Categorized | Internet Security

What is more secure – IE or Firefox?

While surfing the internet, I suddenly landed on a link where I found a very interesting article, by Jeff Jones, about “BROWSER VULNERABILITY ANALYSIS OF INTERNET EXPLORER AND FIREFOX”. Although the article is pretty old (2007) but yes its very interesting and worth reading. I am posting a few excerpts from the article.

BROWSER VULNERABILITY ANALYSIS

OF INTERNET EXPLORER AND FIREFOX

Published on: November 27, 2007

Written By: Jeff Jones

Blog: http://blogs.csoonline.com/blog/jeff_jones

Mozilla released Firefox 1.0 in November 2004 and has subsequently released Firefox 1.5 and Firefox 2.0. These three versions make up the supported Firefox versions in the three years from November 2004 to October 2007. The time period covered in this report is through the end of October 2007. In that same timeframe, Microsoft has supported Internet Explorer 5.01 SP3 and SP4, Internet Explorer 6.0 Gold, SP1, SP2, and Windows Server 2003 edition, plus Internet Explorer 7.

Since the release of Firefox 1.0 in November 2004, Mozilla has fixed 199 vulnerabilities in supported Firefox products – 75 HIGH severity, 100 MEDIUM severity and 24 LOW severity. In the same timeframe, Microsoft has fixed 87 total vulnerabilities affecting all supported versions of Internet Explorer – 54 HIGH severity, 28 MEDIUM severity, and 5 LOW severity.

clip_image002

Significant differences in lifecycle support policies between the vendors that have potential security implications. Mozilla released Firefox 1.0 in November 2004, Firefox 1.5 in November 2005, and Firefox 2.0 in October 2006. Only Firefox 2.0 is currently supported with security fixes from Mozilla, as it is has been Mozilla’s policy to support a previous version for six months after a new (major) version is released. So, according to its original schedule, Firefox 3.0 was scheduled to ship in November 2007, which meant Firefox 2.0 support would end in May 2008. While a revised schedule has not officially been announced by Mozilla, they have announced that three Beta releases are planned and the current estimate for Firefox 3.0 is “early 2008.

To put this in perspective, if Microsoft had this same policy, then support of Internet Explorer 6 would have ended in May 2007, or similarly Internet Explorer 5.01 support would have ended in 2001. In contrast, Microsoft generally releases a browser in conjunction with a new operating system release and commits to supporting that version for the lifecycle of the product – now 10 years for business products. Major versions do have service packs and the Microsoft policy is to support a previous service pack for at least one year after a new service pack is released.

Microsoft released Internet Explorer 6 for Windows XP SP2 in August 2004 and Internet Explorer 7 in October 2006 (for Windows XP SP2 – Internet Explorer 7 Vista released with Windows Vista in November 2007). Both versions of Internet Explorer are currently supported by Microsoft. Below figure shows a timeline of browser releases since November 2004, along with end of life for those products no longer in support.

clip_image004

Although not shown in the diagram, Internet Explorer 5.01 SP4 is also still supported for those Windows 2000 users that have made the decision never to upgrade their browser to a different release. One key factor of lifecycle is simply the fact that “unsupported” versions of products don’t get patches developed for them. This is equally true for all vendors, but shorter lifecycles mean more people may still be running an unsupported version and be exposed. To explain this comment, take a look at an example using Microsoft IE6 SP2. Imagine that after IE7 was released last October that one month later support for IE6 would end. How likely is that everyone will have upgraded by the end of that month? What if it was six months? Isn’t it likely that some consumers or companies might not have upgraded to the newer version by the end of the six month grace period?

I would suggest that you read the complete article because; I have posted very little here (just a few interesting details). For those of you, who really want to read the complete article, please refer to the below link:

http://blogs.technet.com/security/attachment/2594822.ashx

> Up-to-date information can be found @

http://blogs.csoonline.com/scrutiny_of_mozilla_security_claims

View full post on .:: Malware Info ::.

Related Posts
  • Dell launches super secure version of Firefox
    Dell has launched a virtualised version of Mozilla's Firefox web browser, which is designed to keep PC users safe when surfing the web. View full post on Network World on Security...
  • Browser Updates
    Just a few days ago, two major web browsers have been updated to fix security vulnerabilities which may allow attackers to infect the computer with malware just by visiting a hacked website.Google rel...
  • Firefox 4 gets its first security update
    Yesterday, five weeks after shipping Firefox 4, the Mozilla project published the new browser's first-ever security update. The Firefox version number bumps up to 4.0.1.The update fixes 50-odd bugs in...
  • Search Engine Security available for Firefox Mobile
    While the number of threats targeting mobile devices is increasing, web browsers for mobile devices are still lacking the security features of their Desktop counterparts. For example, Firefox 4 Mobile...
  • Google Image Poisoning Leads to Exploit
    Google search results have traditionally been the target of black hat SEO campaigns. WebsenseR Security LabsT has identified a new trend in which cyber criminals take advantage of Googl...
  • Make your old add-ons work with Firefox 4.0
    Every major release of Firefox brings the joy of great new features, along with the frustration of having plenty of add-ons that no longer work. Fortunately, it's quite easy to get most add-ons to wor...
  • Many Updates: Flash Player, Mac OS X, Firefox
    Today is a busy day for those who want to keep their computers secure: Many updates are available, from Adobes Flash Player over Apples Mac OS X operating system to the Firefox webbrowser. There is a ...
  • Mozilla Firefox 4 just arrived: where is Electrolysis?
    Yesterday the long awaited fourth version of Mozilla Firefox was publicly released and the Mozilla download counter already hit more than six millions of downloads in less than 24 hours. Mozilla Fire...
  • New fake AV page uses Firefox internals
    Most Fake AV pages mimic a Windows Desktop application running. In addition, the Fake AV pages have generally been the same regardless of which browser they are viewed. I recently found a new type o...
  • Saving login details in Firefox without notification
    Changing some code in Firefox to make it store passwords without notification isn't a particularly new trick; indeed, code to do just that has been around since at least 2009. What's interesting is th...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
5 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
5 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
5 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
5 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
5 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
5 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
5 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
5 months ago
Some free-based music we play at work http://t.co/xu5agZfc
5 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
5 months ago