Do browsers need a 'best-before' date?

Security researchers have suggested that like food, browsers should have a best-before or expiry date. This comes after revealing that 637 million internet users are surfing with outdated and unpatched browsers, which puts them at risk from web-based attacks.

Using data collected from Google Web searches and security firm Secunia, the researchers, Stefan Frei (of ETH, Zurich), Thomas Dübendorfer (Google), Gunter Ollmann (IBM ISS), and Martin May (ETH, Zurich), analysed the browsers used in a new report (PDF). They did so in an effort to understand why so many recent attacks by criminal hackers have been aimed at the browser, and why those attacks have been so successful.

The authors found that roughly 40 per cent of users had insecure versions of their Web browser. Among the least compliant were users of Internet Explorer, which currently dominates the market.

The data was collected in mid-June 2008. The users were scattered among 78 per cent Internet Explorer users, 16 per cent Firefox, three per cent Safari, and 0.8 per cent for Opera. Of these, 52 per cent were running the latest version of Internet Explorer, 92 per cent for Firefox, 70 per cent for Apple, and 90 per cent for Opera.

The authors note that it has taken IE 7, the current Internet Explorer release, 19 months to gain only 52 percent of the entire Internet Explorer audience. Forty-eight percent of the users in the study were either using an old version of IE 7 or still had IE 6 installed.

Some of this has to do with how the respective vendors provide updates. IE 7 is currently offered as an auto-update with each monthly set of Microsoft security patches, yet a number of people are opting out of the upgrade and still running IE 6.

The study did not include use of insecure browser add-ons, such as older versions of Adobe Reader, because the data from Google contained only the browser info.

For mitigation, the study used comparisons to the food industry, arguing that people understand the need to buy the safest foods, why not browsers? People understand that food is perishable, so why not make Internet browsers display expiration dates? The authors provided an example of a browser that displayed in red in the upper right hand corner "145 days expired, 3 updates missed."

But unlike the food industry there is no liability for software vendors. And, the authors note, software vendors are not legally obligated to provide software updates.

Imagine if the food industry was not accountable for selling spoiled milk.

Like this article? Click below to send it to your mobile for free!

Advertisement

Talkback 2 comments

  1. responsible? Anonymous -- 02/07/08

    It's not a butcher is responsible if you leave meat in the fridge for months before eating it

  2. Difference.. Anonymous -- 03/07/08

    A large number of people still use windows 95/98/ME, those don't suport the newest Internet-explorer, so it might be that those are likely to use IE6, where firrfox would be better. For the newest versions I doubt any difference in safety. I use IE7 as well as firefox2, sometimes I like FF better,other times it's IE...

Add your opinion


Latest Videos

ZDNet's CIO Vision Series

Video | Optus CIO Lawrie Turner

In this exclusive video interview, Optus chief information officer Lawrie Turner speaks to ZDNet.com.au about being the IT head for Australia's number two telco.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • David Braue Telstra's BT coat doesn't fit
    The vision of the future BT portrayed this week at an Australian conference was so far removed from how Telstra's David Quilty has described the British telco that I wonder if they were talking about the same UK.
  • Array Australian security: the lucky country
    Does anyone seriously believe that Australian businesses and government agencies manage security any better than the US or UK?
  • Array Storage infrastructure on the tender track
    For a large-scale storage project, it's not uncommon to go out to tender for the best deal — but when was the last time you had to put together a tender for a document management room?
  • More blogs »

Tags

Back to top

Featured