#### Why people should stop using IE

http://www.itworld.com/security/93253/who-cares-if-ie-patched-soon

Because Microsoft only patches bugs which:

- are publicly known
- for which working exploit code exists
- is being exploited on a massive scale
- people start to jump ship towards other browsers

Most importantly: Microsoft IGNORES all other bugs and security
exploits if they are used on a 'limited' scale. For most bugs they'll
tell you to switch to a new, safer Windows (please buy a new computer
too) and install a newer version of IE.

There are more than likely hundreds of potential security bugs in IE
which aren't patched and which hackers may or may not know about. Large
U.S. companies and defense contractors are learning that they are
beseiged by hackers almost on a daily basis using zero day holes in
both IE and Adobe Acrobat Reader and Flash software. I suspect that the
hackers (the Chinese government) are using these zero day holes
aparingly opting for massive simultaneours breakins before the holes
are patched. That's why we see waves and waves of attacks targetting
U.S. multinationals and defense contractors.

The bottom line is: Windows and Internet Explorer simply can't be
trusted anymore and the U.S. government should publicly advise that
people need to move towards Linux and Firefox. I suspect that this will
happen this year (in 2010).


1/20/2010 9:58:38 PM

http://www.internetnews.com/security/article.php/3374931

US-CERT: Beware of IE

The U.S. government's cybersecurity unit recommends ditching Internet
Explorer in favor of other, safer browsers.

June 29, 2004

Chris
1/20/2010 11:01:01 PM
Microsoft was also caught patching security bugs secretly (no disclosure and no

The numbers they give are bunk.

Roy
1/21/2010 4:59:12 PM
>Non scrivetemi wrote:
>>[...]Windows and Internet Explorer simply can't be trusted
>>anymore and the U.S. government should publicly advise that[...]
>>
Chris Ahlstrom wrote:
>[...]June 29, 2004
>
http://www.kb.cert.org/vuls/id/713878
That was actually CERT's second time putting out the advisory.
(The second time included a bit more detail.)[1]
The first advisory was April 5, 2004.
http://www.kb.cert.org/vuls/id/323070
..
..
[1] The fallout from a conjunction of an IE vulnerability
and an IIS vulnerability
was actually covered by the corporate news outlets.
When your crap makes the national TeeVee news,
it's obvious that you screwed up massively.

JeffM
1/21/2010 7:04:06 PM
New Excel vulnerability being exploited ,----[ Quote ] | Affected versions of the software are Excel 2003 SP2, Excel Viewer 2003, | Excel 2002, Excel 2000, and Excel 2004 for Mac. Microsoft especially warns | that there are no known workarounds for the issue for Excel 2000 or 2002. ---- http://www.itwire.com/content/view/16136/1054/ Related: UK children's charity says goodbye to Excel ,----[ Quote ] | Cognos TM1 will house the charity's budgeting and financial planning data | currently held on 2,000 Excel spreadsheets. ---- http://www.computerbusinessreview.com/article_n...