LinuxWorld

Study: Unpatched Web browsers prevalent on the Internet

Only 59.1% of people use up-to-date, fully patched Web browsers, putting the remainder at risk from growing threats from diligent hackers, according to a new study published by researchers in Switzerland.

The study, published Tuesday, is one of the most comprehensive analyses of what versions of Web browsers people are using on the Internet. The study was conducted by researchers at The Swiss Federal Institute of Technology, Google and IBM Internet Security Services.

Web browsers are often a weak link in the security chain, as software vulnerabilities can make it easy for hackers to gain control of a PC. When that happens, hackers can perform malicious acts such as stealing personal data or turning PCs into spam-spewing drones.

What the researchers found is that although software vendors provide patches for security problems, it can take days, weeks or months before people update their applications. In the meantime, those users are at risk.

But it's not entirely the fault of users, since Web browser vendors haven't exactly made patching easy, said Stefan Frei, a doctoral student at the institute, which is known as ETH Zurich, and one of the report's authors. The Web browser is still fairly young technology, and the industry has yet to settle on a dominant, well-tested design, he said.

The study looked at search and Web application server log data provided by Google to see what versions of the Firefox, Opera or Safari browsers people were using, Frei said.

Microsoft's Internet Explorer, however, only tells Web servers what major version a person is using, such as IE 6 or IE 7. The researchers relied on data from people who have installed a tool on their PC called the Personal Software Inspector, from Danish security company Secunia that can detect incremental versions of IE, Frei said.

Firefox users were the best at upgrading: 83.3 percent are using the latest version (the study just looked at Firefox 2.0). For Apple's Safari, 65.3 percent use the latest version; 56.1 percent for Opera and 47.6 percent for Microsoft's Internet Explorer.


Invalid query - session: Can't connect to local MySQL server through socket '/tmp/mysql.sock' (2)
Newsletter sign-up

Sign up for one of Network World's newsletters compliments of Linux World

Linux & Open Source News Alert
Web Applications Alert
Video and Podcast Alert
Security Alert
Virtualization Alert

Email Address: