Latest Comments
"You should hire people to fight trojans and stuff"
by Me | Aug 29, 2008 7:27 AM
 
"Not exactly an innovative feature Microsoft. Other browsers have had this capability for a long ..."
by Chris Jones | Aug 28, 2008 7:38 PM
 
"Hey"
by Emilio Garcia | Aug 27, 2008 2:53 AM
 
"adfdas"
by ddd | Aug 26, 2008 4:24 PM
 
"i have seen a few iPhone porn sites and while most of them are crap I did run across one that ..."
by gate | Aug 23, 2008 6:30 AM

Windows users prompted for Safari install as part of update

  • Email a Friend
  • Print Page
Windows users prompted for Safari install as part of update
By Dan Kaplan
Mar 26, 2008 10:14 AM
Tags: "windows | update" | "safari | update" | "windows | vs | safari" | "mozilla"
Last week, users were prompted to download an iTunes security update that also included an update to the latest version of Safari for Windows, even if users did not have the browser already deployed on their machine.

Mozilla's John Lilly wrote on his personal blog that he disapproved of using this practice because it is misleading to users and erodes their trust in software vendors.

“The problem here is that it lists Safari for getting an update – and has the “Install” box checked by default – even if you haven't ever installed Safari on your PC,” he said.

“That's a problem because…by and large, all software makers are trying to get users to trust us on updates, and so likely behaviour here is for users to just click [to install]. It's wrong because it undermines the trust we're all trying to build with users,” he continued. “Because it means that an update isn't just an update, but is maybe something more.”

An Apple spokeswoman did not return a phone call seeking comment.

Rich Mogull, founder of consultancy Securosis, told SCMagazineUS.com today that Apple's attempt at creating more market share for Safari could be viewed as deceptive.

“Literally, that is the definition of spyware in many cases,” he said. “It's surreptitiously installed software you don't want on your machine.”

Apple is setting a poor precedent, he said.

“We're starting a bad habit if we continue to intermingle security with [software] functionality updates,” he said. “Let's be honest. A lot of vendors do this, but when you're the size and scope of Apple and when millions and millions of users have iTunes and the next thing you're giving them is a browser they didn't ask for – that's pretty serious.

Statistics show that Safari has between a three- to six-percent share of browser usage, while Mozilla Firefox retains a roughly 15 percent share. Internet Explorer dominates the market with a roughly 75 percent share.

Meanwhile, a security researcher on Monday reported two dangerous vulnerabilities in the Safari for Windows web browser.

Version 3.1 of the browser is susceptible to two vulnerabilities – rated “highly critical” by bug tracking vendor Secunia – that could be leveraged to launch URL spoofing attacks or cause system compromise.

Researcher Juan Pablo Lopez Yacubian discovered the flaws. One of the bugs relates to an error when downloading ZIP files containing too long of a filename. This can lead to memory corruption and permit an attacker to execute arbitrary code.

The other hole involves the handling of windows, which can be exploited to show a bogus URL in the address bar for a legitimate website.

As users await a fix, they are advised not to browse untrusted websites.

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
 
Patch Management Whitepapers