EXPLOITS & VULNERABILITIES

Study: 40 Percent of Web Surfers Using Leaky, Vintage Browsers

Print Version
E-Mail Article
Reprints

Outdated and unpatched browsers are putting 40 percent of Web surfers at risk, according to a recent study by Google, IBM and Switzerland's Communications Systems Group. Most of the surfers at risk are using outdated Internet Explorer versions.


APC by Schneider Electric White Papers
APC white papers provide the techniques, guidelines and tools you need to make the most effective decisions regarding your IT installations. Download a relevant APC white paper today!

If the food industry ran its business like the Internet browsing software industry, then consumers would be hurling lawsuits like bad tomatoes at the companies that give us Internet Explorer, Firefox and Safari.

The comparison is existent in a wide-ranging new study showing that approximately 40 percent of the Internet surfing public -- 576 million users -- browsed the Web using outdated and/or unpatched software, putting themselves and the computing public at risk.

The Methodology

Researchers from Google (Nasdaq: GOOG) Latest News about Google, IBM Internet Security Systems (Nasdaq: ISSX) Latest News about Internet Security Systems and Switzerland's Communications Systems Group conducted the study.

Researchers examined surfing habits in June 2008 using data provided by Google. Seventy-eight percent of the users were running Microsoft (Nasdaq: MSFT) Latest News about Microsoft Internet Explorer, 16 percent used Mozilla Latest News about Mozilla Foundation Firefox, 3 percent ran Apple (Nasdaq: AAPL) Latest News about Apple Safari and less than one percent surfed using Opera. Most of the Web surfers at risk are using old, outdated versions of Internet Explorer.

Web-Based Threats Now a Priority

Two experts with computer security companies interviewed by TechNewsWorld seconded most of the study's findings, saying Web-based threats are now the top problem for IT professionals and consumers.

"This is not one problem, this is many, many problems," said David Perry, director of global education for Trend Micro (Nasdaq: TMIC) Latest News about Trend Micro. "We're not just talking one patch. You would need 100 to 150 patches. It's a very complicated landscape."

Web browsers started becoming problematic with the advent of multimedia on Web sites and the rise of Web 2.0 applications, Perry told TechNewsWorld. "[The browsers] are built to automatically execute code they find on the Web page, and people have found a way to make that code do things they want to do," like stealing personal information or setting up a computer as a "zombie," spewing out spam or malicious software code.

"The browser is one of the top attack vectors in use today," Ben Greenbaum, senior research manager Improve customer service and productivity with Avaya Unified Communications. at Symantec (Nasdaq: SYMC) Latest News about Symantec told TechNewsWorld. "Almost every major attack involves the browser at some point."

Applications and plug-ins are also targeted, Greenbaum said, since many of those can involved outdated or nonsecure code even if running on an updated browser.

Browser Companies Must Become Security Experts

The solutions for bad browsers must focus on more research and responsibility by both software companies and those who use their products, both Perry and Greenbaum noted.

"The vendors have to get into the security research business," Perry said. "They don't just build a browser nowadays, they have to hire scientists to do the research so that they understand the vulnerabilities they are patching."

The updating process needs to be easier for consumers to understand, Greenbaum commented. "Some browsers have auto-update features; some do not. Some are enabled by default; some are not. The user does not want this to be a concern, but regardless, they still need to be protected.

"The first line of defense should be making sure all known vulnerabilities are addressed. That's partially the user's responsibility, but vendors could do a much better job," he added.

Social Networking Toolbox:

Print Version E-Mail Article Reprints More by Renay San Miguel   RSS

Related Resources

Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]