Warning this article may contain opinions of the author that you and iTWire don't agree with.
Visit the last page to have your say in our forum.

No. 1 Story

Telstra adds one million mobile services, but Sensis plummets

Telstra has revealed the addition of almost one million new mobile services in the six months to December 2011, but Sensis revenues plummeted 24 percent in 12 months.

read more

Uh-oh: Safari, IE flaws combine to put Windows at risk!

Opinion and Analysis

The IE flaw was identified and reported "a long long time ago" by Aviv Raff who also realised that it could be combined with carpet bombing.

Microsoft has issued a security advisory on the issue, stating that changing Safari's default download location provides protection from the threat but nevertheless suggests to customers that they "Restrict [the] use of Safari as a web browser until an appropriate update is available from Microsoft and/or Apple."

(Here's an opportunity to use that human imagination I mentioned above: what can you do with a web browser other than use it as a web browser?)

Raff believes changing the download location does not protect against the combined vulnerability, and that carpet bombing could be used in conjunction with vulnerabilities in other products.

The good news is that - as far as Microsoft knows - the technique has not been used in real life, but that probably won't last.

How should this be dealt with?

Well, it seems clear to me that the reported IE flaw requires an urgent fix. If it's possible for a browser to automatically trigger the execution of a file in a user-controlled folder, there's something very wrong.

So, does this let Apple off the hook?

No, but it's harder to see what the 'right' answer would be, and I can understand why Dhanjani was warned that a change to Safari based on his report would require the involvement of the company's human interface team.

A preference that prevents Safari from downloading any non-renderable/playable content has been suggested, but what happens when you want to download a program from a developer's web site? Please read on to page 3 .



- sponsored feature -

The Death of Traditional BI: What’s Next?

How to Make Business Discovery Work for Your Business IP PABX BUYING GUIDE

Business Discovery takes its cues from consumer apps. Like Google, it encourages us- ers to hunt for and explore data without worrying about or even noticing the underly- ing technology. Their entire experience is working within an intuitive interface to get real-time, self-service results with only minimal training. ...more