Skip to navigation
   
Simon Bisson & Mary Branscombe's Blog

Internet Explorer has fewer security holes than Firefox

By Simon Bisson & Mary Branscombe in Editorial

Posted in Web browser, Firefox, Security, Internet, Microsoft on December 4, 2007 at 7:02 pm

Permalink | Author Profile

You type most of your passwords into it - and you type your credit card details into it every time you shop online. It’s how you unlock an iPhone so you can install applications on it. It’s the home of many of your applications and it’s the first avenue of attack for most malware. Really, if you wanted to be secure, you might never use a Web browser again.

You don’t have to be a hacker in the criminal sense to want to get around some security lockdowns. The latest iPhone cracker uses an image security issue in the Safari browser to open the system up. If you have a Buffalo NAS box you can use a security hole in the Web administration interface to make yourself root to install Perl so you can run SlimServer and get music onto your Squeezebox. I’d like to run SlimServer on something other than our main server - but I’m not cracking the security on our backup and media store to do it.

I’ve never switched away from IE to Firefox; originally it was because I had to have IE on my system for work and didn’t want the hassle of managing two browsers. Since IE 7 came out and I found IE 7 Pro I just haven’t bothered. It’s not perfect, but it’s good enough for me. Given that it took me five hours of browsing dubious sites and downloading known spyware to infect a machine running XP SP2 when I tried a few years ago, and given that everything that interested me in Firefox turned out to be Greasemonkey scripts (and I’m probably unfair to carry on thinking of that as a security problem waiting to happen, but I do), I’ve been assuming the security (dis)honours are about equal.

Jeff Jones at Microsoft has done another vulnerability survey, this time for IE and Firefox. Since Firefox 1.0 came out in November 2004, Mozilla has patched a total of 199 bugs: 75 high severity, 100 medium severity, 24 low severity. Microsoft has only patched 87 IE bugs in the same time (and we’re assuming fewer bugs patched is a good thing rather than avoiding the problem): 54 high, 28 medium and 5 low severity. Honours are more equal comparing just Firefox 2 and IE 7 for known bugs that haven’t been fixed: eight high severity bugs for Firefox versus ten for IE, 15 medium severity bugs

12345
Not yet rated
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments
This article has no comments yet.

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

outlook offload appstore magic microsoft security essentials android accelerator RBL MING hyper-v switch multiple monitors virtual desktop Firefox Netscan smartphone flash advertising monitor verdana mobile data tariffs IIW2008b spam geotagging Dell upgrade pixetell Visual Studio apps BitLocker Frauenhofer data tariff Active Directory anti-virus safend CUDA london Vista user interface search data centre transformation optical interconnects legislation co-processor Jeff Hawkins Tripit amherst mobile ofcom network gamer Google Spreadsheets mobile broadband electricity price ec2 3G microsoft research national museum of computing identity metasystem Vodafone DOS Opsware BT Express Gate terabytes high performance computing appzero Tablet PC Volume Shadow Copy pre-boot HP Beacon media center acquisitions GPL hard drive demo09 cloud service google online applications mobile working education GPU Verbatim CES fingerprint scanner developer Magny-Cours 965 business model distributed computing T-Mobile power saving mainframe vmware biometrics Mark Hurd p2v wildfire SKU CPU macro it pro quiz bombe ATI browser turing collaboration networks mobility Quest iPhone IT policy spam fighting FUD gaming security paradox fonts RIA Clear RX oracle Qualcomm analytics Bing TouchSmart natural interface OFCOM semiotics OpenID mms 2009 hibernation firewall disk space TechEd 2008 LHC Windows Live Large Hadron Collider data loss windows server 2008 r2 Google Opteron mash-up relocation wubi politics data centre interoperability futura how do I get the back off? phone management Ask.com Delphi IO traffic Credentica mobile Linux designer rtm claims SSD Corsair Asus beta test OEM Dopplr Mini-Note phone settings navteq O'Reilly i-mate pen computing Reqall Barracuda NexT CERN 2009 Bill Cheswick social engineering Istanbul Lenovo cloud management Hugh Thompson web 2.0 expo SMB 2 exchange bandwidth Girl Geek Dinners culture emulator html HTC case catalyst routing web history images enterprise Trend Micro deborah adler .NET system management Ray Ozzie system center connectivity Ruby Nuance Embarcadero old software support Chrome office politics MIX Linux EEE M&A ballmerbot HSDPA AMD patent business technology optimisation clean install business continuity bug laptop DLP media market share keyboard tennis voice recognition encryption EMC credit crunch enterprise architecture HMT social networking CardSpace lost server cold fusion Internet Explorer g-2 d2c legacy troubleshooting information cards Mercury Microsoft NGSCB email icons venture capital migration Acrobat Pro trends privacy MWC codec Xen city Wyse T9 training control panel RIM tablet IT transformation beta project citrix Web 2.0 ubuntu calit2 Motorola ipsec ANR colossus AIR no signal rich client streaming media office innovation TSA NAS instant messaging workflow Intel RAZR Jeff Jones ruggedized anti-patterns green IT Loki wave bolt SP1 Enterprise 2.0 evernote MRDA database Protected View Apple identity theft LiveID 2.0 installation AuthenTec disaster recovery IM design MAX BBC competition patch Tuesday business intelligence Opera IT value geocaching data netiquette windows 7 Toshiba Portege R500 Tablet Kiosk Location ultraportable open wes ikea mapping netbook augmented reality power supply Gears cellcrypt flex Internet Explorer 8 machine learning Itanium Windows Server 2008 telecoms Safari accessories Trampoline office 2010 malware hdmi Google Sets Nokia vulnerabilities public cloud remove back application compatibility service oriented enterprise cisco visualisation DOSBox future in review flash drive network security secure people battery life direct access merger IBM CIO october ontier cloud computing forensics DSL data loss prevention software green printing international roaming storage deperimeterization radeon wireless USB Treo Pro Google IO gameboard ipv6 Internet AskEraser target regulations security theatre drivers server information productivity isps geneva mobile thin client setup desktop. PC anti-trust yahoo conference windows open source WPF SBS Trolltech MacBook Air etech Live Mesh mobile network thermo Ruby On Rails consolidation bletchley park rc regulation g-1 Eee PC virtualisation identitity disk IDF sun Wimbledon UMPC winhec2008 RSS search screencam Gartner docking station hacking SapphireSteel DisplayLink GPS VSSAdmin CTO Xobni HTML 5 lockdown HSPA WinHEC dual boot utilities Salesforce WWW Previous Versions installer greenplum dvi moscow active digitiser timezones ports private cloud cracking Palladium dual display 64-bit Mono fingerprint video todo list meaning development backhaul MIX08 Netscape demo server sprawl numbers maps toshiba teched Seagate transcoding conferences Secunia Pal utility annotation pgp Skyfire lawsuit Windows Server fault task bar ribbon NVIDIA Tim Berners-Lee hardware robot fibre context Numenta Fire Eagle BlackBerry Tombstone Objects applications business Mozilla community parallel computing power cuts atom Facebook police BES aws business technology automation Sony Crossfader Windows 7 vs Windows Vista camera fire QWERTY ProCurve Moonlight moblin OQO Windows Mobile logitech information rights management congestion charge gabriola WEI downturn nvision08 infrastructure geek tourism Smartbook Greasemoneky macbook navigation Palm mysql bbc iplayer O2 virus cam uninstall screen ClipMate mscape tele atlas voice user experience benchmark isp Silverlight insert SIM hp microsoft research adfs Adobe Tom Hogan netbooks processors webkit hierarchical temporal memory bugs Bill Gates wifi power RSA 2008 web2expo xT9 twitter performance exabytes christmas eu hold music IT automation griffin ADFS 2.0 usb ucsd mythbusters MacWorld 2008 licensing amazon display bea whitelist cosmic rays goview Hp 2710p cables iPass Java
Advertisement
Advertisement