Yet another critical IE security hole

Hey drop us a line about the show. Feel free to ask questions, provide feedback and criticism, or just ramble on about anything your little heart desires.

Moderators: snarkout, Patrick, dann

User avatar
Patrick
Site Admin
Posts: 2519
Joined: Tue Apr 27, 2004 11:38 am
Location: Easton, PA
Contact:

Yet another critical IE security hole

Post by Patrick » Thu Mar 23, 2006 10:27 am

http://www.eweek.com/article2/0,1895,1941507,00.asp
http://www.microsoft.com/technet/securi ... fault.mspx

Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
Ego contemno licentia

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Re: Yet another critical IE security hole

Post by Tsuroerusu » Thu Mar 23, 2006 10:45 am

Patrick wrote:Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
Couldn't agree more, it should be a no brainer to understand that a browser that's not a part of the operating system is safer.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
Gomer_X
Posts: 901
Joined: Fri Jun 03, 2005 1:31 pm
Location: Cincinnati, Ohio, USA
Contact:

Re: Yet another critical IE security hole

Post by Gomer_X » Thu Mar 23, 2006 10:52 am

Patrick wrote:Any admin that says with a straight face that IE is a
safer choice than FF is a baffoon that should be immediately fired!
Great! If they keep wasting their time fixing security holes they'll NEVER get their broken CSS support fixed! :D

Per the article, the hole exists in IE 7 beta, too.

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Re: Yet another critical IE security hole

Post by Tsuroerusu » Thu Mar 23, 2006 11:02 am

Gomer_X wrote:Great! If they keep wasting their time fixing security holes they'll NEVER get their broken CSS support fixed! :D
LOL yeah, maybe by September we'll get something like "Vista is going to be out during summer 2007, we need do a complete security audit!", and then we see Jim Allchin going "Dude, you do want a secure operating system don't you, it'll be worth waiting for Vista my man, don't go with the Lajnix or FreeBFD stuff, no no that stuff is communism, DID YA HEAR ME NIGGA!!" :P

Gomer_X wrote:Per the article, the hole exists in IE 7 beta, too.
Hmmmm, now what was it Microsoft said about IE 7, hmmmmm, I don't seem to remember, it was something about security, oh yeah I got it, they said IE 7 would be more secure!!
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
Patrick
Site Admin
Posts: 2519
Joined: Tue Apr 27, 2004 11:38 am
Location: Easton, PA
Contact:

Re: Yet another critical IE security hole

Post by Patrick » Thu Mar 23, 2006 11:05 am

Gomer_X wrote:Per the article, the hole exists in IE 7 beta, too.
At least they're consistent!
Ego contemno licentia

User avatar
snarkout
Site Admin
Posts: 1342
Joined: Tue Aug 16, 2005 9:35 pm

Re: Yet another critical IE security hole

Post by snarkout » Thu Mar 23, 2006 11:06 am

Tsuroerusu wrote:
Patrick wrote:Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
Couldn't agree more, it should be a no brainer to understand that a browser that's not a part of the operating system is safer.
Tell that to the gnome and kde folks...
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson

Judland
Posts: 1030
Joined: Tue Apr 27, 2004 12:55 pm

Post by Judland » Thu Mar 23, 2006 11:10 am

Actually, isn't Konqueror considered to be in the "most secure" end of the pool?

User avatar
Gomer_X
Posts: 901
Joined: Fri Jun 03, 2005 1:31 pm
Location: Cincinnati, Ohio, USA
Contact:

Re: Yet another critical IE security hole

Post by Gomer_X » Thu Mar 23, 2006 11:13 am

Tsuroerusu wrote:
Patrick wrote:Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
Couldn't agree more, it should be a no brainer to understand that a browser that's not a part of the operating system is safer.
Just heard on CNET's Buzz out loud podcast (03/22/06) that IE 7 will be unbundled from Vista and released separately. Unfortuntely :D it won't be available until Vista is released.

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Re: Yet another critical IE security hole

Post by Tsuroerusu » Thu Mar 23, 2006 11:23 am

Snarkout wrote:Tell that to the gnome and kde folks...
I think they already know, and come on, no one in the open source community is stupid enough to make neither Konqueror, Firefox, Mozilla or whatever, part of the Linux kernel.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
snarkout
Site Admin
Posts: 1342
Joined: Tue Aug 16, 2005 9:35 pm

Re: Yet another critical IE security hole

Post by snarkout » Thu Mar 23, 2006 12:22 pm

Tsuroerusu wrote:
Snarkout wrote:Tell that to the gnome and kde folks...
I think they already know, and come on, no one in the open source community is stupid enough to make neither Konqueror, Firefox, Mozilla or whatever, part of the Linux kernel.
True - but it still creeps me out a little. I admit I really love the coherence between KDE apps, but in the back of my mind is always "This is going to bite someone in the ass at some point..."
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Re: Yet another critical IE security hole

Post by Tsuroerusu » Thu Mar 23, 2006 12:47 pm

Snarkout wrote:True - but it still creeps me out a little. I admit I really love the coherence between KDE apps, but in the back of my mind is always "This is going to bite someone in the ass at some point..."
Well, if KHTML has a vulnerability, KMail is subject to email exploits, because it uses KHTML to display an HTML email.

But dude, think about it, with stuff like Novell's AppArmor, which IS being ported to distros like Slackware and Fedora, you can prevent stuff like this from happening, what AppArmor you say: This application can access these files and this folder.

For example, if you've used Firefox, in some cases it can set itself as the default web browser, which it does to the GNOME environment, it modifies a file in your GNOME configuration. If you have AppArmor enabled, it cannot do this, because AppArmor prevents Firefox from accessing the GNOME configuration, this way we can say: Thunderbird and KMail can access here and here, and in this way, NO ONE can write can exploit a vulnerability in KHTML to wipe your home directory.

I don't see your point about integration biting people in the ass, because if we don't make applications and the desktop integrate nicely with each other, we will always be behind Apple and Linux will never have a huge success on the desktop. For example something I would like Konqueror to do is if digiKam is installed, it should have an option so you can right click on a file and select "Add to photo collection" or something like that, and then the image is copied to digiKam's photo directory and database.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
Wally Balljacker
Posts: 1227
Joined: Fri Jul 29, 2005 3:32 am
Location: University of Massachusetts - Lowell
Contact:

Re: Yet another critical IE security hole

Post by Wally Balljacker » Thu Mar 23, 2006 6:23 pm

Snarkout wrote:
Tsuroerusu wrote:
Patrick wrote:Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
Couldn't agree more, it should be a no brainer to understand that a browser that's not a part of the operating system is safer.
Tell that to the gnome and kde folks...
Exactly. I'm running GNOME right now, and it's dependent on both Mozilla AND Epiphany. That's pretty lame considering I install Firefox and eLinks afterwards, so I end up with 4 web browsers on my system. 5 if I had KDE installed.

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Re: Yet another critical IE security hole

Post by Tsuroerusu » Thu Mar 23, 2006 6:38 pm

I think it's perfectly reasonable for KDE to integrate their own HTML engine into the desktop so an application eaisily can display web content. KDE is not only a desktop, but also a development environment if you think about it. For example, if I were to write an RSS reader, I would want an easy way to display the page the links in the feed points to.

But if you guys believe that every application should be independant of the others, try to convince Mac people, and to some degree Windows whiners, to move to Linux.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

User avatar
snarkout
Site Admin
Posts: 1342
Joined: Tue Aug 16, 2005 9:35 pm

Post by snarkout » Thu Mar 23, 2006 8:16 pm

I'd really appreciate it if you didn't put words in my mouth, or purpously misrepresent my opinions. I think the integration is great, but I also think it can end up being an attack vector.
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson

Tsuroerusu
Posts: 2551
Joined: Mon Sep 05, 2005 8:51 am
Location: Silkeborg, Denmark
Contact:

Post by Tsuroerusu » Thu Mar 23, 2006 10:11 pm

Snarkout wrote:I think the integration is great, but I also think it can end up being an attack vector.
Sure it can, there was a quite critical hole in KHTML, but it was patched about 1½ hours later. I saw a patch from KDE about an hour after I first heard of the exploit, and I received a patch from SUSE two hours later and I saw one available at the same time.

I don't know if Microsoft purposely design their software to be insecure, but it sure looks like that sometimes. I think the KDE developers has looked at Microsoft and how insecure their shit OS are and keep that ind mind, although there will always be some security issues, but then here the advantage of open source comes into place, as those can be found and fixed before having a chance of being exploited.

Whe I look at the amount of patches both Microsoft and Apple ships, I really apreciate GNU/Linux and *BSD, it just seems we have much fewer security vulnerabilities.
Image
Image

"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.

Post Reply