Feeds

Firefox flaws make up 44% of all browser bugs?

But numbers game ignores the big picture

Top 5 reasons to deploy VMware with Tegile

Updated Firefox flaws accounted for nearly half (44 per cent) of all browser bugs in the first half of 2009 - according to a survey which fails to factor in the seriousness of browser flaws.

A study by web application security firm Cenzic makes a decent fist of providing an overview of server-side web, but blots its copy-book with a brief foray into commenting on browser bugs. Of the browser vulnerabilities mapped by Cenzic, Firefox racked up 44 per cent of the total, with Safari bugs making up a 35 per cent slice of the browser vulnerabilities. Internet Explorer was third, with 15 per cent, with Opera copping for six per cent.

Cenzic's one-paragraph treatment of browser security suggests the number of Safari bugs was mainly due to vulnerabilities reported in iPhone Safari, and not much else. In particular, Cenzic fails to mention that the seriousness of flaws and the availability of exploits has a big bearing on how comparatively safe a browser choice might turn out to be.

The majority of media reports on Cenzic's survey fail to make the point that counting vulnerabilities alone is a bit pointless.

"For a proper and fair comparison one needs to dig a lot deeper than just looking at the numbers," Thomas Kristensen, CTO on web security notification firm Secunia, told El Reg.

"Other factors need to be taken into account for a proper comparison; this includes the type of vulnerabilities and thus the underlying type of coding errors, the impact of the vulnerabilities, the time it takes the vendor to fix the reported vulnerabilities, how easy it is to update the software thus how quickly the users (learn about and is able to) apply the patches.

"One may also want to look at the general design of the product, the efforts invested in improving the code and conducting internal security reviews and quality assurance, the usability with regards to certain security related features, the handling of plug-ins (how easy is it to lure the user into installing untrusted plug-ins) and so on," Kristensen concludes.

Lars Ewe, CTO of Cenzic, responded to queries from El Reg by saying it will consider highlighting the severity levels of bugs in future versions of its study. Ewe added that Cenzic supports Firefox in its product, which he personally uses as a default browser, so there's anti-Mozilla agenda in its report and certainly no "finger pointing".

The release of Cenzic's report coincided with Firefox's fifth anniversary on Monday, though this is probably a slightly unfortunate coincidence. The vast majority of the 29-page study concentrates on server-side flaws, drawing on data from enterprise use of Cenzic's managed security assessment services and work by its security researchers.

This section of the report (pdf) is far more detailed.

Of 3100 reported vulnerabilities, an increase of over ten per cent, more than three in four (78 per cent) involved web vulnerabilities. Many web applications continue to be vulnerable to information leaks, cross site scripting (XSS), authentication flaws and session management problems. Flaws in commercial applications, SQL Injection, and XSS dominated the threat landscape surveyed by Cenzic. ®

Choosing a cloud hosting partner with confidence

More from The Register

next story
UNIX greybeards threaten Debian fork over systemd plan
'Veteran Unix Admins' fear desktop emphasis is betraying open source
Netscape Navigator - the browser that started it all - turns 20
It was 20 years ago today, Marc Andreeesen taught the band to play
Redmond top man Satya Nadella: 'Microsoft LOVES Linux'
Open-source 'love' fairly runneth over at cloud event
Chrome 38's new HTML tag support makes fatties FIT and SKINNIER
First browser to protect networks' bandwith using official spec
Admins! Never mind POODLE, there're NEW OpenSSL bugs to splat
Four new patches for open-source crypto libraries
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.