ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Enterprise open source Toolkit

Mozilla hits back at browser security claim

Tom Espiner ZDNet.co.uk

Published: 20 Sep 2005 13:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Mozilla has reacted to a Symantec report issued on Monday which said serious vulnerabilities were being found in Mozilla's browsers faster than in Microsoft's Internet Explorer. The study was conducted over the first six months of 2005.

Tristan Nitot, president of Mozilla Europe, hit back by claiming on Monday that when a vulnerability is found Mozilla's "ability to react, find a solution and put it into the user's hands is better than Microsoft."

Nitot said that Mozilla's reaction time was faster than Microsoft's. "If you look at our ability to respond, we are in much better shape. On 6 September an IDN buffer issue was reported to Mozilla. On 8 September it was publicly disclosed. We ask our developers not to mention any problems until we have a fix for them, but for some reason he went public. On 9 September we had a configuration change that disabled the IDN problem, that users could implement manually, or they could use a patch. Within ten days we had a newer version that was fixed completely."

"If you look at Microsoft — this month they decided to skip a security patch," so any vulnerabilities won't be addressed, according to Nitot. "That's not the kind of thing that happens with us," he said.

He also argued that, according to security company Secunia's statistics, the Microsoft vulnerabilities were more critical, and had been so over a longer timescale. In the period 2003 to 2005 Secunia have issued 22 security advisories regarding Firefox 1.x, and rate it as "less critical". In the same period Microsoft Internet Explorer 6.x had 85 Secunia advisories, and is rated as "highly critical".

"Basically their vulnerabilities are more critical. With Firefox — yeah, you have holes, but they're much less serious." Nitot likened the differences between Firefox and IE vulnerabilities as being like injuries: "Which would you prefer, to have a broken finger, or your head ripped off?"

Ollie Whitehouse, a researcher at Symantec, thought that the results were surprising but were due to a number of factors, primarily the short uptake time for Firefox and the fact that it was open source.

"Firstly, there has been a wide adoption of Firefox in a short space of time. More security researchers and people with more nefarious motives have been able to look at the code base. Secondly, as Firefox is open source more people have access to the code base, so they are free to look for bugs. IE is closed source, and so it's more difficult to access the code."

"Rogue Web sites find Firefox is quite difficult to exploit because it runs on a large number of platforms."

When asked to comment on Nitot's point about the short timeframe of the study, Whitehouse responded, "Up until now Firefox has had a lot less holes [than IE] — but it has had a wider adoption in the last six months. It will be interesting to see whether this is a blip, or whether the trend will continue."

"As Firefox becomes more popular, it becomes a more attractive target. People who have swapped [from IE to Firefox], even if this is a blip, should ask whether the assumption that Firefox is more secure than IE is valid anymore. They shouldn't just rely on changing their browser, but may think about having to look at a different configuration."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
93 out of 169 people found this useful


Full Talkback thread

25 comments

  1. Even if the two browsers had equally insecure code... Rich Steiner
  2. Let's not lose perspective here people. Even if Fi... Call Me Yo Daddy
  3. Im fine with Both Internet Explorer and Fire... Albert B
  4. What is this REALLY telling us? It tells us that... Thomas Corriher
  5. Remember: * Mozilla's core theme is Internet {brow... Cade Foster
  6. To Ollie Whitehouse: You have given us the answer... Arthur B.
  7. Symantec and Microsoft cannot be trusted. Muc... Michael Jennings
  8. What is this nonsense being spouted by a supp... Mike Read
  9. When you think about it, Symantec's entire busines... Anonymous
  10. You guys bashing Symantec about this are all... Anonymous
  11. We've heard this all before. They're trying t... Anonymous
  12. perhaps people should be fair when reporting vulne... Anonymous
  13. Obviously symantec has to point problems on Mozill... Ramprasad B
  14. Replying to Thomas Corriher above: Quote: " .... Joe Jones
  15. Opera8 has great security (see secunia.com) and si... Anonymous
  16. Last time I checked Firefox didn't automatically u... Anonymous
  17. Last time I checked Firefox didn't automatica... oldator
  18. Actually, Firefox DOES automatically update i... Omega Shenron
  19. As anyone thought that maybe Symantec's report is... Greg Pfister
  20. Is it any wonder many technologists view tech jour... Kevin Theobald
  21. firefox may fail to update itself, and won't give... Anonymous
  22. Security by Obscurity has been found to be frail.... Jerry Mcguire
  23. So they(mozilla) do agree that their browser are N... Anonymous
  24. What the hell is this symantec 'expert' talking ab... Anonymous
  25. The spammers with their popups are getting cl... Flash Sucks

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

SAP FI/CO, CAREER-HUNGRY SAP ANALYSTS - TOP LOCATIONS - LONDON BASE

SAP FI/CO career-hungry SAP Analysts required to work for a market leading FMCG in some of Europes sexiest locations. Based in London, you will be ...

Senior Sales Manager - Bristol - 50-60k base (Higher Education Sales)

Huxley Associates are looking for a Senior Sales Manger / Sales Director to work for our exclusive client based in North Somerset (Bristol) area. ...

SAP FICO - NORTH LONDON BASE

My client, a globally recognised media firm are currently on the lookout for a SAP Finance business analyst. You will be primarily based in Iver ...

Featured Talkback

Its the applications and device drivers that run on windows that cement its dominance. How many people would fork out hundreds of pounds for Vista if Linux ran all the software and kit they wanted to use.

By: pround

Read full story:
Windows' dominance stifles demand for Linux