« 3.3 ounces of security | Main | The independent channel »

The more popular, the more vulnerable

If you like it here, please consider subscribing to the RSS feed or spreading the news among your friends who also care about security.

Think Internet Explorer. Still significantly more popular then other web browsers. Lets put aside its ifamous incompatibility with w3c standards and concentrate on its security. Or insecurity rather. A friend of mine got almost scammed lately by an online banking password harvesting trojan. Happened under IE and wouldn't happen under say Firefox or Opera... at least by now.

Unfortunately it's not very likely it has something to do with a more secure design or a better coding of the alternative browsers. The design of each browser gives a choice of virtually the same amount of potentially vulnerable places. Also the code is similarly big and complicated and thus bug prone. What is the difference then?

It seams like nothing more and nothing less, but the popularity.

Even if you had a perfectly exploitable flaw in say Firefox, it's times more profitable to find and exploit one in a lot more popular IE. So, just wait until the alternative web browsers gain more userbase and it's pretty likely we'll see the amount of attacks on them comparable to those aimed at IE.

The bottomline — the more popular something is, the more impact on security it can potentially have.

TrackBack

TrackBack URL for this entry:
http://sobiegraj.com/blog/mt-tb.cgi/25

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

© 2006-2007 Michał Sobiegraj. All rights reserved. The views expressed here are my own, and not necessarily endorsed by any former or current employer.

About

This page contains a single entry from the blog posted on November 11, 2006 6:29 PM.

The previous post in this blog was 3.3 ounces of security.

The next post in this blog is The independent channel.

Many more can be found on the main index page or by looking through the archives.

Powered by
Movable Type 3.34