Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Fixes and Improvements

June 30th, 2012, 09:44 GMT · By

Security Risks Posed by Internet Explorer 10 in Windows 8 Metro

SHARE:

Adjust text size:

Comparison between fake and genuine PayPal sites in Internet Explorer 10 for Metro
Enlarge picture
Windows 8 promises a lot of innovative security features, but experts fear that many of the functionality improvements, especially the ones that come with the Metro interface, bring with them a number of risks that until now haven’t existed.

McAfee introduces a series of articles in which they detail the risks that come with the brand new Microsoft operating system and the first piece focuses on Internet Explorer 10 in Metro.

In Metro, Internet Explorer 10 has a cleaner look, mainly because the address bar and all the buttons are not visible by default. However, this could be a great advantage for cybercriminals that specialize in phishing campaigns.

First of all, users cannot see on which domain they’re actually on. If they’re presented with a well-designed replica of a PayPal webpage, for instance, internauts who fail to bring up the address bar could easily hand over their credentials to fraudsters.

When the address bar is visible, it actually represents a great security improvement, because it turns green if a secure connection is identified.

Experts say that the address bar should be programmed to automatically reveal itself whenever the user is on a page that requests login details.

Furthermore, the fairly large number of new features such as WebSockets, HTML5, cross-domain messaging, the support for Web Workers within JavaScript apps, and postMessage all bring with them a new attack surface.

“Malware may require only active browser instances to start and propagate instead of executable control over the entire system,” McAfee Security Architect Prashant Gupta explained.

“Proactive measures from antimalware solutions would be the most effective defense in this case because JavaScript is notoriously mutable, and executing JavaScript in a browser is more common for users than running downloaded applications on the desktop.”


2,169 hits
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


HITB 2012 Topics: WinRT and the “Ghost” in the Windows 7 Allocator

Torvalds: UEFI Keys Are a Solution, but Clever Hackers Will Bypass the System

Experts Find Improvements in Classic Phishing Emails

Scam: Dear PayPal Customer, Update Your Records Before June 12

Scammers Improve National Lottery Commission Scam, Experts Find

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM