Flaws in Microsoft Internet Explorer found
By Our Convergence Bureau | 13 Aug 2002
San Francisco: Security researchers claim that they have found serious flaws in Microsoft’s Internet Explorer (IE) browser and in PGP, a widely-used data scrambling programme, that could expose credit card and other sensitive information of Internet users.
The IE problem has been around for at least five years and could allow an attacker to intercept personal data when a user is making a purchase or providing information for e-commerce purposes, says Mike Benham, an independent security researcher based in San Francisco.
“If you ever typed in credit card information to a Secure Sockets Layer (SSL) site, there’s a chance that somebody has intercepted it,” he adds. “IE fails to check the validity of digital certificates used to prove the identity of websites, allowing for an undetected, man-in-the-middle attack.”
Digital certificates are typically issued by trusted certificate authorities, such as VeriSign, and used by websites in conjunction with the SSL protocol for encryption and authentication. Anyone with a valid digital certificate for any website can generate a valid certificate for any other website, says Benham. “I would consider this to be incredibly severe.”
Cryptography expert Bruce Schneier, co-founder and chief technology officer at Counterpane Internet Security, a California-based network monitoring firm, agrees: “This is one of the worst cryptographic vulnerabilities I’ve seen in a long time. What this means is that all the cryptographic protections of SSL don’t work if you’re a Microsoft IE user.”
Latest articles
Featured articles
The analog antidote: perception, reality, and the "Windows crisis" narrative
By Cygnus | 17 Feb 2026
Viral claims of a Windows collapse contrast with market data showing a slower shift as enterprises weigh AI, hardware costs, and legacy systems.
The analog antidote: why Americans are trading algorithms for physical media
By Cygnus | 16 Feb 2026
Vinyl, books, and DVDs are seeing renewed interest as Americans seek ownership, focus, and a break from screen fatigue in an increasingly digital world.
China opens market to 53 African nations in zero-tariff pivot
By Cygnus | 16 Feb 2026
China will grant zero-tariff access to 53 African nations from May 2026, reshaping global trade ties and deepening economic links across the Global South.
The deregulation “holy grail”: Trump EPA dismantles the legal bedrock of climate policy
By Cygnus | 13 Feb 2026
The Trump EPA moves to rescind the 2009 Endangerment Finding, reshaping federal climate authority and business risk.
Tokenising the gilt: what the UK’s digital bond pilot could mean for sovereign debt
By Cygnus | 12 Feb 2026
HM Treasury selects HSBC Orion and Ashurst LLP for its Digital Gilt Instrument (DIGIT) pilot. A deep dive into the architecture, legal framework, and the shift toward near real-time settlement.
The silicon-rich AI race: how Cisco’s G300 puts networking at the center of compute
By Cygnus | 11 Feb 2026
Cisco's new Silicon One G300 targets AI data center bottlenecks as networking becomes central to compute performance.
Server CPU Shortages Grip China as AI Boom Strains Intel and AMD Supply Chains
By Cygnus | 06 Feb 2026
Intel and AMD server CPU shortages are hitting China as AI data center demand surges, pushing lead times to six months and driving prices higher.
Budget 2026-27 Seeks Fiscal Balance Amid Rupee Volatility and Industrial Stagnation
By Cygnus | 02 Feb 2026
India's Budget 2026-27 targets fiscal discipline with record capex as markets tumble, the rupee weakens and manufacturing struggles to regain momentum.
The Thirsty Cloud: Why 2026 Is the Year AI Bottlenecks Shift From Chips to Water
By Axel Miller | 28 Jan 2026
As AI server density surges in 2026, data centers face a new bottleneck deeper than chips — the massive water demand required for cooling next-generation infrastructure.

