Yet another critical IE security hole
Moderators: snarkout, Patrick, dann
Yet another critical IE security hole
http://www.eweek.com/article2/0,1895,1941507,00.asp
http://www.microsoft.com/technet/securi ... fault.mspx
Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
http://www.microsoft.com/technet/securi ... fault.mspx
Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
Ego contemno licentia
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
Re: Yet another critical IE security hole
Couldn't agree more, it should be a no brainer to understand that a browser that's not a part of the operating system is safer.Patrick wrote:Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!


"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.
Re: Yet another critical IE security hole
Great! If they keep wasting their time fixing security holes they'll NEVER get their broken CSS support fixed!Patrick wrote:Any admin that says with a straight face that IE is a
safer choice than FF is a baffoon that should be immediately fired!
Per the article, the hole exists in IE 7 beta, too.
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
Re: Yet another critical IE security hole
LOL yeah, maybe by September we'll get something like "Vista is going to be out during summer 2007, we need do a complete security audit!", and then we see Jim Allchin going "Dude, you do want a secure operating system don't you, it'll be worth waiting for Vista my man, don't go with the Lajnix or FreeBFD stuff, no no that stuff is communism, DID YA HEAR ME NIGGA!!"Gomer_X wrote:Great! If they keep wasting their time fixing security holes they'll NEVER get their broken CSS support fixed!![]()
Hmmmm, now what was it Microsoft said about IE 7, hmmmmm, I don't seem to remember, it was something about security, oh yeah I got it, they said IE 7 would be more secure!!Gomer_X wrote:Per the article, the hole exists in IE 7 beta, too.


"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.
Re: Yet another critical IE security hole
At least they're consistent!Gomer_X wrote:Per the article, the hole exists in IE 7 beta, too.
Ego contemno licentia
Re: Yet another critical IE security hole
Tell that to the gnome and kde folks...Tsuroerusu wrote:Couldn't agree more, it should be a no brainer to understand that a browser that's not a part of the operating system is safer.Patrick wrote:Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson
--Spider Robinson
Re: Yet another critical IE security hole
Just heard on CNET's Buzz out loud podcast (03/22/06) that IE 7 will be unbundled from Vista and released separately. UnfortuntelyTsuroerusu wrote:Couldn't agree more, it should be a no brainer to understand that a browser that's not a part of the operating system is safer.Patrick wrote:Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
Re: Yet another critical IE security hole
I think they already know, and come on, no one in the open source community is stupid enough to make neither Konqueror, Firefox, Mozilla or whatever, part of the Linux kernel.Snarkout wrote:Tell that to the gnome and kde folks...


"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.
Re: Yet another critical IE security hole
True - but it still creeps me out a little. I admit I really love the coherence between KDE apps, but in the back of my mind is always "This is going to bite someone in the ass at some point..."Tsuroerusu wrote:I think they already know, and come on, no one in the open source community is stupid enough to make neither Konqueror, Firefox, Mozilla or whatever, part of the Linux kernel.Snarkout wrote:Tell that to the gnome and kde folks...
Shared pain is lessened, shared joy is increased; thus do we refute entropy.
--Spider Robinson
--Spider Robinson
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
Re: Yet another critical IE security hole
Well, if KHTML has a vulnerability, KMail is subject to email exploits, because it uses KHTML to display an HTML email.Snarkout wrote:True - but it still creeps me out a little. I admit I really love the coherence between KDE apps, but in the back of my mind is always "This is going to bite someone in the ass at some point..."
But dude, think about it, with stuff like Novell's AppArmor, which IS being ported to distros like Slackware and Fedora, you can prevent stuff like this from happening, what AppArmor you say: This application can access these files and this folder.
For example, if you've used Firefox, in some cases it can set itself as the default web browser, which it does to the GNOME environment, it modifies a file in your GNOME configuration. If you have AppArmor enabled, it cannot do this, because AppArmor prevents Firefox from accessing the GNOME configuration, this way we can say: Thunderbird and KMail can access here and here, and in this way, NO ONE can write can exploit a vulnerability in KHTML to wipe your home directory.
I don't see your point about integration biting people in the ass, because if we don't make applications and the desktop integrate nicely with each other, we will always be behind Apple and Linux will never have a huge success on the desktop. For example something I would like Konqueror to do is if digiKam is installed, it should have an option so you can right click on a file and select "Add to photo collection" or something like that, and then the image is copied to digiKam's photo directory and database.


"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.
- Wally Balljacker
- Posts: 1227
- Joined: Fri Jul 29, 2005 3:32 am
- Location: University of Massachusetts - Lowell
- Contact:
Re: Yet another critical IE security hole
Exactly. I'm running GNOME right now, and it's dependent on both Mozilla AND Epiphany. That's pretty lame considering I install Firefox and eLinks afterwards, so I end up with 4 web browsers on my system. 5 if I had KDE installed.Snarkout wrote:Tell that to the gnome and kde folks...Tsuroerusu wrote:Couldn't agree more, it should be a no brainer to understand that a browser that's not a part of the operating system is safer.Patrick wrote:Any admin that says with a straight face that IE is a safer choice than FF is a baffoon that should be immediately fired!
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
Re: Yet another critical IE security hole
I think it's perfectly reasonable for KDE to integrate their own HTML engine into the desktop so an application eaisily can display web content. KDE is not only a desktop, but also a development environment if you think about it. For example, if I were to write an RSS reader, I would want an easy way to display the page the links in the feed points to.
But if you guys believe that every application should be independant of the others, try to convince Mac people, and to some degree Windows whiners, to move to Linux.
But if you guys believe that every application should be independant of the others, try to convince Mac people, and to some degree Windows whiners, to move to Linux.


"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.
-
Tsuroerusu
- Posts: 2551
- Joined: Mon Sep 05, 2005 8:51 am
- Location: Silkeborg, Denmark
- Contact:
Sure it can, there was a quite critical hole in KHTML, but it was patched about 1½ hours later. I saw a patch from KDE about an hour after I first heard of the exploit, and I received a patch from SUSE two hours later and I saw one available at the same time.Snarkout wrote:I think the integration is great, but I also think it can end up being an attack vector.
I don't know if Microsoft purposely design their software to be insecure, but it sure looks like that sometimes. I think the KDE developers has looked at Microsoft and how insecure their shit OS are and keep that ind mind, although there will always be some security issues, but then here the advantage of open source comes into place, as those can be found and fixed before having a chance of being exploited.
Whe I look at the amount of patches both Microsoft and Apple ships, I really apreciate GNU/Linux and *BSD, it just seems we have much fewer security vulnerabilities.


"Hatred does not cease by hatred, but only by love. This is the eternal rule."
- Siddhattha Gotama (Buddha), founder of Buddhism.