IE Homeland Insecurity
From the “for those of you who don’t regularly read slashdot department”: I’m usually pretty skeptical of the Department of Homeland Security; I think it’s a pretty bad solution to the threat presented (see, e.g., Bruce Schneier’s comments on the subject), but I have to agree with them this time. The agency has issued a recommendation that users stop using Microsoft’s Internet Explorer and pick an alternative web browser. Wired Magazine reports that upgrades of the free software browser Mozilla have spiked sharply following the announcement.
The only reference I could find to the issue on the DHS website (which is not, incidentally, served by Microsoft software) was the following bit from this report:
Handling Dependencies
A coordinator may be required to conduct significant research into software, hardware, and firmware dependencies in order to provide complete and correct advice.
Rationale: Vulnerabilities are often discovered in software components on which other software relies. For example, a shared library may be used by dozens or hundreds of products. For instance, vulnerabilities in Microsoft’s Internet Explorer often affect other products (including products by third-party vendors) in ways that aren’t obvious to end users. Examples of products that are sometimes affected by Internet Explorer vulnerabilities include Lotus Notes, Eudora, and Microsoft Outlook. Furthermore, these dependencies are not typically recorded.
Presumably something more on-topic will be posted soon. There is also this warning from CERT (the United States Computer Emergency Readiness Team).