Symantec rethinks Firefox vs IE vulnerabilities

Hacking, cracking and bluejacking. Discussions on how to keep your stuff secure and private here.

Moderators: Andy, fac51, 117

Post Reply
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Symantec rethinks Firefox vs IE vulnerabilities

Post by fac51 »

Symantec has changed how it spells out Firefox and Internet Explorer browser vulnerabilities in reaction to complaints last September from

"How we did it before wasn't a fair comparison," said Oliver Friedrichs, the senior manager of Symantec's security response group. "It wasn't an apples to apples comparison."

Previously, Symantec's Internet Security Threat Report counted only vendor-confirmed bugs in the two browsers, which led to gripes from Firefox fans that the Internet Explorer tally was inaccurate, and too low.

In the newest report, which Symantec issued Tuesday, the Cupertino, Calif.-based security company has split the counts into two categories: vendor-confirmed and a combination of vendor- and non-vendor-confirmed flaws.

That gives the edge to IE in one tally, Firefox in the other.

In the last six months of 2005, Microsoft confirmed 12 vulnerabilities in Internet Explorer, down slightly from the 14 in the first half of last year. Firefox, however, sported 13 vendor-confirmed flaws, one more than IE, but also down from the 27 in the previous period.

In fact, when counting only vendor-confirmed bugs, Firefox appears to be significantly more vulnerable than IE over the last 18 months. During that period, the number of Firefox-admitted flaws easily topped 60. In the same period, IE posted fewer than half as many vendor-confirmed bugs.

Explaining the difference, Friedrichs said "In open source, more vulnerabilities will be acknowledged because of the transparency in development."

But the new counting methodology, which Friedrichs said was the "more accurate" of the two, combines all vulnerabilities, including those made public but not necessarily confirmed by the vendor.

In that count, IE comes out second-best: In the same six months, Firefox suffered from 17 total vulnerabilities, while IE had 24.


full story
Image
117
Lowly Janitor Guru
Posts: 12548
Joined: Sat Jun 14, 2003 12:23 pm
Location: a destination a little up the road

Post by 117 »

hehe was just reading the same story :P
Image
Image
User avatar
fac51
Gaming Guru
Posts: 14526
Joined: Sat Jun 14, 2003 11:00 am
Location: Rapture
Contact:

Post by fac51 »

At least they're being honest now. we all knew when they said Firefox was more insecure than IE there was a lot they hadn't taken into consideration.
Image
Post Reply