Friday, October 2, 2009

Google Chrome Browser Security Fail

Google's Chrome browser has had a spotty history of security issues. How spotty? Microsoft says that their security is no good:

The release of Google Chrome Frame, a new open source plugin that injects Chrome's renderer and JavaScript engine into Microsoft's browser, earlier this week had many web developers happily dancing long through the night. Finally, someone had found a way to get Internet Explorer users up to speed on the Web. Microsoft, on the other hand, is warning IE users that it does not recommend installing the plugin. What does the company have against the plugin? It makes Internet Explorer less secure.

"With Internet Explorer 8, we made significant advancements and updates to make the browser safer for our customers," a Microsoft spokesperson told Ars. "Given the security issues with plugins in general and Google Chrome in particular, Google Chrome Frame running as a plugin has doubled the attach area for malware and malicious scripts. This is not a risk we would recommend our friends and families take."
Microsoft's right. Google has at best a so-so record with Chrome (from a security perspective). Add the fact that it's hard to update browser plugins, and this is A Bad Idea.

And regular readers know that I don't think much of Internet Explorer. However, IE 8 is changing that. Microsoft has that old security religion with IE 8. It's still a big target, but the security is quite frankly impressive. There's just one thing you have to do - turn ActiveX off. I'll do a more detailed post, but here's what you want to do:
  1. From the "Tools" menu, Select "Internet Options"
  2. On the "Internet" tab, select "Custom Level"
  3. You'll have a list of options. Scroll down to the ActiveX section and turn off everything in the section that uses the words "ActiveX control". Yes, everything.
At this point, you have a decently secure browser. I still like that Firefox checks for security updates as needed, and you don't have to hang around until Patch Tuesday to get your fixes. But IE 8 is something that I'll actually use once in a while without wincing. Must be getting soft in my old age ...

Remember, Internet Explorer 6 and 7 are a nightmare. A lot of you still use it, so you should switch to Firefox or upgrade to IE 8. Like right now.

Srlsy. Opera's good, too.

No comments: