Sun, Aug 20 2006 2:47
bradley
The lesson this month.
http://www.vladville.com/2006/08/internet-explorer-security-tips.html#comments
Just a follow up to this....
I catch anyone installing Firefox on a server and I'll use a 2x4 on you.
Servers "serve".
Servers don't surf. Period. Therefore there is no need for truly 'any' browser on a server. Nor email for that matter.
You don't go to websites other than MU/WU on a server... not even Vlad's site.
In fact for many server admins.. you could rip out IE all together and it would not phase them a bit.
Yes every month there is seemingly another browser vuln out there...but it's not just IE ...and as long as all of us are running with admin rights... pick a browser any of them... it doesn't matter. The malware guys will still nail you. HD Moore's month of browser vulnerabilities granted had most found in IE, but Firefox and Opera were not immune. And in fact there are indeed malware exploits that are specifically targeting Firefox these days. As long as we're all running our machnes with administrative rights, a browser is like anti-virus. Reactive and not proactive. Always one step behind the bad guys.
I'd argue that the issue this month is not with the vulnerability of IE, but rather how dependent we are on IE for our line of business apps. What you should have been ranting about instead Vlad, was not for folks to install Firefox....but rather that there were two Microsoft apps this month that got NAILED by it's own patches.
Microsoft CRM and Navision. That tells me that those two apps were not properly tested in the patch testing matrix.
That, my man, is the thing you should have been making the point about. I won't blame Microsoft for patches that affect some of my more bizarre line of business crud that I have. But at a minimum they should validate all of their own apps.
Because you see if they had validated their own, I think they would have found that IE crashing issue and prevented it (my personal opinion not validated on anything at all scientific).
That my man is the lesson to be learned from this month's patches.
...that and don't let me catch anyone installing Firefox or Opera on servers...
Filed under: Rants