Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Don’t Blame the Browser
Melih Abdulhayoglu, 2009-02-06

There was a time when most diseases were fatal for humans. Intense study and research helped doctors manage diseases better, and subsequently even prevent them altogether.

Comments Mode:
Economics says "blame the browser" 2009-02-08
Jim (1 replies)
So, your argument seems to be that the browser shouldn't be doing security; because the OS should be doing it.

That would be fine in an ideal world. However the OSs (all of them) are known to apply insufficient security, some more than others. Given that the browser is the primary interface to th...

[ more ]  [ reply ]
Re: Economics says "blame the browser" 2009-02-10
Anonymous
I think what he was saying is that rather than the onus of security being the browser (or the O/S as you suggested), dedicated security software should form an outer protective layer and co-operate in conjunction with the security contained within the browser and the O/S.

Cheers,
:-)
...

[ more ]  [ reply ]
Don’t Blame the Browser 2009-02-09
Anonymous (1 replies)
i don't understand the point of this article. please don't write any more SF articles.

thanks....

[ more ]  [ reply ]
Re: Don?t Blame the Browser 2009-02-09
Anonymous (1 replies)
Agreed.

How is the OS at fault for the browser sending the google.com cookie to attacker.ru?......

[ more ]  [ reply ]
Re: Re: Don't Blame the Browser 2009-02-17
Anonymous
I do not like to see especially these kinds of generic writings posted on SF.If you don't have new or interesting stuff to provide, just read, do not post.Of course from a relative view of perspective this subject may be open to discussions.But here is not the place to discuss it.Try some Yahoo or G...

[ more ]  [ reply ]
Don’t Blame the Browser 2009-02-09
Anonymous
This is a poorly written column which is rife with mistakes. Was it even edited? The content isn't much better....

[ more ]  [ reply ]
Don’t Blame the Browser 2009-02-09
Anonymous (1 replies)
A browser's job is to provide information.
A restaurant's job is to provide something to eat.

It's not the browser's fault if some of that information damages your computer.

It's not the restaurant's fault if some of that stuff makes you sick....

[ more ]  [ reply ]
Re: Don?t Blame the Browser 2009-02-11
Anonymous
It is the restaurant's fault if they fail to take proper precautions, and the customers get sick from salmonella.

It is at least partly the browser's fault if, likewise, the developers fail to take proper precautions and prevent memory leaks and the like....

[ more ]  [ reply ]
An ounce of prevention 2009-02-09
mechBgon
The most powerful blanket defense is to use the least-privilege principle. Use a low-rights account to browse the Internet. Anything else is like driving without your seatbelt fastened.

For those versions of Windows that support it, Software Restriction Policy in disallowed-by-default mode will...

[ more ]  [ reply ]
Don’t Blame the Browser 2009-02-10
Grenage
A poor analogy, and browsers are supposed to browse the web while not compromising the computer. You can pass the buck as frequently as you like, but it has to stop somewhere....

[ more ]  [ reply ]
Don’t Blame the Browser 2009-02-10
m6a
what he mean is that your not safe with any browser, that you need something to guard the browser.

Such as comodo internet security that will protect it from buffer overflows, and all types of driveby downloads....

[ more ]  [ reply ]
D i D 2009-02-10
Eric H
Defense in Depth
Blame everybody. The browser SHOULD be to blame for its own buffer overruns. It should be blamed for cookie related issues, etc. It should be blamed for things for which it is in charge. The OS should be responsible for its areas and so on.
Then we should ALSO install security so...

[ more ]  [ reply ]
Don’t Blame the Browser 2009-02-14
RG (1 replies)
His point is spot on - browsers have a specific job to do and security was not part of their original mission statement.

It's a new world and we must look at the high failure rate of browser security and intelligently ask difficult questions. That's what he is doing.
...

[ more ]  [ reply ]
Re: Don?t Blame the Browser 2009-03-11
Anonymous
You are right, No Idea is obsolete. Its the time to ask intelligent questions among Research community.. to spot exactly where these problems can be fixed efficiently. Don't criticize one without a legitimate example or situation. ...

[ more ]  [ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus