The Register® — Biting the hand that feeds IT

Feeds

Rancid IE6 'more secure' than Chrome and Opera US bank says

Suck it up, or swallow: customer choice

Agentless Backup is Not a Myth

Microsoft's creaking Internet Explorer 6 is more secure and popular than either Google's Chrome or Opera US banking giant Chase has determined.

The bank's therefore decided its online baking services will continue to support aging the IE 6 but drop support for Chrome and Opera.

IE 6 is nine years old and even Microsoft is now desperately speaking out against the browser, to get individuals and businesses to move on to IE 8.

Micosoft's Australian business unit recently equated using IE 6 to being as risky as drinking - or maybe, eating - a carton of nine-year-old milk as it lacked up-to-date cross-site scripting and anti-malware protection among other defenses.

Chase has said it will support later versions of Microsoft's browser, such as IE 8, that does offer greater protection. Also making the cut are Mozilla's Firefox 2.0 and higher and version 3.0 and higher of Apple's Safari on the Mac - but not the PC.

The bank has "strongly recommended" people using Chrome or Opera upgrade to a version of IE, Firefox or Safari it supports.

The bank's site cited security and popularity as behind its reason to dump Chrome - which has been growing fastest of all browser - and Opera.

Chase said in a story pick up here: "There are dozens of browsers in use today, but not all offer the minimum levels of security that we require while others may not perform well with our site. The security of your accounts and private information is one of our highest priorities and some browsers, especially older versions, are simply higher security risks to use with our site."

If a new browser grows in popularity, Chase will assess and test its security and performance to determine whether the bank should support its use.

Claiming one browser is more secure than another is a difficult task, as all are targets. IE is probably the most widely attacked, followed by Firefox. Interestingly, IE, Firefox and Safari were all felled during the annual Pwn2Own competition at CanSecWest, and only Chrome was left unhacked. Google's browser has a very sophisticated sandbox design that makes it extremely hard to attack.

One possible factor behind the decision by Chase, the retail banking arm of JP Morgan Chase, is that it's in the middle of digesting the IT operations of Washington Mutual - the failed bank acquired in 2008 when the economy was heading south. Chase could be looking for ways to curb its IT costs by focusing on just a handful of browsers on the app-development front.

JP Morgan Chase has already seen its customer satisfaction rating drop since the Washington Mutual deal and this won't help. The decision blocks users accessing their accounts at their convenience on PCs using the Opera Desktop browser and mobile devices including the iPhone - now a quarter of US smartphones - using Opera Mini, in addition to blocking the fast growing segment of Chrome adopters.

Opera called the situation "disappointing", while Google has not commented. ®

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Say what?

"Chase could be looking for ways to curb its IT costs by focusing on just a handful of browsers on the app-development front."

Err, surely if you simply code your site to be standards compliant then you don't need to worry about supporting multiple browsers.

Isn't that the whole (original) point of TBL's World Wide Web?

26
3

"while others may not perform well with our site"

Translation: our cutting-edge web designers hard-baked so much IE6-specific crud into our site that we have no clue how to pull it out.

Nor can we be bothered to fix this as we badly need cash to pay bonuses to our execs.

12
1

Utterly insane

I can understand why a bank might assign different browsers different tiers of support, e.g a site must work perfectly in IE7 and Firefox and acceptably in Chrome, Safari. So QA tests in the main browsers and does cursory validation in others. But dropping support altogether is sheer bloody laziness and nothing else.

It's incredibly shortsighted in this day and age to even support browsers by name rather than a particular set of capabilities that many browsers may implement. For example, if the site can take advantage of canvas, test for the canvas, don't test if user agent == Firefox. Coding to the capabilities rather than the browser version is a much better strategy for development and for maintenance when inevitably the site needs to be updated for new browsers.

11
1

More from The Register

Bjarne Again: Hallelujah for C++
Plus: Now officially OK to admit you never used STL algorithms
Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Apple: iOS7 dayglo Barbie makeover is UNFINISHED - report
Plus: You don't like the icons? Blame marketing
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Shy? Socially inadequate? Fiddling with your phone could help
App 'tells the brutal truth' about social inadequates' chatup lines
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry