Mozilla: Firefox antiphishing tool better than IE7's
IDG News Service - Mozilla Corp. fired a shot back at Microsoft Corp. in the browser war's latest battle this week, using a company-sponsored study to claim that the antiphishing filter in Firefox 2 more accurately flags potential phishing attacks than the one in Internet Explorer 7.
The move comes after Microsoft in late September released its own data based on tests by an independent research group claiming that IE7's phishing filter is superior to competitive offerings, including those from Mozilla, McAfee Inc. and EarthLink Inc.
Mozilla tapped independent consulting firm SmartWare Consulting in Herndon, Va., to test the effectiveness of Firefox 2's Phishing Protection feature, the company said. According to Mozilla, SmartWare's testing found that Firefox's antiphishing feature is "more effective" than IE7's.
Out of a total of 1,040 sites, Firefox blocked 820 when running in local mode, with 78.85% accuracy, the study found. Local mode checks a list of known phishing URLs stored locally in the browser. When running through Ask Google, which can check URL phishing site lists that are updated online, Firefox 2 blocked 848 sites, for 81.5% accuracy.
When running in a mode with the antiphishing filter's autocheck turned off, IE7 blocked 16 phishing sites for 1.54% accuracy, according to Mozilla's study. With autocheck turned on, IE7 blocked 690 sites, with 66.35% accuracy.
Further, there were 243 instances where Firefox blocked sites and IE did not, and 117 instances where IE blocked sites but Firefox did not, the study found. There were 65 instances where neither browser's antiphishing filter blocked phishing URLs.
The comparison tests between Firefox 2 and IE7 were conducted over two weeks, from Oct. 19 to Nov. 11, using phishing URLs from a service called PhishTank via its public XML feed of phishing URLs. PhishTank is a service that allows community participants to submit and verify phishing URLs. For the test, the feed was downloaded once per hour, and any new phishing URLs found were added to the testing database.
The browsers were running on Windows XP machines, Mozilla said.
An overview of Mozilla's tests can be found on its Web site.
Microsoft's own analysis of how IE7's antiphishing filter stacks up against Mozilla and others was published on the company's IE7 team blog for the product. Microsoft used 3 Sharp LLC to conduct its study.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts