Slashdot Mirror


Criminals Prefer Firefox, Opera Web Browsers

An anonymous reader writes "Security researchers at Purewire have leveraged vulnerabilities in malware infrastructure to track the criminals behind it. In a three-month long project, they used security flaws in exploit kits to get operators to expose themselves (Obnoxious interstitial ad between link and content) when they access the kits' admin control panels. Data collected shows that 50% of those tracked use Firefox, while 25% use Opera."

13 of 172 comments (clear)

  1. So the story is.. by Anonymous Coward · · Score: 5, Insightful

    crim.. *cough* technically inclined people tend to use firefox and opera rather than IE.
    Shocking!

    1. Re:So the story is.. by gmuslera · · Score: 4, Insightful

      A better reading could be "people that exploit vulnerabilities of browsers prefer to not use those vulnerable browsers". Not sure how much technically inclined they are (not sure if there are a black market of plug-and-exploit-for-dummies kits), but they are aware of how much damage can be done to whoever (including them) using those vulnerable browsers.

    2. Re:So the story is.. by linear+a · · Score: 5, Insightful

      Close. Hackers know better than to use IE for all the obvious reasons nobody else should use it.

  2. Does that make me a criminal? by MartinSchou · · Score: 4, Insightful

    I prefer Opera myself - does that now incriminate me? Or does it merely show that these criminals are security conscientious and knows that using IE on the type of websites they probably frequent would be like throwing stones at bees nests?

    They did neglect to mention the most frequently used operating system. If it's equally divided between Linux, OS X and Windows it'd be hard for Internet Explorer to get beyond 33% to begin with.

    1. Re:Does that make me a criminal? by Jurily · · Score: 4, Insightful

      The classic difference between correlation and causation.

      Also, people who think about security much use secure browsers! Think of the children!

  3. Gotta love statistics by Idimmu+Xul · · Score: 5, Insightful

    What does this article even mean?

    Tech savvy IT security enthusiasts prefer alternative browsers to Internet Explorer?
    Criminals prefer Firefox?
    Firefox users have criminal tendancies?
    Firefox encourages exploitation of inferior browsers?

    Or, Internet Explorer sucks.

    What.

    --
    The problem with slashdot is that most of its users were bullied and stuffed into lockers as kids!
    1. Re:Gotta love statistics by Xenographic · · Score: 4, Insightful

      > What does this article even mean?

      People who write exploits know how to prevent themselves from getting exploited? (i.e. Don't use IE.)

      Of course, it's not as simple as merely choosing a good browser, but that's a starting place.

    2. Re:Gotta love statistics by swillden · · Score: 4, Insightful

      What does this article even mean?

      Easy: This article means that this set of computer criminals primarily uses Firefox and Opera.

      The problem with statistics isn't with statistics, it's with people drawing conclusions unsupported by the statistics.

      --
      Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
  4. Re:What do you mean? by MichaelSmith · · Score: 4, Insightful

    Is it the mouse-clicking or the keyboard-typing that requires more technical capability while using Firefox or Opera rather than IE?

    Knowing about them.

  5. Dubious logic? by Johnny+Loves+Linux · · Score: 5, Insightful

    Interestingly, Opera, which by some measures has only a 2 per cent market share, ranked second among the kit operators, with 26 per cent. "I think that's probably because operators have a familiarity with the web threat landscape," Royal told The Register, suggesting that many black-hat hackers take a security-through-obscurity approach to making sure they themselves don't get hit. "It makes them wary of using mainstream browsers."

    Huh, and here I was thinking that maybe, just maybe, these hackers knew the security history of the various browsers and knew that Opera had a better security history than Internet Explorer?

  6. Maybe so by mysidia · · Score: 5, Insightful

    I'm reminded of an old observation: whenever ice cream sales rise, so do shark attacks. So does eating ice cream cause sharks to attack you? No.

    The observation that more Criminals prefer Firefox over IE, doesn't associate Firefox use with criminal behavior.

    It most likely just means that there is a common occurence that causes technically savvy computer users to prefer Firefox.

    People who build malware infrastructure are technically savvy, otherwise, they would not be able to understand and defeat technical security measures.

    Non-technically savvy users often use IE because they don't understand the alternatives.

    Also, they don't understand the weaknesses in IE's security defenses, the technical advantages of using Firefox (or Chrome) over IE, or the basic security principle that installing and using less-popular software (alternatives to the most popular option) means there are fewer people interested in devising a way to attack your software.

    Eg Opera is not a very ripe target that hackers are highly interested in attacking, because it has so few users, it's a low value target.

  7. Re:What do you mean? by Itninja · · Score: 4, Insightful

    FF or O don't require more technical skill, but people with more technical knowledge with usually opt to use them. For example, only a technically savvy person knows the dangers of allowing scripts to run without direct user permission. With FF one can get NoScript running in less than a minute. With IE, you might be able to cobble together some goofy proxy, but for the most part you are on your own.

    No one knows better than a scumbag malware distributor how to protect themselves online.

    --
    I judt got a nre Kinesis keybiartf so please excusr ant egregiou typos.
  8. Think about it a moment. by Ungrounded+Lightning · · Score: 5, Insightful

    A better reading could be "people that exploit vulnerabilities of browsers prefer to not use those vulnerable browsers".

    In particular:

    "People who create websites containing malware that takes over the browsing computer NEED to use a browser that is immune to their own takeover tools for their command-and-control console."

    Jeez. Think about it a moment. How the heck are they going to work on the thing if it eats their machine when they touch it?

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way