IE, along with the rest of Windows, is designed with the primary goal of making life easier for developers while hiding the resulting complexity for users. Unfortunately, this creates an ideal environment for malicious coders, who regularly take advantage of IEs "auto-magical" scripting capabilities to wreak havoc on the Windows platform.
Microsoft Corp.s Web site states, "As soon as you start using Internet Explorer 6, it takes precautionary measures to help you have a secure browsing experience." Also according to Microsoft, the only way to ensure a truly secure browsing experience is to disable this functionality by twiddling with security zone settings and modifying registry keys to plug the holes that Microsoft shouldnt have opened in the first place.
Windows XP Service Pack 2, due by the end of the summer, will make some of these changes by default, but it will also break applications that depend on IEs built-in vulnerabilities to function.
Since much of IEs "richness" must be disabled to browse safely—and its a safe bet that weve not seen the last of IEs vulnerabilities—enterprises must ask themselves whether theyd be better off switching to a different browser.
Alternatives such as Mozilla and Opera boast better security track records than IE and significant usability advantages. Mozillas and Operas support for tabbed browsing and pop-up blocking alone are worth the switch, but IE also cannot match these browsers Web standards support.
Its true that IE alternatives bring with them added deployment complexity for enterprises, but with Microsoft advocating checklists of complicated adjustments to run IE with relative safety, the IE deployment story is no simpler. This is true particularly for sites running Windows 2000, which wont be updated with the security fixes in Windows XP SP2.
Its also true that many Web-based enterprise applications have a preference for IE, but with your companys security on the line, its time to send a message to these application vendors by going with cross-platform-friendly options.Senior Analyst Jason Brooks can be reached at firstname.lastname@example.org.