So this happened over the weekend and I'm still kind of annoyed about it: Homeland Security put out an advisory telling people to stop using Internet Explorer until Microsoft patches it. Not "consider alternatives." Not a soft suggestion buried in a mailing list. An actual US-CERT bulletin, basically saying the browser that probably still opens by default on half the PCs in this country is not safe to use right now.
The bug is CVE-2014-1776, found by FireEye, and it hits everything from IE6 up through IE11. That's not a niche version range. That's the whole install base, more or less, minus whatever sliver of people have switched to Chrome or Firefox already. It's a use-after-free vulnerability that lets an attacker run code on your machine just by getting you to visit a booby-trapped page, no download or click-through required beyond loading the site. A working Metasploit module showed up within a day or two of the disclosure, which is the part that actually worries me, because that's when it stops being "researchers found a theoretical thing" and starts being "randoms on forums can point and click their way into your laptop."
Microsoft hasn't shipped a fix yet. As of right now they're just saying they're aware of it and investigating, which is the corporate version of "we see you, please hold." And here's the part that's been bugging me all weekend: Windows XP stopped getting security updates three weeks ago, on April 8th. So if you're one of the however-many-million people still running XP (and I promise you, there are still a lot, my aunt's desktop among them), there is currently no plan on the table to patch this on your machine. Ever. That's not me being dramatic, that's just where things stand today.
I work someplace where our internal timesheet tool was built for IE8 and, as far as I can tell, has never once been tested in anything else. Buttons don't render right in Firefox. The date picker just doesn't open in Chrome. So for years the unofficial rule has been: keep IE around for the one internal app, use whatever else you want for actual browsing. Except now that "keep IE around" thing is the exact thing being flagged as dangerous, and I don't have a good answer for what I'm supposed to do on Monday. Probably just open it in a private window, do the timesheet thing as fast as possible, and close it immediately, which is not a plan, it's a coping mechanism.
It's a rough month for anyone whose job is "trust that the software mostly works." We're barely three weeks past Heartbleed, which had me resetting passwords on a dozen sites and reissuing an SSH key I'd been lazy about rotating for way too long. I'm not going to rehash the whole Heartbleed thing here since it feels like every tech site on the internet already wrote the same five paragraphs about it (and honestly a lot of those posts read like they were assembled from the same press release). But it's worth saying out loud that these two things landing so close together is not a great sign for anybody's spring. First the encryption layer that was supposed to protect traffic turns out to have a hole in it for two years, then the browser a huge chunk of the planet defaults to turns out to have one too. At some point you start to wonder what isn't broken.
The advice going around is just: use Chrome or Firefox for anything that matters until Microsoft actually ships something. Which, fine, I already mostly do that, but it's a genuinely inconvenient ask for the people who don't have the option, corporate machines locked down by IT policy, government office computers, whatever ancient banking portal your local credit union still insists only works in IE. Those people don't get to just "switch browsers this weekend." Somebody has to approve that.
I moved my mom over to Chrome on her desktop Saturday afternoon while I was there for dinner, mostly as a preemptive thing since she clicks on literally everything that lands in her inbox. She has not stopped complaining that her bookmarks toolbar looks different. I told her that's the price of not getting your computer taken over by whoever wrote that Metasploit module, and she said she'd rather take her chances. We are still negotiating.