Skip the navigation
News

Update: Microsoft, Mozilla trade punches over browser security

IE has fewer bugs, says Microsoft; we patch Firefox faster, counters Mozilla

By Gregg Keizer
December 5, 2007 12:00 PM ET

Computerworld - The feud between Microsoft Corp. and Mozilla Corp. over whose Web browser is more secure heated up again as officials for both companies trotted out statistics to show their application is safer.

Jeff Jones, the strategy director in Microsoft's security technology unit, started the latest bug count battle last Friday, when he posted a report (download PDF) that claimed Microsoft Corp.'s Internet Explorer had been affected by fewer than half as many vulnerabilities in the last three years as Mozilla's Firefox had.

"Over the past three years, supported versions of Internet Explorer have experienced fewer vulnerabilities and fewer High severity vulnerabilities than Firefox," said Jones in the report, "a result that stands in contrast to early assertions by Mozilla that Firefox 'won't harbor nearly as many security flaws as those [in] Microsoft's Internet Explorer.'"

Jones counted 199 Firefox bugs that Mozilla has quashed since November 2004: 75 ranked "High" in severity, 100 rated "Medium" and 24 were "Low." In the same period, Microsoft fixed 87 total vulnerabilities: 54 High, 28 Medium and five Low.

He also tallied flaws that have been fixed for the newest versions of each browser -- IE 7 and Firefox 2.0 -- and again concluded that Microsoft's browser is better, although Jones acknowledged that Mozilla, like Microsoft, had improved the security of its application.

Mozilla wasted little time firing back. "When you compare how long it takes Microsoft to fix Internet Explorer vulnerabilities versus how long it takes Mozilla to fix vulnerabilities in Firefox, it becomes clear why he chose to count vulnerabilities in this report instead," Window Snyder, who heads Mozilla's security efforts, charged last week in a blog posting of her own.

Others from the open-source developer chimed in. Mike Shaver, Mozilla's chief evangelist, called Jones' logic baffling. "Jeff is saying that Mozilla's products are less secure than Microsoft's because Mozilla fixed more bugs," said Shaver. "By that measure, IE4 is even more secure, because there were no security bugs fixed in that time frame. Microsoft should be embarrassed to be associated with this sort of ridiculous 'analysis.'"

Mike Schroepfer, Mozilla's vice president of engineering, also took Microsoft to the woodshed, first criticizing the vendor for not providing a public bug database so that Jones' numbers could be verified, then discounting the figures entirely. "Bug counts are meaningless; what matters is whether you are at risk or not," Schroepfer said.

In a telephone interview, Snyder ran with that line of reasoning. "Microsoft only counts the vulnerabilities that have been reported externally," she said, and it doesn't include in its total those found by its own engineers or by penetration testers it hires to hammer on its software. Those bugs, said Snyder -- who once worked at Microsoft as a security strategist and was responsible for signing off on the security aspects of Windows XP SP2 -- are patched in the less-frequently-released service packs or major updates.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Web 2.0 and Web Apps White Papers
Why Business Ethernet Services?
Everybody's heard the cliché, "the network is your business." But that's not going to help you choose the best wide area networking service...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Web 2.0 and Web Apps White Papers
Web 2.0 and Web Apps Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Web 2.0 and Web Apps Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs