Mozilla beating IE... but not in a good way.

Looks like IE is finaly getting a break...

It is interesting to note that Mozilla browsers, including firefox, had the most vulnerabilities during the first half of 2005. For once, Internet Explorer must be relieved they are behind Mozilla in this measure.

Read the article:

http://www.sans.org/newsletters/newsbites/...=7&issue=38#319

See what popularity will get ya.

#317307

oh dear it's rjohnstone again! I think I'll go sleep. :P

*contemplates playing guitar naked*

#317311

Yep... I'm back!!! ;)

#317332

Open source is the devil!

#317342

... a devil with a lot of bugs?

#317344

had the most reported vulnerabilities

/. style hyperbole

#317355

Oh... I guess people can't find any more IE bugs, so many have been already reported =P

But yeah popularity comes both good and bad ways. I'm trying to imagine in a few years how many Mac OS X viruses and exploits we'll have with all this Intel stuff... =

#317357

Any future vulnerabilities in OSX will not come from a platform switch to Intel. Not directly anyway.

The CPU has nothing to do with an OS's ability to be exploited.

It may have an indirect impact, where increased popularity raises it to a level where hackers will feel it worthy of focusing their attention on it, but only time will tell that story.

I prefer to use Firefox myself and am still doing so as I write this, but I knew it was only a matter of time before it would attract the eye's of hackers.

#317362

I guess no one here reads other computer news sites:

Mozilla has reacted to a Symantec report issued on Monday which said serious vulnerabilities were being found in Mozilla's browsers faster than in Microsoft's Internet Explorer. The study was conducted over the first six months of 2005.

Tristan Nitot, president of Mozilla Europe, hit back by claiming on Monday that when a vulnerability is found Mozilla's "ability to react, find a solution and put it into the user's hands is better than Microsoft."

He also argued that, according to security company Secunia's statistics, the Microsoft vulnerabilities were more critical, and had been so over a longer timescale. In the period 2003 to 2005 Secunia have issued 22 security advisories regarding Firefox 1.x, and rate it as "less critical". In the same period Microsoft Internet Explorer 6.x had 85 Secunia advisories, and is rated as "highly critical".

Nitot likened the differences between Firefox and IE vulnerabilities as being like injuries: "Which would you prefer, to have a broken finger, or your head ripped off?"

Source: ZDNet UK

#317363

Hey Chris... yea... I read them as well.

The Symantec report was only taking into account the number, not severity of the vulnerabilities.

Trust me... I'll take the "broken finger" any day.

Although I do think his analogy is a bit extreme.

#317365

The analogy is definitely extreme, but hilarious none-the-less.

However I also think that the numbers don't matter unless you look at what they are related to. For instance, let's say Laptop Maker A has issued different recalls on 50 various products because the plastic was manufactured incorrectly and the casing could break, damaging the computer. Now let's say Laptop Maker B has issued different recalls on only 4 various products because the battery was manufactured incorrectly and could possibly explode (this seems to happen a lot lately). I'd much rather have a laptop from A than B in that case.

Also, code base and open source play a big deal in this. If IE was open source, can you even imagine the amount of flaws that would be found? Security companies and programmers alike would rip through IE, finding every possible bug. And while it's not exactly the same, if you were to compare the security issues in Win 95 and XP, that's unfair. While they are both operating systems, they aren't equal. They have different code base and are just two different pieces of software, even though they both accomplish roughly the same thing.

#317366

I would actualy be afraid to dig into the IE 6 source code.

I'm a beta tester for IE 7 and M$ have definately done some house cleaning.

The installer, when extracted, has a foot print of less than 25 MB. That's including the system dll's that would need to be replaced for full OS integration. Actual download is like 10MB, much smaller than the IE 6 install package of close to 40MB.

Let's hope they finaly take the Apple approach and sacrafice some backward compatibility for security.

So far it's looking pretty good... so far anyway.

#317368

Any future vulnerabilities in OSX will not come from a platform switch to Intel. Not directly anyway.

The CPU has nothing to do with an OS's ability to be exploited.

It may have an indirect impact, where increased popularity raises it to a level where hackers will feel it worthy of focusing their attention on it, but only time will tell that story.

I prefer to use Firefox myself and am still doing so as I write this, but I knew it was only a matter of time before it would attract the eye's of hackers.

Come on man, I meant that the problem would be brought by the popularity Intel would bring to Apple systems, no technical reasons mentioned... I'm not dumb. That looked like showing off...

#317389

So one day, I was thinking about these vulnerabilities, and I remembered I was using Safari. ^_^

// Lou

#317418

So one day I was thinking about the fact that Lou doesn't know who I am or where I live, therefore I could be his next door neighbor and throw eggs at his house :P.

Stupid Mac users! I'm better than you are. Say it with me...Windows users are better than Mac users. Again. And again. Deep breath...let out. One last time.

:P

-NC

#317435