Re: The price of success... Firefox users take note.



Pete Dashwood wrote:

I have always claimed that one reason why IE has been targeted has been
because it is successful, and not because of any particular innate
vulnerability.

That is indeed one reason. Alas, there are others, including a great
many particular innate vulnerabilities.

The simple fact is that IE 6 (and to a lesser extent some of the other
IE releases) has a great many features which are insecure as designed.
Other mainstream browsers have smaller attack surfaces simply by
virtue of omitting those features.

My contention is that EVERYTHING is vulnerable...The more
successful somethng becomes, the more chance of it being targeted.

The former is a truism - you can always extend a threat model past the
security parameters of a system. (Not many systems are designed to
resist a massive asteroid strike.) The latter is difficult to prove,
however plausible; but doesn't it imply that the makers of the
most-successful browser have an obligation to devote extra attention
to its security?

--
Michael Wojcik
Micro Focus
Rhetoric & Writing, Michigan State University
.



Relevant Pages