Slashdot Mirror


IE More Secure Than Mozilla?

killproc writes "Symantec has issued a report that suggests that Internet Explorer may be more secure than the open source Mozilla Foundation browsers. "According to the report, 25 vendor-confirmed vulnerabilities were disclosed for the Mozilla browsers during the first half of 2005, "the most of any browser studied," the report's authors stated. Eighteen of these flaws were classified as high severity. "During the same period, 13 vendor-confirmed vulnerabilities were disclosed for IE, eight of which were high severity," the report noted." "

106 of 534 comments (clear)

  1. Questions by daveschroeder · · Score: 5, Insightful

    How many of these vulnerabilities were discovered or aided because of the very fact that the Mozilla family of products are open source, open to the intense peer scrutiny of the community, one of the core, fundamental facets of the Mozilla products, and open source projects in general, that will help quickly make them more secure? Do they even grasp this concept?

    How quickly and effectively were the Mozilla/Firefox vulnerabilities patched in comparison to IE?

    Is there any consideration given to the fact that Internet Explorer is a decade old and integral to the OS, and STILL routinely has extremely critical vulnerabilities, and may have an untold number of yet-to-be-discovered critical vulnerabilities?

    Assuming customer choice is important, a customer can elect to not use Firefox and remove it from their system. Can the customer remove IE? Can the customer even elect to not use IE, or does the OS still force them to use IE for some tasks?

    I could go on, but I think it goes without saying that at best this "report" uses extremely flawed logic to draw its conclusions, and at worst, Symantec is shilling for Microsoft.

    Or both.

    1. Re:Questions by servo335 · · Score: 2, Insightful

      How many virus writers have designed their virus just to attack symantec? Gues they are just as insecure. Seems like they are verry biased in their reports.

    2. Re:Questions by ShieldW0lf · · Score: 4, Funny

      Microsoft found a great way to make their browser more secure than the competition. They pay their staff to contribute code to Mozilla!

      --
      -1 Uncomfortable Truth
    3. Re:Questions by TurdTapper · · Score: 5, Insightful

      I don't want to completely argue with you, I believe that most of your points are valid. But I don't agree with this one:

      Is there any consideration given to the fact that Internet Explorer is a decade old and integral to the OS, and STILL routinely has extremely critical vulnerabilities, and may have an untold number of yet-to-be-discovered critical vulnerabilities?

      10 years from now, the latest Mozilla version will probably have critical vulnerabilities. Each new version will have different technologies to deal with as well as have new developers/programmers involved. If one thing is constant in programming any app, as time goes on and new versions come out, there are always new bugs and problems. Mozilla won't be immune to those.

      --
      A man with a gun is called a citizen. A man without a gun is called a subject.
    4. Re:Questions by shades66 · · Score: 2, Informative

      >Can the customer even elect to not use IE, or does the OS still force them to use IE for some tasks?

      I have IE disabled (well as much as you can using the built in functions for disabling certain microsoft programs like outlook,IE,messenger). I wanted to print out a visio2003 page but did not have visio on my machine! So I install the Microsoft Visio Viewer and double click on the file. Does it open in its own window? NO. Does it open in firefox? NO. Does it run it in IE? YES ! So YES you still are forced by some microsoft OS extensions to use IE.

      For an extra laugh do a print preview of the document. As far as I can tell the print preview suggests that once printed I can move the image around using the scrollbars or using the scroll wheel.... Only problem to solve now is how to plug my mouse into the paper!

      --
      ---- There are 10 types of people in the world. Those that understand binary and those that don't
    5. Re:Questions by SpectreBinary · · Score: 5, Interesting

      Saw a great comparison on firefox and mozilla a few months ago. Looking at the age of critical vulnerabilities and the time it took to patch them, IE was safe to use for a total of seven days in 2004. All other days had an unpatched known critical vulnerability. Firefox fared better by far, being only vulnerable for small patches at a time.

      If I weren't so lazy I'd find the comparison. I'll leave that as an exercise for the reader and google.

    6. Re:Questions by lgw · · Score: 4, Insightful

      I think it goes without saying that at best this "report" uses extremely flawed logic to draw its conclusions, and at worst, Symantec is shilling for Microsoft.

      FTFA, it looks like the *conclusion* that IE is more secure is News.com's, and Symantec is just presenting the numbers. Symantec is quoted as saying "at the time of writing, no widespread exploitation of any browser except Microsoft Internet Explorer has occurred" which doesn't sound like they're drawing the conclusion that IE is more secure.

      Does anyone have a link to the actual report? My first instinct is that TFA is just trolling, but I could be wrong.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    7. Re:Questions by morgan_greywolf · · Score: 4, Informative

      I have Cingular. I have Firefox. I have never experienced any difficulties in paying my Cingular bill on their website.

    8. Re:Questions by slaker · · Score: 4, Informative

      IE can be downloaded, if you know how. One way to get all the client install files is to download and use the IE Administrators Kit.

      But yeah, I can't pay my power bill unless I use IE, so I know you pain and think it's stupid, too.

      --
      -- I wanna decide who lives and who dies - Crow T. Robot, MST3K
    9. Re:Questions by LazyBoyWrangler · · Score: 2, Insightful

      The key word is DISCLOSED in this discussion. The report isn't worth the electrons used unless we are comparing vulnerabilites apples to apples. Vulnerabilities that are undisclosed and publicly ignored by vendors can skew statistics dramatically.

      Given the open and extremely public nature of open source projects, I would expect that there are less undisclosed vulnerabilities, therefore chances are the stats quoted are worth less than advertised.

    10. Re:Questions by urmensch · · Score: 4, Insightful

      It may be true that Mozilla browsers will continue to have new technologies that create new bugs. However, IE 6 has been stagnant for years now and the only changes have been security patches. Yet it still has many critical vulnerabilities *and* these are tied to the OS as well.

    11. Re:Questions by Directrix1 · · Score: 5, Informative

      Just to show that CNet News is not unbiased against open source. Bugs Found In Open Source AntiVirus Tool talks about a bug that was only in versions from June 23 and BEFORE. And yet it makes the headlines today. And with an advertisement for Trend Micro. How peculiar.

      --
      Occam's razor is the blind faith in the natural selection of least resistance and in universal oversimplification. -- EF
    12. Re:Questions by Zeveck · · Score: 5, Informative

      Not true. Firefox does indeed make patches available. Look at Gentoo Linux - it is currently at Firefox v1.0.6_r7. That is seven revisions (i.e. patches) since v1.0.6. It was a decision of Mozilla to only bundle prebuilt-binaries as timely groupings of these patches. This was done, as far as I know, because it seemd the most intuitive way of doing so.

    13. Re:Questions by Citizen+of+Earth · · Score: 2

      I could go on, but I think it goes without saying that at best this "report" uses extremely flawed logic to draw its conclusions, and at worst, Symantec is shilling for Microsoft.

      Hmmm, an anti-virus vendor would prefer people to be using IE. Kinda sounds like Symantec is shilling for themselves.

    14. Re:Questions by op12 · · Score: 3, Insightful

      My first instinct is that TFA is just trolling, but I could be wrong.

      Not only is TFA trolling, so is Slashdot. We're just rehashing all the debate from 4 days ago.

      (or 10 days ago, and so on...)

    15. Re:Questions by vwgtiturbo · · Score: 2, Informative

      Cingular doesn't support Firefox?? That's funny, because I have been doing all of my online bills and such with Cingular for about two years now. Hmm... Maybe you have another issue. The only site that I use that I can't access with Firefox is Clark Pest Control. They require Windows, and Internet Explorer. With Clark, I get screwed, as I end up having to use my wife's machine, as their site doesn't really care for Slackware...

      And, you can remove Internet Explorer, using a nifty little tool called nLite.

    16. Re:Questions by pjrc · · Score: 4, Interesting
      and Symantec is just presenting the numbers.

      As I explained in another post, I believe their numbers are wrong.

      The simple reason is because many bugs where viewing a malicious web page could allow remote code execution (or something similarly nasty) are reported as "windows" bugs rather than "internet explorer" bugs.

      If you actually read throught the microsoft bulletins, and consider anything where simply using IE allows an attack (which requires reading the vulunerability info rather than Microsoft's searchable fields of impacted software), you'll find a lot more bugs than Symantec is claiming.

      But you don't need to do all that work... I did it, admittedly rather quickly, a few days ago. Just follow that link, and the one in that post, to my quick summary of "simply using IE" bugs.

      While googling around, I also found several others mentioned on various security sites, which didn't seem to correspond to any of the bulletins. And complaints of known bugs still not fixed. And some microsoft "notices" which basically claim "that's not a bug, you just need to avoid doing XYZ".

      My quick list alone almost puts IE to the raw number of bugs as firefox, and I'm sure if someone did all the digging needed to compile a list that also included other non-microsoft-bulletin sources, we'd see what is plainly known... that IE has a lot more bugs.

      It's sad that Symantec couldn't do this. Looks like they simply using Microsoft's database, which ignores lots of bugs Microsoft doesn't "officially" consider IE bugs (even though simply viewing a page with IE is the attack vector), and all the bugs Microsoft is ignoring or denying, or has quietly fixed.

    17. Re:Questions by utnow · · Score: 2, Interesting

      so what you're saying... is that all programs should be closed source, because then the majority of vulnerabilities would remain hidden while they are discovered and patched! It's perfect! MS has the right idea! (half kidding, half mocking the parent)

    18. Re:Questions by man_of_mr_e · · Score: 4, Informative

      I'm curious, but can you explain exactly what makes 'integral to the OS' inherantly insecure? Do you even know what that phrase means in regards to IE? Do you know HOW it's "integral"?

      It's not running in the kernel. It doesn't run with privileges that are above the current users. In fact, there's nothing about IE's "integration" that Mozilla isn't just as vulnerable to (in effect, anything IE can do, so can Mozilla, because IE just uses userland API's the same as Mozilla does).

    19. Re:Questions by man_of_mr_e · · Score: 2, Interesting

      I hate to say it, but apparently you believe everything you read.

      The statistic you're talking about is misleading because it only takes into account the length of time from the vulnerability being publicly disclosed and the time of the patch. Typically bug details are embargoed for weeks to months before a patch is made public and the vulnerability is publicly reported.

      Don't believe me? Go ahead and look at the bugzilla database for when the vulnerabilities were created, not when the security alert was issued.

    20. Re:Questions by malfunct · · Score: 3, Interesting

      The big reason that being integral to the OS is bad is that firstly everyone knows it will be on the box which means its a good target for attack, secondly the core dll's are exposed in many applications so securing the surface of IE isn't enough to close all possible vulnerabilities (the security has to be at every single layer that any application is allowed to call into). Mozilla could get away with only securing the top levels and benefits from the fact that it is only on like what 30% of windows boxes?

      --

      "You can now flame me, I am full of love,"

    21. Re:Questions by tchernobog · · Score: 5, Insightful

      It's Symantec, boys!

      You know what, they have large revenues from a MS Windows-related market, and they produce Norton Antivirus, Norton Utilities, and all the damn product line.

      If they start saying that a free (as in beer) OpenSource browser (maybe one that works even on GNU/Linux, sheesh!) is able to actually lower the number of virus/malware you get, people may start considering the switch.

      If people get less virii/malware, this means less revenues for them. And what if people discover things like ClamAV, which also works on GNU/Linux? What next?

      I ain't saying that Symantec is creating new virii by itself (that's an urban legend like alligators in sewers), but I ain't saying they want to lose customers too.

      I'll just wait a less biased source than Symantec, or "Microsoft Watch". It's like Microsoft saying that the TCO of Windows is less than the one of GNU/linux (or vice-versa, for what matters).

      PS: this doesn't mean that Firefox is "the most secure" thing around. It isn't. But it is free software and works really well for me. I won't switch to Opera now because of this stupid report, nor because Opera has gone free as in beer. A lot of /.-ters make a tragedy out of a rumor (speaking in general). We're a bunch of chattering mothers-in-law... :-)

      Anyway, the damage a Firefox bug can do is limited to user space; a hole in IE, which is tightly tied with Windows kernel... brrr.

      --
      42.
    22. Re:Questions by Pieroxy · · Score: 2, Funny

      Never had any issues beyond the login guy

      There is a guy doing the login? Which century do we live in already ??? ;-)

    23. Re:Questions by erroneus · · Score: 2, Interesting

      You are making a completely invalid assumption. The assumption you make is that all software will always have bugs. This is provably untrue. When software is designed against such failure, then it is likely that they will accomplish that end. An example of this is QMail. (check here for the only ones I could find)

      This isn't meant to bash any project in particular, but the fact remains that a program is a series of instructions and the computer folows them. It is possible to write a series of instructions that does not present vulnerabilities to attackers. If a utility or library has problems, the utility or library should either be fixed or avoided. It's POSSIBLE. It always has been and always will be. To suggest that there are impossibilities such as this would be the same as saying it's impossible to quit smoking or doing drugs -- it may be difficult or even painful to do, but it remains in the realm of possible. It them becomes a question of whether or not a programmer chooses a more difficult challenge.

    24. Re:Questions by man_of_mr_e · · Score: 2, Interesting

      What you're describing is security through obscurity. Mozilla has core libraries as well, and they are exposed to any application that wants to take advantage of them.

      Of course you can get around this problem by statically linking all the code together, but then you create far more maintenance work.

    25. Re:Questions by man_of_mr_e · · Score: 2, Insightful

      You didn't really answer the question. I'll take that as a "No, I don't know what that really means. No, I don't know how it really effects security, i'm just assuming things".

    26. Re:Questions by John+Whitley · · Score: 4, Interesting

      Given the topic, I'm amused that your sig is simultaneously on topic and out of date:

      Keep firefox secure, vote for bug #262536

      Bug 262536 "Bigger notice for updates and critical updates" has been marked resolved by Ben Goodger: "This is fixed by the new update system UI."

      8-)

    27. Re:Questions by Proc6 · · Score: 3, Insightful
      You're right. It sounds retarded.

      Anything that can deceive the user like spoofing a title bar should be taken as a security risk. I'm sorry you don't, I just hope you're not someone working on the Firefox code.

      --

      I'm Rick James with mod points biatch!

    28. Re:Questions by toddestan · · Score: 2, Insightful

      I Really think Mozilla should start defining "vulnerabilities" as "visiting a website can cause evil code execution on your computer".

      Other stuff, like "spoofing a titlebar" or "click here, then here, then here, then pray while performing a rain dance, then click here and your infected!" should be classified as something like "user experience glitches" or something.


      On the other hand, rebuilding my Windows installation is a lot less hassle than rebuilding my credit rating.

      If anything, it's the issues where the worst they can do is crash the browser are the ones that should be downgraded.

    29. Re:Questions by Trepalium · · Score: 2, Insightful
      Better to ask -- how many vulnerabilities were discovered or aided because of the very fact that Mozilla family of products are open source but have not been reported.
      And how many bugs were found and fixed by Microsoft silently, rolled into the next hotfix or service pack, and never reported? I seriously doubt Microsoft would issue an advisory for an internally found bug unless it was also discovered by an outside entity because it gets them more bad press. Mozilla engineers never really have this option.
      Open source cuts both ways.
      In more ways than you know.
      --
      I used up all my sick days, so I'm calling in dead.
    30. Re:Questions by generalpf · · Score: 2, Informative

      Holy FUD, Batman. IE is not tied to the Windows kernel and I defy you to show me how it is. It's tied to the shell, which incidentally is not the kernel.

    31. Re:Questions by dubl-u · · Score: 2, Funny

      As far as I can tell the print preview suggests that once printed I can move the image around using the scrollbars or using the scroll wheel.... Only problem to solve now is how to plug my mouse into the paper!

      You need a bluetooth mouse and bluetooth paper. It works fine for the regular mouse functions, but I couldn't get the scroll wheel to work.

    32. Re:Questions by malelder · · Score: 2, Informative

      Thats silly...sure if you delete iexplore.exe (note, no final "r" in "explore") it stops you from running IE. The problem /. readers have is System File Protection putting it right back into place.

      This is bad for those who want 100% control of their computers. But for the other 99 44/100's % of the people out there who just "want it to work", this is a good thing...then when they accidentally delete "important" files, they don't blow up their PC, and have to spend WAY too much money at CompUSA to have it fixed.

      For most, just installing an alternate browser is good enough though. With my Internet Explorer folder in XP being just under a meg in size, I don't feel the urge to remove it...and for those who say that MS MAKES you use it to get updates, thats wrong too...turning on Automatic Updates doesn't require you to use IE at all.

      I've tried quite a few different browsers...I've just not used any of the other ones enough to be as efficient as I am with IE. Maybe I'm just super lucky, but I've never had any problems using it...no viruses, no spyware, no issues at all. But then I'm different, because I keep my patches updated, and don't goto websites that try to connect my (non-existent) modem to Jamaica for free porn.

      All ranting aside, your reply didn't even come close to answering my actual question, but thanks for playing the /. game anyway! (;

      --


      Yuma, AZ...You will never find a more wretched hive of scum and villainy. We must be cautious.
    33. Re:Questions by phasmal · · Score: 2, Informative

      If anyone wants to have a look at the report, I think this is probably it:
      http://www.techweb.com/wire/security/159906119

  2. Yea but... by P0pinjay · · Score: 5, Insightful

    I have yet to get a spyware infection from using Firefox...

    1. Re:Yea but... by RingDev · · Score: 2, Insightful

      I disagree. I beleive FF users are, on average, smarter/more computer literate then IE users. I'm not saying all FF users are rocket scientists, but they atleast have some grasp of the social circle that is the net. That rules out a lot of stupid people that do not perform safe browsing.

      The fact is, that we can both come up with anecdotal evidence for both sides of this arguement, but large amounts of anecdotal evidence != data. As mentioned in another post, you really have to look at the number of people effected, the level of exposure, the possible damages, and the length of the exposure. And that's why I say they are both good products. FF had more exposures in the last 6 months, but fixed them faster, IE had less, but it took longer to get them fixed, the over all net balance is that each app had a similar level of insecurity over the time period.

      Will FF's open source development reduce problems? will it make it easier for hackers to penetrate as it's market share rises? will the net effect of those two forces balance out to be better or worse then IE's security performance? Only time will tell. In any case, each app drives the other to improve and innovate. With out either of these apps, both would be worse off.

      -Rick

      --
      "Most people in the U.S. wouldn't know they live in a tyrannical state if it walked up and grabbed their junk." - MyFirs
  3. dupe? by webagogue · · Score: 3, Informative

    Is this a dupe story? 'course not! (rolls eyes)

    --

    Knowledge is valuable. Ignorance is dangerous. Censorship is unacceptable. http://slashdot.org/comments.pl?sid=10
  4. Security is a process! by DeadSea · · Score: 5, Insightful

    Security is a process not a state.

    A browser that has 5 reported vulnerabilities is not more secure than a browser that has 30. All it takes in one vulnerability to make your browser insecure

    Once any vulnerability is discovered, relative security depends upon is how many users are exposed, and for how long.

    Given that vulnerabilities have been found in both, security comparisons should compare the steps taken to reduce the window of vulnerability.

    • How quickly a patch is issued
    • How quickly are users notified
    • How easy it is to apply the patch or upgrade
    • What percentage of users actually apply the patch

    A simple comparison of the number of vulnerabilities does not give much indication about how long the average user was exposed. Nor does it give an indication of how many hackers are taking advantage of the vulnerability to give you a useful security indicator: "How likely is that any given user was hacked via the product".

    Currency calculator that accepts free form input such as "23 canadian dollars --> rupees"

    1. Re:Security is a process! by TheRaven64 · · Score: 4, Interesting
      You are missing the most important thing:

      • What is being done proactively to ensure that the system remains secure?
      Once a new form of vulnerability is discovered, is the rest of the code audited to ensure that no other vulnerabilities of this nature exist? Is the vulnerability class documented, and are the coding guidelines for the project updated to ensure that people who read them (all committers, at a minimum) don't make the same mistake again?

      There is a reason why I trust the security of OpenBSD more than most other projects. Security is not just a process, it's an attitude.

      --
      I am TheRaven on Soylent News
  5. Vunerable? by rampant+mac · · Score: 5, Insightful

    How many of those Mozilla exploits compromise the entire OS?

    --
    I like big butts and I cannot lie.
    1. Re:Vunerable? by Anonymous Coward · · Score: 2, Interesting
      Approximately the same proportion of those that affect IE. IE has no "special" priviledges*; run it as a limited user and you'll do no more damage than if you run Mozilla. By the same token, if an attacker is able to run arbitrary code via Mozilla and you are running Mozilla as Admin, then you are fucked.

      * Anyone who simply parrots "IE is tied to the OS!" without showing how this statement applies to this situation gets stabbed in the eye :) The phrase does not mean what you think it means!

  6. How many? by sglider · · Score: 3, Insightful

    Two points to consider:

    1. How many 'high severity' bugs did IE have to fix to get to that point? Remember also that IE is integrated into Windows, so any vulnerability that affects Windows affects IE in one way or another (and vice versa).

    2. How many have been disclosed by Microsoft before being fixed? They are notorious for not disclosing these things until after it is fixed, and even then they don't always label it as a "IE" fix.

    --
    War isn't about who's right. It's about who's left.
    1. Re:How many? by minginqunt · · Score: 5, Interesting


      What drivel.

      There are several massive logical ballsups here, made by the linker and the linkee.

      1) Not all exploits are created equal. Look at the number of those Moz exploits rated by Secunia as 'Extremely Severe' or 'Critical' compared to those for IE.

      2) Mozilla Firefox is not bug free. No piece of software is bug free, and only a mentally retarded moron would believe otherwise. What is important is not that security flaws get found, but (a) how open the organisation is about the flaw [full disclosure] and (b) timeliness of fixes.

      3) Mozilla believes in full disclosure, Microsoft does not.

      4) The average time taken to patch a flaw in Firefox is two days. IE has unpatched vulnerabilities going back SIX YEARS.

      5) Critical components of Firefox run in an sandboxed unprivileged space. When Firefox flaws are discovered, the damage done is minimised. IE runs everything with administrator privileges. When IE is exploited (regularly), a full-on system-rape inevitably follows.

      6) ActiveX. The unsafe system by which 90% of spyware, adware, trojans, porn diallers etc. enter your system. Guess which browser has ActiveX turned on by default? Yes, IE. Firefox doesn't support ActiveX because it's just too bloody dangerous.

      The security arguments being made about IE vs Firefox in that argument are unreconstructed luddite ballacks.

      Although, honestly, we all know security is not the reason we geeks like Firefox. We like it because OMG 3XT3NSI0NZ!!!

      So squish.

      Martin

  7. Security flaws? by mokiejovis · · Score: 3, Informative

    Personally, I think it's stunning that a browser as old as IE6 STILL HAS CRITICAL vulnerabilities. They've had litterally YEARS to root out and discover these sorts of things. To compare that to a much newer Mozilla browser seems like apples and oranges to me.

    1. Re:Security flaws? by Red+Flayer · · Score: 4, Insightful

      I'm not apologizing for IE, but...

      (1) Even though IE is old, the nature of threats changes -- not all the security holes could have been predicted five years ago.

      (2) Just because Mozilla is newer doesn't mean that they don't have the responsibility to have fewer holes in security. On the contrary, the Mozilla developer community has had the opportunity to learn from all the security holes of IE, and to develop the code from the ground up in such a way that limits vulnerabilities.

      That said, response time to threats is better for Firefox. The total threat posed is probably less, because the time of exposure is a fraction of IE vulnerabilities.

      But Mozilla faces a tough road ahead -- if they maintain or gain market share, they have to be very cautious, as their vulnerabilities will begin to be targeted seriously by malware.

      Anyone who uses any browser online should still be running virus-detection software. This will never change, no matter what OS or browser you use.

      --
      "Trolls they were, but filled with the evil will of their master: a fell race..." -- J.R.R. Tolkien on Olog-hai
  8. a few days ago by bcrowell · · Score: 2, Informative

    We had a similar story a few days ago. It was not very informative, and for the same reasons this one's not very informative, e.g., IE is closed-source, so they don't disclose all the bugs.

  9. Mozilla hits back at browser security claim by anandpur · · Score: 5, Informative

    Mozilla has reacted to a Symantec report issued on Monday which said serious vulnerabilities were being found in Mozilla's browsers faster than in Microsoft's Internet Explorer. The study was conducted over the first six months of 2005.
    http://www.zdnet.co.uk/print/?TYPE=story&AT=392191 86-39020375t-10000025c

    1. Re:Mozilla hits back at browser security claim by tktk · · Score: 2, Insightful
      In the article, from a Symantec researcher:

      People who have swapped [from IE to Firefox], even if this is a blip, should ask whether the assumption that Firefox is more secure than IE is valid anymore. They shouldn't just rely on changing their browser, but may think about having to look at a different configuration."

      By different configuration, I think he means, "Buy our products! Or else."

  10. So spyware installation is a feature? by jurt1235 · · Score: 3, Insightful

    My neighbours using firefox on MS windows have had zero problems due to these security flaws. The neighbours using IE under XP with service pack 2 installed and automated update on still get tons of spyware.
    So the alternative conclusion of the symantec report would be: Spyware holes in MS IE are not spyware holes, but easy software installation features.

    --

    My wife's sketchblog Blob[p]: Gastrono-me
  11. Symantec is a scourge by Shaman · · Score: 5, Interesting

    Anyone who thinks Symantec isn't acting in a *VERY* self-serving manner in the past few days worth of FUD is kidding themselves.

    I kid you not, Symantec has been saying "Don't use the Mac, it's insecure! Or Linux! Or Mozilla! They're not secure, oh noes!!!"

    Guess why... maybe it's because they don't have products for those operating systems... or maybe it's because there are no virii in the wild, and they haven't been able to figure out how to write good enough virii for those OS' to scare people into buying their shitty product?

    You decide. I already have.

    --
    ...Steve
    1. Re:Symantec is a scourge by ScarabDrac · · Score: 3, Interesting

      Actually Symantec does have a OSX version of Norton Antivirus, I've seen it on the shelf at the retail store I work at. But as a friend of mine explained to me, writing a virus/worm for Windows is much easier and "can reach a larger audience" (his own words). So as you can imagine, Norton AV for OSX doesn't sell very well at all. In fact, it's the joke I use to close a Mac sale. But seriously, the sad thing is that many people will buy this FUD and let it dissuade them from trying Firefox. I probably wouldn't otherwise think this, but I am constantly surprised at how many people buy our service plans.

  12. Symantec's Business? by DarkBlackFox · · Score: 4, Interesting

    Since Symantec is best known for their Anti-Virus products, wouldn't it make sense for them to promote IE as the more "secure" browser?

    I mean, it may not be secure in the traditional sense of the word, but with all the trojans/malware/ActiveX vulnerabilities out there, surely IE is the best way to "secure" profits for themselves?

  13. Let the zealots start their engines... by bogaboga · · Score: 2, Insightful

    Let the open source zealots start their engines. Guys, this is just one company's opinion. BTW you are entitiled to yours as well.

    1. Re:Let the zealots start their engines... by starfishsystems · · Score: 3, Insightful
      Guys, this is just one company's opinion.

      Don't be a troll. An opinion is a statement based on subjective criteria. And yes, everyone has them, and comparisons between them are not particularly interesting.

      But we're not talking about subjective matters here. Symantec has released a security analysis, whose premises and reasoning may or not be correct at various points. That's what we're discussing here. Symantec is not saying, "We think Britney Spears is cute." It's claiming that vulnerabilities have been found faster in one browser versus another over a certain period of study.

      Our discussion is about the merits of that claim. It's called a rational discussion. I'm sure there will be some subjective opinions thrown in as well. After all, we're not a corporation issuing a press release on the findings of a security study, so tests of intellectual rigor are a bit different here.

      --
      Parity: What to do when the weekend comes.
  14. Another repost... almost word for word this time by Beatbyte · · Score: 4, Informative

    Seriously would it hurt anyone's feelings if the duplicate stories were just pulled off /. ?

    It not only makes /. look bad, but it is a known problem with an easy fix.

    Anywho...

    Cliff notes of last story:
    IE's exploits would be someone taking over your computer remotely
    Firefox's exploits would be malicious popups/crashing (of browser only)

    So the "severity" thing doesn't really matter here.

  15. IE is more secure... by suso · · Score: 4, Funny

    if you don't use it.

    1. Re:IE is more secure... by sootman · · Score: 3, Informative

      IE is more secure... if you don't use it.

      I know you're joking, but as it happens, you're actually wrong.

      2/2/2004: KB832894: Security Update for IE6/Windows XP: "This affects all computers with Internet Explorer installed (even if you don't run Internet Explorer as your Web browser)."

      Yes, IE is that fucking bad.

      --
      Dear Slashdot: next time you want to mess with the site, add a rich-text editor for comments.
  16. Re:Symantec? by FidelCatsro · · Score: 5, Interesting

    I think you may be confusing Symantec with another company . Last I heard Symantec were a menace who enjoyed spreading fear so people would buy their security products (which in a lot of cases did more harm than good) .

    --
    The only things certain in war are Propaganda and Death. You can never be sure which is which though
  17. New /. vulnerability found! by Spy+der+Mann · · Score: 2, Funny

    I think it's going to be called "dupeware" :P

  18. Essentially dupe by karvind · · Score: 2, Informative

    We discussed this before on slashdot.

  19. The Statistic I Want To See... by JohnPerkins · · Score: 2, Insightful

    ...is an aggregate measure of vulnerability time. How many days/weeks/months of total time will I experience between a vulnerability becoming public knowledge and the patch becoming available? How many for the Mozilla browsers? Even if there are 10 times as many vulnerabilities in the Mozilla browsers, if they get patched 100 times as fast, I would think the user would still be safer with some flavor of Mozilla than with IE.

  20. All lies! by GrayCalx · · Score: 4, Funny

    These are all a bunch of horrible horrible lies of course. There is no way that Mozilla is worse than IE in any aspect.

    All of those bugs reported last year for IE were well founded, with serious implications that needed to be released to the public for THEIR OWN SAFETY!

    Obviously these Mozilla bugs reported this year are miniscule at best, and it does the community a great disservice to release any information about them!

    Gates is the devil! Impeach Bush! Katrina is a direct result of WalMart cutting lunches! And Starbucks is lacing their coffee with microscopic beta nanomachines, built to track and report our intake of caffeinated beverages!

  21. Current Secunia Ratings by Epeeist · · Score: 4, Informative

    For Firefox

    Mozilla Firefox 1.x with all vendor patches installed and all vendor workarounds applied, is currently affected by one or more Secunia advisories rated Less critical

    This is based on the most severe Secunia advisory, which is marked as "Unpatched" in the Secunia database. Go to Unpatched/Patched list below for details.

    Currently, 3 out of 22 Secunia advisories, is marked as "Unpatched" in the Secunia database.


    And IE

    Microsoft Internet Explorer 6.x with all vendor patches installed and all vendor workarounds applied, is currently affected by one or more Secunia advisories rated Highly critical

    This is based on the most severe Secunia advisory, which is marked as "Unpatched" in the Secunia database. Go to Unpatched/Patched list below for details.

    Currently, 19 out of 85 Secunia advisories, is marked as "Unpatched" in the Secunia database.

  22. Opera by lilmouse · · Score: 2, Interesting

    Thanksfully, Opera is now available as a free browser. Yes, free as in beer, but it's still good. Why? Because when you have multiple browsers, a single infection can't hit all of them.

    Yay Opera for windows, and Konquerer for Linux!

    --LWM

  23. Re:Symantec? by tpgp · · Score: 2, Insightful


    These guys are actually somewhat reputable and they're saying this. Worth keeping and eye on.


    No - Symantec are not reputable. They are a software company making a great deal of money off a particular business model (attempting to close the gate after the horse has bolted)

    Of course Firefox/Linux/Mac/anything other then a microsoft hegemony scares the crap out of them.

    I will leave it to others to say how the study is flawed (hint counting vulnerabilities without taking into account seriousness!) as other people can do that.

    --
    My pics.
  24. RTFA by mothlos · · Score: 4, Insightful
    There is one caveat: Symantec counts only those security flaws that have been confirmed by the vendor. According to security monitoring company Secunia, there are 19 security issues that Microsoft still has to deal with for Internet Explorer, while there are only three for Firefox.
    I think that says it all.
  25. With a MAJOR Caveat by mjh · · Score: 5, Interesting
    From TFA:
    There is one caveat: Symantec counts only those security flaws that have been confirmed by the vendor. According to security monitoring company Secunia, there are 19 security issues that Microsoft still has to deal with for Internet Explorer, while there are only three for Firefox.
    Interesting methodology. That means that the browser vendor is in complete control of the vulnerability counts. This is NOT the kind of reporting of vulnerabilities that I think should be encouraged. I'd rather see vulnerability reports that encourage full disclosure. This creates an incentive for the vendor to hide vulnerabilities. I think that's bad.

    How about this: a report that identifies the vulnerabilities associated with a vendor, and not a product. In other words, after the initial public announcement of a vulnerability, we report how long it took the vendor to release a patch. Lower scores are better.

    Anybody think that'll work? If not, why not?

    --
    Key to financial independence: Spend less than you earn. Save and invest the difference. Do it for a long time.
  26. A little adovcating for the devil... by sterno · · Score: 2, Insightful

    How quickly and effectively were the Mozilla/Firefox vulnerabilities patched in comparison to IE?

    While this is important in the grand scheme of things, ultimately, the more often vulnerabilities come out, the less likely it is that everybody is going to stay up to date consistently. Lest we forget, most attacks are exploiting publicly known and well understood software flaws. Many attackers are simply using the lists of critical bugs as specifications for their next attack.

    Having said that, I think this is less a reflection on the code for Firefox and more about the development status of the two browsers. Firefox is still actively developed, getting new features on a routine basis. Invariably as new features are added, new bugs will be made and old bugs will be discovered. With IE, it is purely maintenance mode right now. The only updates it receives are bug fixes. So invariably there are less bugs to find over time if you aren't adding them with new code.

    Symantec isn't shilling for Microsoft, they are just drawing a rather short sighted conclusion based on the the statistics they have. It doesn't say anything about longer term trends for the browsers, nor does it suggest anything about the innate security of their development methodologies.

    --
    This sig has been temporarily disconnected or is no longer in service
  27. Blowing smoke. by SoupIsGood+Food · · Score: 2

    I have never, in the course of my IT career and in my daily personal web surfing experience, been affected by security exploits aimed at Firefox or any other Mozilla-based browser.

    I can say with confidence that I have laughed mightily at colleagues, friends and family members running IE who have to juggle two or three anti-malware programs and still wind up shoulder-deep in the Windows Registry or re-install because of security holes in IE.

    Symantic can only blow so much smoke up my ass before reality re-asserts itself. Theoretical vulnerabilities are bad. Giant screaming voids you could drive a Peterbilt through are worse. Open Source Software frequently gives you the former. Microsoft can be counted upon, in a lead-pipe cinch, to deliver the latter.

    SoupIsGood Food

  28. Right then. by Slashcrap · · Score: 2, Insightful

    Hands up anyone who has contracted spyware/adware/viruses through IE.

    Ok, now hands up anyone who has contracted spyware/adware/viruses through Mozilla/Firefox.

    Your honour, I rest my case.

  29. 10 year old latest version? by nlinecomputers · · Score: 3, Interesting
    10 years from now, the latest Mozilla version will probably have critical vulnerabilities. Each new version will have different technologies to deal with as well as have new developers/programmers involved. If one thing is constant in programming any app, as time goes on and new versions come out, there are always new bugs and problems. Mozilla won't be immune to those.


    This is true. However IE is supposed to be a mature application. It isn't a new version that comes out every few months. At some point shouldn't a developed app reach a point that it is locked down and secure?
    --
    Slashdot, home of supporters of free software, free music, and free speech.Except for Moderators that disagree with you.
    1. Re:10 year old latest version? by TurdTapper · · Score: 3, Insightful

      I would agree if the app was being developed against a non-changing set of technologies. If there are not any other changes that need to be accounted for, then at some point the app should be completely secure. Unfortunately, that doesn't work when it comes to software. There will always be a new version of something that new functionality is needed for (XML, Java, CSS, etc). If a program does not keep updating and incorporating the latest technologies, especially if it's a web browser, then it would quickly become unusable. Can you use any old version of IE and still be able to do EVERYTHING on the web? No. The same way that I would guess if you keep the current version of Mozilla without ever upgrading, 10 years from now you won't be able to do 90% of what is available on the web.

      --
      A man with a gun is called a citizen. A man without a gun is called a subject.
    2. Re:10 year old latest version? by Zak3056 · · Score: 2, Insightful

      There's a problem with the point you're making:
      IE6 is four years old. While SP2 was released last year, this version is applicable ONLY to WinXP SP2--all other platforms are stuck at IE6 SP1, which was released almost exactly three years ago. Everything since then has supposedly been security fixes and the like.

      It's not a moving target--it really IS supposed to be mature code. There's a far cry between this and something under active development!

      --
      What part of "shall not be infringed" is so hard to understand?
    3. Re:10 year old latest version? by Zoop · · Score: 3, Insightful

      I would agree if the app was being developed against a non-changing set of technologies.

      Every technology IE 6 supports is older than IE 6. IE 6 was released years ago, and hasn't upgraded its support for internet technologies, nor has it added new ones. So really, the argument that "IE 6 is vulnerable because it supports changing technologies" is hogwash. IE 6 is an unchanging application with multiple years available for fixing vulnerabilities.

  30. Yawn. Follow the money. by petard · · Score: 5, Informative

    Even symantec admits that this report is a steaming pile of crap.

    From TFA:

    Symantec counts only those security flaws that have been confirmed by the vendor. According to security monitoring company Secunia, there are 19 security issues that Microsoft still has to deal with for Internet Explorer, while there are only three for Firefox.

    Nice. So in terms of checking off the reported vulnerabilities and counting each one equally, if the report would be honest, IE would have 32 issues and Firefox would have 29. For the sake of this report, all vulnerabilities are equally bad, right? Well, not according to TFA:

    Symantec admitted that "at the time of writing, no widespread exploitation of any browser except Microsoft Internet Explorer has occurred," but added that it "expects this to change as alternative browsers become increasingly widely deployed."

    So the IE vulnerabilities result in widespread exploitation and the Firefox ones don't, but firefox is somehow worse? I think the only way in which firefox is worse, from Symantec's perspective, is that the constantly malware-infested machines (where IE is the main infestation vector) inflate demand for the crap that Symantec peddles, and they're afraid that if people aren't constantly suffering from the pain of these infections this demand will evaporate.

    Feh. Maybe I'm a cynic, but this looks like marketing poorly disguised as research to me...

    --
    .sig: file not found
    1. Re:Yawn. Follow the money. by Anonymous Coward · · Score: 2, Interesting

      No, you're not a cynic. You ARE right on the money, literally. Besides, Symantec 2005 relies on ActiveX controls to run their anti-virus software! How stupid is that?! (Hint: VERY stupid when my wife's computer with SYMANTEC A/V software got a nasty little ActiveX virus which caused Symantec software to completely cease proper functioning. - no updating, no scanning, no more protection)

  31. They are just protecting their interests by erroneus · · Score: 2, Insightful

    Yesterday there was something from them about how Firefox and Mac users are in a fantasy land for thinking they are safer for using them. Now they are asserting that within their selected window of time, more vulnerabilities were reported in FF than MSIE. How about we change the window from the beginning of their respective initial public releases until now? Would that be fair? How about if we pick a month window where no vulnerabilities had been reported in FF? Would that also be fair and balanced?

    If people start jumping ship (Win+MSIE) onto another ship, Symantec will see that they will sell fewer floatation devices.

    This is a pretty pathetic attempt to sway opinion by Symantec.

  32. Criticality and Vulnerability Window by Bob9113 · · Score: 2, Informative

    Aside from the question raised in many posts about whether the fact that Firefox is open source leads to faster and fuller disclosure, the following is an email I sent this past weekend regarding this article.

    Lots is being made the past few days about the number of security holes found in various browsers. Just to try to keep the discussion from descending to complete irrelevance, here's the stats that actually matter:

    Solution Status (has it been fixed?):
    http://secunia.com/graph/?type=sol&period=all&prod =11
    http://secunia.com/graph/?type=sol&period=all&prod =4227

    Criticality (how bad is it if I get hit?):
    http://secunia.com/graph/?type=cri&period=all&prod =11
    http://secunia.com/graph/?type=cri&period=all&prod =4227

    Unpatched Criticality (what can happen to me today?) Requires a little more looking - see the list at the bottom of each page:
    http://secunia.com/product/11/
    http://secunia.com/product/4227/
    IE: 5 unpatched moderate or greater criticality
    Firefox: 0 unpatched moderate or greater criticality

    Finally, and unfortunately not clearly covered in [the Secunia] report is vulnerability window - how long does a bug go without being patched. You can, however, make a fairly good estimate by looking at the patch time for highly critical or worse bugs:

    MS has been making big improvements lately, so I'll only look at the MS holes from the past year (the older ones have dramatically longer vulnerability windows) (I've also left out holes which were publicly discovered as a result of a windows patch)

    IE Highly+ Critical Windows (past year)
    http://secunia.com/advisories/12806/ 103 days
    http://secunia.com/advisories/12889/ 108 days
    http://secunia.com/advisories/12959/ 29 days
    http://secunia.com/advisories/13482/ 53 days
    http://secunia.com/advisories/15891/ 7 days

    Firefox Highly+ Critical Windows (all time)
    http://secunia.com/advisories/14654/ 7 days
    http://secunia.com/advisories/14938/ 24 days
    http://secunia.com/advisories/15292/ 5 days
    http://secunia.com/advisories/16043/ 7 days
    http://secunia.com/advisories/16764/ 3 days

    Keep the discussion rational - security is hard, so is assessing security. Be skeptical of anyone who has a dog in the fight (eg: Symantec). [Which is not to say that Symantec cannot be trusted for Windows security, only that their PR department's press releases regarding software security should be treated as suspect - particularly when they draw questionable conclusions from insufficient data.]

  33. Flaw in the methodology by Bruce+Perens · · Score: 4, Insightful
    Symantec only counts vendor-acknowledged flaws in this study. Microsoft has yet to handle 19 flaws, and this is admitted by Symantec. If they had counted those, IE would have been less secure in their study. It seems to me that the methodology is deliberately flawed.

    Bruce

  34. Bug Free by Mark_MF-WN · · Score: 5, Interesting

    Bug free software is quite possible. It's just prohibitively expensive, because it usually requires that the developers use a mathematical validation system. Thus it's typically confined to projects where system failure would result in Human casualties. It's an irrelevant quibble though, since web browsers are far, far too complex to ever be formally validated.

    1. Re:Bug Free by shis-ka-bob · · Score: 2, Informative

      Is that why TeX is so expensive? Its well over a decade since the bug in TeX was acknowledge by Knuth. Validating may be costly, but that doesn't prevent the software from being inexpensive.

      --
      Think global, act loco
    2. Re:Bug Free by podperson · · Score: 2, Informative

      Bug free software is quite possible. It's just prohibitively expensive, because it usually requires that the developers use a mathematical validation system. Thus it's typically confined to projects where system failure would result in Human casualties.

      It also requires specifications to be expressed mathematically, which tends to restrict it to programs where the specifications are written by scientists or engineers.

  35. Re:Another repost... almost word for word this tim by PepeGSay · · Score: 2

    "Malicious popups"?? "Crashing browler only"??

    Yeah right. Please! Stop! I'm laughing so hard it hurts.

    2003-2005
    http://secunia.com/graph/?type=imp&period=all&prod =4227
    2005 Alone
    http://secunia.com/graph/?type=imp&period=2005&pro d=4227

  36. IE vs Windows bugs by pjrc · · Score: 4, Informative
    In a previous post I found 22 IE bugs by simply looking through all the 2005 Microsoft security bulletins. These don't include bugs that Microsoft hasn't even fixed. This probably isn't a complete list either (I did it in only 10 minutes or so, plus avoiding slashdot's lame lameness filters to post a nicely formatted list). There are lots of other bugs not covered by the bulletins, where they post "notices" (like the infamous "don't click on links, type them instead"). But even if I found them all, 22 is a lot more than 13. And most on that list of 22 allow remote code execution.

    But within the bulletins, there are lots of bugs, like the one fixed by MS05-024 that aren't "technically" IE bugs. But the end result is that a malicious web page (or advert iframe) could do something nasty... usually execute arbritrary code (install spyware or a virus if the server is infected). If simply viewing a web page with IE allows an attack, I call that an IE bug, regardless of where the actual bug is located by Microsoft's way of thinking.

    Notice how the "affected software" of MS05-024 is many versions of windows, but Internet Explorer isn't specificly mentioned. So when someone tallies IE bugs, this one probably doesn't make the list. But the "Vulnerability Details" section says:

    Web View Script Injection Vulnerability - CAN-2005-1191:

    A remote code execution vulnerability exists in the way that Web View in Windows Explorer handles certain HTML characters in preview fields. By persuading a user to preview a malicious file, an attacker could execute code. However, user interaction is required to exploit this vulnerability.

    I can see how a journalist could do such poor research. But Symantec? Come on, I found 22 nasty IE bugs by just browsing though 40-some Microsoft bulletins. That Symantec only thinks there's 13 doesn't build much confidence in the supposed "market leader" of anti-virus products!

  37. How to respond to bad Mozilla security news on /. by Overly+Critical+Guy · · Score: 4, Funny

    How to respond to bad Mozilla security news on /.

    1.) First, immediately dismiss the results, just like you did in the last Mozilla security story. Mozilla is flawless.

    2.) Randomly reference Open Source, claiming the flaws were easier to find because of it, which has nothing to do with the report in the article and actually sounds like a criticism of Open Source, if anything.

    3.) Accuse the study of bias or "shilling." ALWAYS do this when the study goes against your pre-made worldview (in this case, Mozilla being flawless). When the study gives the opposite conclusion, agree with it and praise it, often with related anecdotal stories.

    4.) Reference Internet Explorer's age, which has little to do with and doesn't change Mozilla having more flaws than Internet Explorer today.

    5.) Ask how quickly the Mozilla vulnerabilities were patched, ignoring that Mozilla has marked vulnerabilities "Confidential" before for them to sit for two years unfixed.

    6.) Claim Internet Explorer is integral to the OS, when you argued that Internet Explorer was easily removed from Windows during the anti-trust trial.

    7.) Claim matter-of-factly that, for some reason, it "goes without saying" that the study uses some sort of flawed logic, without citing the logic, giving proof, or backing the statements in any way. Simply claim it, knowing everyone will mod you up because they, too, want to believe Mozilla is flawless.

    --
    "Sufferin' succotash."
  38. Symantec is living off of their rep from the 80s by gothzilla · · Score: 2, Insightful

    Symantec stopped producing effective software a long time ago. There was a time though when any self-respecting geek had a copy of Norton Utils, you know, the ones with all two-letter file names like NU.EXE.
    Brand familiarity and name recognition are suitable substitutes for quality when it comes to business and profits. I wouldn't touch any of their software with a 10 foot IDE cable anymore, and haven't for the past few years.

  39. Vendor-confirmed? by Todd+Knarr · · Score: 2, Insightful

    I think this is the kicker. The 25 vulnerabilities for Mozilla are almost certainly all the known vulnerabilities. For IE, how many vulnerabilities are there that've been reported that MS hasn't publicly acknowledged?

    In addition, what's the severity? The last Mozilla vulnerability was the IDN bug, which was trivially worked-around by changing one config setting until a patch was released. Contrast that to the recent vulnerability in IE that MS won't discuss details of, other than to say that it allows total compromise of the machine and they won't be patching it until next month, and there's no workaround for the bug because nobody knows what the bug is (outside of MS, the security company that found it and the black-hats, of course).

    My take on it: Mozilla may be having more vulnerabilities reported, but it's still fewer than in IE and those vulnerabilities are less severe, easier to work around without crippling your system and fixed sooner than IE's holes. From a user's viewpoint, this makes Mozilla more secure than IE.

  40. Keyword: Disclosed by bubkus_jones · · Score: 2, Insightful

    I'm sure everyone's noticed the word "disclosed". Firefox/Mozilla are open sourced, so everyone can see potential voulnerabilities and tell the world. IE, however is generally limited to the MS developers, and it will pretty much be up to their bosses to decide whether to disclose a voulnerability.

    How many IE voulnerabilities are there that we don't know about?

  41. Comment removed by account_deleted · · Score: 2, Insightful

    Comment removed based on user account deletion

  42. Re:The key point, to me is... by starfishsystems · · Score: 2, Insightful
    Fundamentally more secure means there's something inherent in their technology that makes it more secure.

    There are indeed fundamental differences in the security between the two approaches. One obvious difference is modularity. A browser which is monolithically integrated with a system is a greater security risk than one which can be removed or replaced, since its risk cannot be mitigated.

    Another fundamental difference is in transparency. Security fundamentally requires verification. Closed source strictly prevents verification.

    Another is containment. What are the consequences to the system if the browser is compromised? If the browser is designed, say, with the intent of installing software or modifying the window system, then it fails to contain security risks compared to a browser which defers these actions to the part of the system which is nominally responsible for system configuration.

    --
    Parity: What to do when the weekend comes.
  43. Vendor-confirmed by Ruphuz · · Score: 2, Informative
    From TFS:
    ...25 vendor-confirmed vulnerabilities were disclosed for the Mozilla browsers
    and
    13 vendor-confirmed vulnerabilities were disclosed for IE,

    The difference in the amount of bugs might just be caused because Microsoft is somewhat more reluctant than MoFo to admit its own faults.

    I am not trolling, I am just stating an option.

    --
    My other post is a First.
  44. For those who may be fooled by this by Trailer+Trash · · Score: 5, Insightful

    This exposes the gulf between open source security and proprietary security. Ignore for a minute the fact that Symantec a) has a vested interest in you using insecure products and b) uses highly flawed methodolgy as their "count" is actually "count of vendor-admitted bugs". There's a major difference between a vulnerability in Mozilla and a vulnerability in IE.

    Since we don't have the source for IE, any vulnerability found is, by definition, exploitable. Someone found a way to exploit it- you get a vulnerability.

    Vulnerabilities found in Mozilla, on the other hand, are often theoretical in nature. Someone looking through the source finds the problem, but no exploit is written.

    Another major problem is here:

    The average severity rating of the vulnerabilities associated with both IE and Mozilla browsers in this period was classified as "high", which Symantec defined as "resulting in a compromise of the entire system if exploited."

    My entire system isn't going to be compromised from me browsing with Mozilla. Period. Somebody is confused.

  45. In other news... by Glog · · Score: 2, Informative

    ... several Microsoft employees were found snuggling below the desks of the Symantec "experts" who recently performed a comparison between Firefox and IE security.

  46. Seriously though... by Anonymous Coward · · Score: 2, Informative

    Even with extensive code reviews, the potential for malicious developers to submit code with hidden vulnerabilities is high. We just had the 2005 Underhanded C Contest (see link) which demonstrates the possibilities. http://developers.slashdot.org/article.pl?sid=05/0 9/18/158200&tid=156&tid=172

  47. Show me a percentage by Rick+and+Roll · · Score: 2, Insightful
    Show me a percentage of Firefox users that have had their computers screwed up, compared with IE. I'm sure the Firefox number will be lower.

    If Firefox had been more popular, would it have been more exploited? Would it have been worse than IE? These are useless questions.

    The point is, Firefox users are more secure than IE users. And Firefox developers are much better listeners than IE developers. People who use Firefox have a better experience with their computers. And that is why IE has lost market share.

    I hope nobody takes all these B. S. articles seriously.

  48. Broken link. by Neoncow · · Score: 2, Informative

    Parent's link to the previous post is broken. Parent's previous post.

  49. Re:where is googleBrowser? by Farmer+Tim · · Score: 2, Funny

    googleBrowser development has temporarily stalled because they're having a bit of difficulty working out how to make it a web delivered app.

    --
    Blank until /. makes another boneheaded UI decision.
  50. No. by khasim · · Score: 2, Insightful
    Anyone who uses any browser online should still be running virus-detection software. This will never change, no matter what OS or browser you use.
    I'm running FireFox with the NoScript extension. That way, no JavaScript runs from any site I don't specifically whitelist. So, no exploits from that side.

    FireFox, by default, requires you to whitelist sites to install software from them. So, no exploits from that side.

    And so on and so forth.

    The key to security is to reduce the avenues of attack.

    If my browser will not run any code from your site and I will not download any apps from your site, then I do not have to worry about being cracked via my browser going to your site.
    That said, response time to threats is better for Firefox. The total threat posed is probably less, because the time of exposure is a fraction of IE vulnerabilities.
    No. That only applies if 100% of the population (or close to it) applies those patches as soon as they're released.

    You cannot depend upon the users applying patches so you must focus on removing the threat before the user is involved. That is where FireFox's whitelists beat Microsoft every time.
    But Mozilla faces a tough road ahead -- if they maintain or gain market share, they have to be very cautious, as their vulnerabilities will begin to be targeted seriously by malware.
    Again, that is only the case if the vulnerabilities can be exploited. If I don't allow Java or JavaScript or installs from a website, then it is going to have to be a pretty dramatic vulnerability for me to be infected.

    And until that vulnerability is shown to exist, the discussion is purely theoretical while the discussion of IE's exploits is documented fact.
  51. Security is not reported incidents by WillAffleckUW · · Score: 2, Informative

    It's also unreported and undisclosed major gaping holes, the ability to automatically run scripts that install viruses and spyware on your laptop, and the clear fact that running IE without security at top levels leads to a compromised PC within minutes on the UW campus, whereas you can run for days with Firefox.

    Let's get real, and stop pushing phony statistics.

    --
    -- Tigger warning: This post may contain tiggers! --
  52. What a Wonderful World by GhodMode · · Score: 2, Funny

    Sung to the tune of "What a Wonderful World" by Sam Cooke...

    Don't know much about security
    Don't know much about the industry
    Don't know much about those M$ crooks
    Don't know how those statistics look

    But I know that Firefox is what I use
    And I know that if y'all use it too...

    What a wonderful world this would be ...
  53. Bug Bounty Program by JCsPiN247 · · Score: 2, Interesting
    http://www.mozilla.org/security/bug-bounty.html

    I think that everyone has for got an important factor here. Not only is Firefox open source, but Mozilla actually rewards people monetarily for bringing vulnerabilities to their attention. This is in sharp contrast to say Microsoft who has threatened legal action against these same people. So lets look at an example...

    Mozilla's Bug Bounty Program will PAY you $500 and openly discloses their code and vulnerabilities (after a fix of course)

    Microsoft will threaten and perhaps follow through on legal action, and certainly does not open their source code.

  54. Re:How to respond to bad Mozilla security news on by d34thm0nk3y · · Score: 2, Insightful

    If these responses are so predictable should you not have had time enough to think of some actual rebuttals. I have another for your list:

    8.) Pointless troll ranting against the Slashdot groupthink without adding anything to the discussion.

  55. True but by einhverfr · · Score: 2, Informative

    First I will say that I am a Mozilla user that has been considering going to other nonXUL-based brousers in order to get better security. I now regard Mozilla and Firefox design at more or less the same level of security as IE.

    IE's main problem is that you have this concept of security zones. These zones are supposed to allow one to trust intranet sites with activeX controls that might not be trusted on the internet. However, there are plenty of ways to cross this barrier so it is fairly porous. Hence the combination of ActiveX and security zones makes IE inherently insecure. Get rid of either one and things get a whole lot better.

    The problem with Mozilla is that you have very expansive capabilities in the Mozilla Portable Runtime, and that these capabilities can be accessed by Javascript. How do we make it secure? We require that these are accessed via Chrome components. In other words we have a very similar set of design flaws to IE in Mozilla and Firefox. Don't believe me about the separation, try putting this into your address bar chrome://navigator/content/navigator.xul (harmless yet a good demonstration of the link between content and interface and sufficiently annoying that Slashdot won't let me add it as a link ;-)).

    Now, Mozilla has two advantages over IE:
    1) XUL is a really great RAD tool as long as you don't use it as a general purpose browser.

    2) You can get around the security border issue by running a Gecko-based non-XUL browser, such as Epiphany, Camino, etc.

    --

    LedgerSMB: Open source Accounting/ERP
  56. Umm 1.06 versus 6.+ by Kylere · · Score: 2, Interesting

    When Mozilla has been a real concern (for example since .9) on a big scale close tohalf the time IE has been a real concern, this will not be an issue, and in the meantime security through obscurity beats using the primary target of ever scumbag coder on the planet.

  57. head-in-sand (or head-in-ass?) by jusdisgi · · Score: 4, Informative

    Jesus fucking Christ. This has got to be the worst number doctoring all day long. From TFA:

    There is one caveat: Symantec counts only those security flaws that have been confirmed by the vendor. According to security monitoring company Secunia, there are 19 security issues that Microsoft still has to deal with for Internet Explorer, while there are only three for Firefox.

    Oh, well that's just a minor fucking nuclear bomb. Doesn't that make the count 28 to 32? For fuck's sake....the 19 vulnerabilities that Microsoft simply hasn't acknowledged just don't count? This new revelation should make it much cheaper to make secure software...after all, I'm sure it takes far fewer man-hours to do nothing then it does to fix something, and according to Symantec, it produces better results, too!

    --
    Given a choice between free speech and free beer, most people will take the beer.