Slashdot Mirror


Firefox Users Surf Safer

SenseOfHumor writes "According to two University of Washington Professors, Firefox users have a safer browsing experience than users of IE. These researchers sent their crawlers to 45,000 websites and studied the impact on Firefox and IE." From the article: "Levy and Gribble, along with graduate students Alexander Moshchuk and Tanya Bragin, set up IE in two configurations -- one where it behaved as if the user had given permission for all downloads, the other as if the user refused all download permission -- to track the number of successful spyware installations. During Levy's and Gribble's most recent crawl of October 2005, 1.6 percent of the domains infected the first IE configuration, the one mimicking a nave user blithely clicking 'Yes;' about a third as many domains (0.6 percent) did drive-by downloads by planting spyware even when the user rejected the installations."

7 of 240 comments (clear)

  1. Post this in Public Somewhere by neonprimetime · · Score: 4, Insightful

    Could somebody with power please post results like this somewhere that the general public would see?
    Slashdot readers already know this!

    This needs to be in USA Today, New York Times, on Fox News, CNN, local newspapers, local news, etc.

    Then it would actually mean something.

  2. How about a four-way matchup... by PFI_Optix · · Score: 5, Insightful

    From TFA:

    "We can't say IE is any less safe," explained Levy, "because we choose to use an unpatched version [of each browser.] We were trying to understand the number of [spyware] threats, so if we used unpatched browsers then we would see more threats."

    I hope they used a very old version of Firefox. Comparing FF1.5 to an old unpatched version of IE is hardly a fair comparison.

    They should have patched both browsers and had them run the same crawl. Then we could see how each browser in its most current state handles spyware, and how much each one has improved via patch releases.

    --
    120 characters for a sig? That's bloody useless.
  3. User education by doombob · · Score: 4, Insightful

    A better, but longer headline: Firefox browser less likely to automagically download malware that damages the operating system than internet explorer browser.

    The misleading headline makes it sound like people who use firefox are less likely to visit a site that would take advantage of an unpatched exploit in their computer. That conclusion, however, would not surprise me if it were true.

    In addition, there are very few people who just go the websites of the world in a random fashion. So who cares if around four percent of the websites out there have malicious programs - that is a problem of domain hosts that allow nasties to keep their sites on those servers. In a world where most people (probably around 80% of internet users) visit the top websites (probably around 20% of sites), I think the problem is one of user education (don't go to sites you don't trust, don't randomly click on crap - which probably needs to be applied most to pr0n surfers).

  4. Re:What are those 0.6% evil sites doing? by realmolo · · Score: 4, Insightful

    What are they doing?

    They're popping up a dialog box that says "To view this site, you must install the "Fuck My Computer Up Beyond Recognition" ActiveX Control". Please click "Yes" to continue."

    Sad but true. Most people just blindly click "OK, YES, I AGREE". There's no good way to stop that.

  5. Re:Who cares? by OneSeventeen · · Score: 5, Insightful

    So if I user never heard of Firefox, but has heard of spyware, this study won't change anthing? I work in a department that switching to Firefox would solve 25% of the tech support calls, but the users still insist on IE because they don't know the severity of the situation, and also don't even know what Firefox is. This article will actually help to prove to the non-techies that switching would be a good idea.

    --
    "Now the trouble about trying to make yourself stupider than you really are is that you very often succeed." -C.S. Lewis
  6. Yet another lame FF ra-ra post by fzammett · · Score: 4, Insightful

    I'm really sick to death of all the "Firefox kicks everyones' ass" pieces all over the place. I really can't stand being in the mindset to defend MS, but yet...

    This whole "study" was stupid in terms of proving one browser more secure from malware than the other (which wasn't their point apparently, which makes the /. post even more stupid). The conclusion is if you take two unpatched browsers, you'll get spyware a lot, and moreso for IE.

    Ok, as others have said, that's not exactly like finding out the Sun orbits the Earth or anything.

    It is much like saying "hey, you know, if you go into a burning building without firefighting gear, your gonna get burnt".

    REALLY?!? WOAH! HEADLINE NEWS!

    "If you have sex with a number of HIV-positive people you may well contract the virus".

    SERIOUSLY?!?

    "If you vote republican, you will slowly lose your personal rights".

    THE HELL YOU SAY?!?

    "If you vote democrat, you will pay a bunch more in taxes".

    YEAH, I GET IT, IT'S OBVIOUS!

    Let's see what happens with two FULLY-PATCHED browsers. Will FF still come out on top? Yes, I would imagine so. I'm not about to say IE isn't inherently more dangeruos than FF, because I think it is. But it's a question of degrees... are two completely up-to-date installs of FF and IE going to be *that* much different? I would seriously doubt it. I'd be willing to bet they are close enough that you could effectively ignore the difference (until your machine gets wiped out by the .00000001% of malware that got through I guess!)

    It's interesting to me... I've been using IE all along... there are some things that annoy me about FF that keeps me from using it full-time. In all that time, I can count on one hand how many times I've been infected with anything. And, once I moved to Maxthon a year or so ago, I haven't been infected with anything even once. The difference between IE and FF is not THAT big, when you are fully-patched.

    Talking about anything less is pointless... and yeah, I know the argument... "But grandma doesn't know she should be patching her browser and doesn't know how". Well, get grandma off the computer! We don't let kids drive cars because THEY DON'T KNOW HOW TO (neither do many adults of course, but I digress). Using a computer is no different than using any other tool: you can hurt yourself, and sometimes others, if you don't know how to use it. Can't you smash your hand with a hammer? Can't you cut a finger off with a can opener? Can't you badly burn yourself using your oven? There is a certain amount of risk to using any tool, and you accept that risk, but more importantly, you learn about the tool to some minimal degree that allows you to mitigate the risk as much as possible. People need to start doing the same with computers. Not everyone has to know how to hook a system call or spawn daemon threads in a VM or whatever else, but keeping a browser up to date, especially as relatively easy as it is today? Yeah, I'd say that's the MINIMUM level of knowledge one should have, and if you don't have it, git knit a sweater, you shouldn't be touching a computer.

    Enough with all the "FF rules and IE sux0rs" crap... if you like one or the other, great, no problem, choice is good, use what you like. But enough with constantly telling me how unsafe I am using IE (or an IE derivative). My experience does not bear it out, and even if it did, the answer would still be what it's been all along: the USER is more at fault than the browser.

    Hey, when something gets through FF by the way, do we start screaming that it is insecure and no good? Of course not! We first ask "well, what did the USER do to let the garbage in"? Because OF COURSE it could never be FF's fault. And you know what? 9 times out of ten, it isn't! Just like 9 times out of 10, it isn't IE's fault... ok, to be fair, 8.5 times out of 10 for IE... like I said, I don't doubt FF is a bit better.

    Ok, I'm done, rant over.

    --
    If a pion (n-) collides with a proton in the woods & noone is there to hear it, does lamdba decay into the source pa
  7. Re:Or 100% if its a new installation... by hazem · · Score: 4, Insightful

    Why are you installing XP (or any other OS) with it directly connected to the internet?

    Get a router with NAT to block most of the bad stuff - and heck, disconnect IT from the internet. Get the computer working and as much security in place before going online with it.

    A simple netgear or linksys router provides tons of protection and costs about $50... definitely worth the time saved from reinstalling windows once or twice.

    If you're really paranoid, download the security patches and burn them to CD so you can install them without going online.