  he added,  "The flaw cannot be eliminated."

Microsoft traditionally release a security update once a month - the next scheduled patch is the 9th of February. However, a spokesman for  Microsoft told BBC News that developers for the firm were trying to  fix the problem.

"We are working on an update on this issue and this may well involve  an out of cycle security update," he said.

However, this is no easy task. Not only have the firm got to fix the loophole, but they have to ensure it does not create another one and -  equally importantly - works on all computers. This is a challenge  compounded by the fact they have to fix three different versions of  its browser.

Microsoft said that while all versions of Internet Explorer were affected, the risk was lower with more recent releases of its browser.

The other problem facing developers is that the possible risk might not be prevented by anti-virus software, even when recently updated.

"We've been working to analyse the malware that the Chinese are using.  But new versions can always be created," said Mr Cluley.

"We've been working with Microsoft to see if the damage can be  mitigated and we are hoping that they will release an emergency patch.

"One thing that should be stressed is that every browser has its  security issues, so switching may remove this current risk but could expose you to another."

Daniel Emery, Technology Reporter, BBC News, 17 Jan 2010 

( But at least you could try one of these alternatives:

http://www.google.com/chrome

http://www.opera.com/download/

http://www.mozilla.com/en-US/firefox/firefox.html )


Add your comment

Click here to add your blog comment to this item.

Comments will be subject to approval and should not be defamatory, obscene, racist, in breach of copyright, or contrary to law. The NUJ New Media Industrial Council is not reponsible for any views expressed here.


Calendar

double click highlighted dates

» click here to clear date list

Miscellany

  • Blog News
  • Contact
  • Union
  •  

    Links

  • Campaign for Press and Broadcasting Freedom
  • Freelance Directory
  • Freelance Fees Guide
  • New Media mailing list
  • NUJ main website
  • NUJ Training site
  • The New Media blog