Mozilla Disputes Bit9's Claim That Firefox is "Most Vulnerable App"
December 18, 2008 8:43 AM
comment(s) - last by
Experts are taking issue to a recent study which warned users of potential risk of using Firefox
A recent security study from Bit9 argued that Mozilla's
Firefox was the most vulnerable application
and thus a major threat to businesses. One of the chief reasons it gave was the lack of a large-network patching system. For this reason, despite
recent security flaws
, it did not consider Microsoft's Internet Explorer software, as it assumed that such a patching system dramatically lowered vulnerability.
Bit9 went as far as to suggest that enterprises block their employees from having access to Firefox and delete it from work computers.
Some firms, including Mozilla, were quick to take issue with Bit9's alarming comments. Representatives from Mozilla's security branch, Human Shield contacted
with remarks on the topic. The company's Johnathan Nightingale states, "While we're always happy to see stories that focus on educating our users about security, there are some problems with Bit9's methodology that hinder its ability to draw any meaningful conclusions."
According to Mr. Nightingale, by raising the "risk" of companies which disclose critical vulnerabilities, Bit9's study punishes openness, a critical key to security. It rewards companies that keep their vulnerabilities secret, he argues.
He also criticizes Bit9's stance on patching, stating that the firm's claims fall short of reality. He states, "Bit9 seems to understand (the need for smarter metrics) in its focus on application support for updates, but again it fails to account for the real world experience. Firefox does not deliver WSUS updates, but our built-in update mechanism requires no user intervention, and we consistently see 90% adoption within six days of a new update being released."
He concludes, "The Firefox vulnerabilities Bit9 discusses are long-since fixed, with the majority of these fixes coming within days of it being announced. That is the real measure of application security: are known vulnerabilities fixed promptly, tested carefully, and deployed thoroughly? Bug counting is unfortunately common because it's easy, but it should not be a substitute for real security measurement."
Similar sentiments were also echoed by various readers on
as well as several sources in the security business. While the Bit9 study certainly takes a controversial and interesting position, according to many its claims are overly broad and flawed. Whether this is the case is largely a matter of opinion, but one thing's for sure -- whether you're on Firefox, Opera, Chrome, or Internet Explorer, security is largely in the
hands of the user
This article is over a month old, voting and posting comments is disabled
RE: Yeah, as the IE exploit raged wild for a few days ...
12/18/2008 4:03:23 PM
I still don't understand why companies don't use FF as their preferred browser. Except for those that do have IE6 apps. Other than that is sheer stupidity, IMHO
"It looks like the iPhone 4 might be their Vista, and I'm okay with that." -- Microsoft COO Kevin Turner
Critical Vulnerability In Internet Explorer Found, Patch on the Way
December 17, 2008, 12:50 PM
Firefox: Most Risky App to Businesses in New Study
December 12, 2008, 4:00 PM
Woman Succumbs to "Greed", Loses $400K USD to Nigerian Scammers
November 18, 2008, 8:31 AM
NSA Spying Won't Impact Huawei's Growth
April 23, 2014, 8:24 PM
Amazon, HBO Team up to Bring HBO Content to Prime Members
April 23, 2014, 11:36 AM
U.S. Wants to Reduce Tension Over Internet Net Neutrality
April 22, 2014, 2:07 PM
AT&T Announces Plans to Expand Ultra-Fast Fiber Internet Network to 100 Cities
April 22, 2014, 9:36 AM
AT&T Takes First Steps in Launching Its Own Online Video Service
April 22, 2014, 9:25 AM
Netflix Opposes Comcast/Time Warner Deal, Says It's Anti-Competitive
April 22, 2014, 8:52 AM
Most Popular Articles
A Bug's Life: Female Cave Bugs Have Penises, Penetrate Males for Three Days
April 17, 2014, 7:20 PM
HTC Hires Former Samsung Marketing Chief Who Developed "Galaxy" Brand
April 18, 2014, 6:00 PM
NASA Finds "Habitable Zone" Planet Sized Similar to Earth
April 18, 2014, 3:13 PM
Mounties Arrest 19-Year-Old Who Delayed Canada's Tax Filing w/ Heartbleed
April 17, 2014, 3:24 PM
Thanks to Government Crackdown, Chinese "Porn Cop" Has Watched 600K Adult Videos
April 21, 2014, 12:00 PM
Latest Blog Posts
Facebook Aims to Provide Internet to "Every Person in the World" with Drones, Satellites
Apr 1, 2014, 10:20 AM
Retail Mobile Sites Experience Outages in Light of Simplexity's Bankruptcy
Mar 14, 2014, 8:48 AM
Tesla vs. BMW: Who Has the Safer EV?
Feb 1, 2014, 2:56 PM
Justice Leaks Details of Next HTC One Two Flagship Phone
Dec 5, 2013, 4:04 PM
Global Cyber Espionage Concerns Reveal Growing Cyber Armies
Nov 29, 2013, 11:04 AM
More Blog Posts
Copyright 2014 DailyTech LLC. -
Terms, Conditions & Privacy Information