Firefox Most Vulnerable Browser, Safari Close
An anonymous reader writes "Cenzic released its report revealing the most prominent types of Web application vulnerabilities for the first half of 2009. The report identified over 3,100 total vulnerabilities, which is a 10 percent increase in Web application vulnerabilities compared to the second half of 2008. Among Web browsers, Mozilla Firefox had the largest percentage of Web vulnerabilities, followed by Apple Safari, whose browser showed a vast increase in exploits, due to vulnerabilities reported in the Safari iPhone browser." It seems a bit surprising to me that this study shows that only 15% of vulnerabilities are in IE.
How many of these vulnerabilities were due to Firefox itself, and how many due to plugins?
which is totally what she said
So just down the page on slashdot, this very day, there are warnings about a "Windows kernel vulnerability" that is exploited through IE. I'll take three cross-site scripting bugs any day over a kernel level compromise, thank you.
I know the world doesn't have a good objective measure of "impact" to assign to these things so that one could assess the total "probable inconvenience" of the presented security vulnerabilities, and that makes unbiased data gathering difficult, but this feels pretty absurd.
It seems a bit surprising to me that this study shows that only 15% of vulnerabilities are in IE.
There is an explanation for that.
Cenzic Recognized as a Microsoft Certified Partner, Experiences Substantial Momentum in Q2
Just another consultant hired to slant reality if you ask me.
http://search.cert.org/search?q=advisory+internet+explorer
http://search.cert.org/search?q=advisory+firefox
boycott slashdot February 10th - 17th check out: altSlashdot.org
According to the report, as best I can determine, this is how they found their results:
"Cenzic analyzed all reported vulnerability information from sources including NIST, MITRE, SANS, US-CERT, OSVDB, as well as other third party databases"
It seems reasonable that any/all open source software would have a higher number of reports in these databases than proprietary software, simply because more people are able to publicly scan and report on vulnerabilities... by definition, open source software conducts it's business in public, while proprietary software does so behind it's private curtain.
Isn't counting bugs released as part of press releases and change logs kind of like saying "All confirmed criminals are in jail?"
Comparing openly known vulnerabilities, and calling it "all in all vulnerability".
As if they wouldn't know perfectly well, that Microsoft sends a cease and desist letter to anyone who is even talking about a vulnerability that is not official to MS.
I guess the old saying is true, that:
If you can't program, you teach.
If you can't teach, you administrate.
If you can't administrate, you report.
If you can't report, you criticize.
Any sufficiently advanced intelligence is indistinguishable from stupidity.
Microsoft is reeling from the vicious and unwarranted slanders of security companies and the US government’s Computer Emergency Response Team that its Internet Explorer web browser has alleged “security holes” or is in any way less than the finest software known to mankind and excellent value for your money. "Cenzic proves it's Firefox! FIREFOX DID IT! Fuckers."
The festering paedophiles of CERT have gone so outrageously far as to make the ludicrous claim that just viewing a malicious webpage in IE could leave your computer open to being hacked and turned into a Russian Mafia spam server. “We don’t know what could have triggered such vindictiveness,” sobbed Microsoft marketing marketer’s marketer Steve Ballmer. “Do they hate free enterprise that much?”
There are things you can do to make your computing experience even more secure. Microsoft’s official suggestion — make sure your anti-virus software is up to date and using an entire CPU doing nothing much, click through five screens to run IE in “protected mode,” click through four screens to set zone security to “high,” click “JUST BLOODY DO IT WILL YOU” when the User Access Control asks if you really want to do this, enable automatic updates with the minor side-effect of installing Microsoft DRM on your system or Windows Genuine Advantage randomly turning your computer into a paperweight, and sacrifice a goat to Microsoft at midnight on a moonless night — is simple and straightforward. “It’s the quality you’re paying for.”
On no account should you consider that there might be other web browsers out there, as researchers have demonstrated that all of them automatically download the cover of Virgin Killer. “I saw a report,” said marketing marketer John Curran of Microsoft Completely Enderlependent Analysts, Inc., “that another browser had more vulnerabilities than ours! People would be very foolish indeed to move from the latest IE to Netscape 4.01.”
“These CERT wankers are Mactards and trolls,” said Guardian marketing marketer Jack Schofield. “They just want to take IE users out, brutally sodomise them, gas them in concentration camps and” [This comment has been removed by a Guardian moderator. Replies may also be deleted.]
http://rocknerd.co.uk