Flaws in Microsoft Internet Explorer found
By Our Convergence Bureau | 13 Aug 2002
San Francisco: Security researchers claim that they have found serious flaws in Microsoft’s Internet Explorer (IE) browser and in PGP, a widely-used data scrambling programme, that could expose credit card and other sensitive information of Internet users.
The IE problem has been around for at least five years and could allow an attacker to intercept personal data when a user is making a purchase or providing information for e-commerce purposes, says Mike Benham, an independent security researcher based in San Francisco.
“If you ever typed in credit card information to a Secure Sockets Layer (SSL) site, there’s a chance that somebody has intercepted it,” he adds. “IE fails to check the validity of digital certificates used to prove the identity of websites, allowing for an undetected, man-in-the-middle attack.”
Digital certificates are typically issued by trusted certificate authorities, such as VeriSign, and used by websites in conjunction with the SSL protocol for encryption and authentication. Anyone with a valid digital certificate for any website can generate a valid certificate for any other website, says Benham. “I would consider this to be incredibly severe.”
Cryptography expert Bruce Schneier, co-founder and chief technology officer at Counterpane Internet Security, a California-based network monitoring firm, agrees: “This is one of the worst cryptographic vulnerabilities I’ve seen in a long time. What this means is that all the cryptographic protections of SSL don’t work if you’re a Microsoft IE user.”
Latest articles
Featured articles
The decoupling paradox: Why Wall Street keeps funding AI despite $100 oil
By Axel Miller | 11 May 2026
AI infrastructure stocks continue rallying despite $100 oil as investors bet on productivity gains and semiconductor demand in 2026.
Hybrid bonding gains attention as AI chip packaging demand grows
By Cygnus | 23 Apr 2026
Hybrid bonding is driving AI chip packaging demand as backend technologies gain importance in the semiconductor supply chain.
The agentic transition: how enterprises are scaling AI from pilot to profit
By Cygnus | 22 Apr 2026
AI has entered its execution era. Discover how companies like Valeo and Microsoft are scaling agentic AI systems—from copilots to autonomous workflows driving real business impact.
Post-splashdown: What Artemis II taught us about the ‘deep space wall’
By Axel Miller | 15 Apr 2026
Artemis II splashdown marks a breakthrough in deep space exploration. Discover AVATAR radiation data, Orion’s distance record, and insights shaping NASA’s 2028 Moon mission.
Can aviation go green? The multi-billion dollar race for sustainable fuel
By Cygnus | 10 Apr 2026
Airlines are racing to adopt sustainable aviation fuel, but limited supply and high costs challenge the future of green aviation.
The battery race: who will control the future of electric vehicles?
By Axel Miller | 08 Apr 2026
The global battery race is reshaping the electric vehicle industry, with China, the US, and Europe competing for control over supply chains and technology.
AI vs governments: Who controls the future of intelligence?
By Cygnus | 07 Apr 2026
Governments and AI companies like OpenAI and Anthropic are shaping the future of intelligence amid rising policy conflicts and global competition.
Strait of Hormuz: how one chokepoint controls the global economy
By Axel Miller | 06 Apr 2026
The Strait of Hormuz is a critical global chokepoint. Learn how disruptions impact oil prices, shipping, and the global economy.
The $2 trillion AI infrastructure race: Who will control global compute?
By Cygnus | 06 Apr 2026
AI spending is set to exceed $2 trillion in 2026, driving a global race in data centers, chips, and energy infrastructure.


