Hacker News new | ask | show | jobs
by jiggy2011 4842 days ago
Or people often have their decisions made for them by slightly more tech savvy friends. "Oh, you're using IE? Don't you know that it gives you viruses? Here let me fix that for you.."
1 comments

I try not to tell less tech-savvy people any more that IE opens their computer to viruses, because afaik it's not really true any more. Back in the day many exploits targeted IE/ActiveX specifically, but nowadays it's Flash and Java that make holes in any browser. (Somebody correct me if I'm wrong and IE is still significantly more vulnerable)

But you can't convince people to drop Java if they as much have one site/app depending on it. I'd love to install an alternative non-Oracle Java (not because they're significantly more secure, but to diversify the ecosystem a bit, and to stick it to Oracle for bundling that Ask toolbar), but I haven't figured out how to install them in Win7 yet. (that's not for other people btw, but for the computers at the kids centre I teach)

Still, what I wanted to say, the reason I do give them Chrome (or Firefox, or Opera), is because I'm absolutely unfamiliar with IE, no idea how to enable the proper security settings (or if there are any) and I do want to help many people with an AdBlocker (which also can do wonders for one's Internet security, btw).

Chrome is far safer than IE: 1. built in flash (sandboxed and up-to-date) 2. built in PDF reader 3. security updates are not delayed 4. the filtering is very good 5. friends & family on XP or Vista get the latest version

There are other good reasons why the security is better, with the only downside being the invasion of privacy, where Google are no worse than others, so pick your poison.

Any doubts about Google's intentions are easily negated by using Chromium.
Which is unstable and does not auto update without writing a script. Google wants you to use Chrome and not Chromium.
Go to settings, advanced, privacy, untick all boxes, don't sign in to a Google account. Or Facebook, for that matter. Heck, there's even a version of Gostery for Chrome iirc.
I'd rather support Firefox, to be honest. I still like a lot of what Google does, fwiw.
How about Comodo Dragon[1], a free and stable Chromium based browser, with 'auto updates' ;)

[1] http://bit.ly/cjbh1z

Not open source, IIRC.
The real issue with IE is people running old versions of it. So, Chrome's auto update is significantly safer than IE if your going to install once and possibly never touch the computer again.
Except that this doesn't really happen anymore unless the person's running an old version of Windows. IE updates with Windows Update, so it's just as "automatic" as Windows Updates.
Which is still slower: making the assumption that automatic updates are actually enabled (which is often not the case), Microsoft's update cycle is slower (monthly) whereas Chrome & Firefox have both deployed patches within a day of learning about a new zero-day. Microsoft also does not update Flash (prior to Windows 8) or blacklist known-insecure plugins as quickly – better than in the past, to be sure, but still concerning as the reaction loop speeds up.
And the important part is that Microsoft rapidly depreciates updates on old versions of Windows all the time. The adoption of Windows 7 in the poweruser space is probably significantly higher than the adoption in the grandparents category of people still running 2003 - 2004 Dells with XP. Most of them, if unassisted by more tech savvy relatives, would still be running IE 6 - 8, and 9+ won't be backported. Throw Firefox or Chrome on those old PCs and they will stay auto-updated forever.
But couldn't IE be updated via Windows Update? The problem is the people who depends on older version for intranets and the such.
IE's updates are always limited to what version of windows your running. In theory windows update should be good enough, but I know plenty of people who can't upgrade to the latest version of IE and see no need to upgrade there computer.