Sunday | 23 November, 2008
Symantec report sparks safe-browser debate
Todd R. Weiss 21/09/2005 11:58:28

In its latest Internet Security Threat Report, released Monday, security vendor Symantec noted that in the first six months of 2005, the open-source Firefox Web browser had more confirmed vulnerabilities than Microsoft's Internet Explorer browser. So does that mean that the Mozilla-based browser is less secure than proponents have said and that Internet Explorer is more secure than believed?

Not exactly, according to security experts.

Symantec reported that during the first half of 2005, 25 vendor-confirmed vulnerabilities were disclosed for Mozilla browsers, including 18 that were classified as highly severe. During the same six-month period, 13 vendor-confirmed vulnerabilities were disclosed for Internet Explorer, eight of which were considered highly severe.

But that's not the whole story, said Vincent Weafer, senior director of Symantec's Security Response Team. Even though more confirmed vulnerabilities were reported for Mozilla browsers, he said, the widespread use of Internet Explorer means that whatever vulnerabilities affect it have the potential to affect a much larger user base.

"No technology by itself is safer," Weafer said. "It really is about securing it all to the max. None of them are immune to attack."

Internet Explorer has been a target of hackers for many years as the most widely used Web browser worldwide, he said, meaning it has been attacked so many times that the easiest-to-target flaws have already been uncovered. That makes it harder for hackers to find and take advantage of vulnerabilities.

With the recent popularity of Firefox, hackers are beginning to go after it in larger numbers in an effort to uncover -- and exploit -- any vulnerabilities, he said.

Mike Schroepfer, director of engineering for the Mozilla open-source project, which develops the Firefox browser, questioned the Symantec numbers.

"Vendors tend to report vulnerabilities differently," Schroepfer said. Microsoft tends to group several confirmed vulnerabilities together in one announcement and patch, whereas Mozilla announces each confirmed vulnerability individually. That skews the number of confirmed vulnerabilities.

Other security monitoring companies, such as Secunia show different results, he said. Recent Secunia vulnerability reports show 19 unpatched Internet Explorer 6 vulnerabilities, compared to three unpatched Firefox 1.0 vulnerabilities, he said.

"In general, we still believe Firefox is the safest browser around," he said. In addition, the open-source development model used for Mozilla allows vulnerabilities to be found and fixed much faster, making it easier to patch. "It speeds the time when we discover and patch these vulnerabilities, which I think is more important."

Analyst Pete Lindstrom, of Spire Security said the arguments over the number of vulnerabilities in the competing products is overrated.

"The whole game we play about counting vulnerabilities is kind of silly to begin with," Lindstrom said. "The entire security industry ought to be slapped on the wrist for saying Firefox was more secure than IE about a year ago" because Firefox wasn't out long enough to prove its stealth and hackers hadn't yet had enough time to attack it.

"Firefox and every application that receives some sets of information can also be attacked" successfully by hackers, Lindstrom said. Users need to take the approach that every single application must be properly configured for defense. "If someone wants to, they can protect their applications," he said, though it costs money and takes time to do it properly.

Symantec's semiannual Internet Security Threat Report covers Internet threat data from Jan. 1 to June 30, 2005, according to the security and maintenance software vendor. The report provides analysis of network-based attacks, a review of known vulnerabilities and highlights of malicious code and additional security risks.

More about Symantec, Microsoft, Spire
Related Features
  • +

    9 Paths to Higher Performance 10/12/2007 14:09:23

    When an organization brings together talented people in a creative, collaborative environment it fosters a culture of high performance, which in turn leads to superior business results
    Like high-achieving individuals, some organizations seem to have the Midas touch. Virtually every initiative they touch earns them gold and even those that fail never seem to cost them much of anything at all
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Achieving the impossible: Unlimited application scalability

Learn how provide applications with significantly higher throughput and lower latency for data operations while retaining the appropriate levels of data quality with clustered caching. Read on to improve your application scalability now.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links