Is Firefox the Most Secure Web Browser?--Part 3

Microsoft's Jeff Jones discusses Mozilla's Mike Shaver's point that "You Can Only Count What The Vendor Wants You to See."

By
Wed, February 04, 2009

CIO — [FULL DISCLOSURE: In addition to being a 20-year Security Guy, I work for Microsoft. While I try hard to focus on objective data, go ahead and assume bias, if you wish, and challenge my analysis with your own comments—you'll be helping me fulfill my goal of ensuring all sides of security claims are thoroughly examined and rigorously debated in the public view.]

I encourage you to read Part 1 and Part 2 of this series for background and context. As I discussed in Part 1, I challenged Mozilla claims that Firefox "won't harbor nearly as many security flaws as those that have Microsoft's Internet Explor" with an Internet Explorer and Firefox Vulnerability Analysis, which resulted in rebuttal from Mozilla's Mike Shaver (please do read it, so you have his viewpoint).

My main issue with the rebuttal is that rather than address the issue of software vulnerabilities and acknowledging that Writing Secure Code is hard (for everybody in the industry), it takes the approach of changing topics to redirect the conversation away from Firefox and towards Microsoft, asserting that my analysis of security flaws is a poor measure of security. Of course, that ignores the fact that it is a really good measure of specific claims about having low numbers of vulnerabilities.

I still think the issues raised should receive a vigorous and open discussion, today I will dig into one of the two main points raised by Shaver: "You Can Only Count What The Vendor Wants You to See."

You Can Only Count What the Vendor Wants You to See

Rather, I would say you can count everything that gets disclosed in a broad and public way, by security researchers or vendors. This is at the heart of the theory of Full Disclosure and I am comfortable asserting that most vulnerabilities across the industry in open and closed source models are disclosed by someone other than the vendor or development teams. Vendors do disclose issues, but it is typically a small percentage of the overall set of vulnerabilities.

If that's true, why is this issue even raised? Probably because of the issue of so-called "silent fixes" and because this was a hotly debated concern a few months before my analysis was released. After studying the discussions quite a bit, I see this as another incarnation of the various interpretations of Full Disclosure and a continuation of the debate between differing camps:

  • (position one) Full disclosure requires that full details of a security vulnerability are disclosed to the public, including details of the vulnerability and how to detect and exploit it.
  • (position two) The disclosure process and what information is disclosed should be guided by the best efforts to minimize overall risk to users. I lump the "disclose the minimum" crowd in here too.

Continue Reading

Backup is one of the most frequently performed storage tasks; however, the perceived level of cost and complexity is rising dramatically for an activity that has been in practice for many decades. This Gartner research sponsored by HP + Intel details the challenges associated with the current state of backup and recovery, and presents the top best practices for improving the backup process.
This online eBook provides insight and advice on how to build an effective disaster recovery strategy in the evolving world of virtual infrastructures, while mitigating the impact of so-called 'Black Swan' events in the datacenter. Practical, how-to best practices, real customer success testimonials and links to additional resources.
This report outlines five trends that enterprises are architecting to better equip their DR solutions today including: secondary site configuration and separation, cloud recovery, tiers of applications and causes of disasters.
This paper breaks down attack sources into four categories: external, malicious insiders, accidental insiders, and unknown.
This paper covers power utilization, intelligent power management and industry best practices for energy efficiency. Extreme Networks® takes a lifecycle approach to power efficiency, management and recycling, offering savings to our customers and promoting a greener world.
With increasing data growth, comes increased need for data security.  The existing DLP model, with a focus on compliance/enforcement is not sufficient as the data discovery and classification capabilities are not granular enough.  Read this paper to find how you can efficiently and accurately manage your risk by rapidly inventorying and classifying your data and then developing remediation workflows that support business needs. 
A simple, cost-effective disaster-recovery solution for virtual environments is high on the agenda for IT organizations as they virtualize more business-critical applications with VMware. VMware vCenter™ Site Recovery Manager-the market-leading disaster-recovery product-ensures the simplest and most reliable disaster protection for all virtualized applications. VMware vCenter Site Recovery Manager provides centralized management of recovery plans, enables nondisruptive testing and automates site-failover processes.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Virtualizing business-critical applications is an essential step in your journey to the cloud. Microsoft SQL Server, Exchange and SharePoint, and Oracle applications, are often the backbone of business IT. The benefits of virtualizing these applications extend far beyond mere consolidation. Understanding how VMware improves quality of service and agility while reducing costs will help you make the case for taking virtualization to the next level in your company.
Applications are changing - they're increasingly web-oriented, global in nature and run from multiple device types. Additionally, the volume of data is growing exponentially every year. How do you ensure your applications have fast, accurate, up-to-date information in this new world? Modern applications are data-intensive; delivering data the old way using monolithic databases isn't working. What's needed is a modern approach to data. One that scales-out as needed and delivers predictable high performance, but without sacrificing data consistency or integrity.
Real-time, global data updates have become a critical business requirement for financial-services firms. Overnight or hourly batch jobs can cause erroneous results and missed opportunities. New regulatory requirements dictate real-time reporting of liquidity; traders want access to real-time market and risk positions; and the time windows for relevancy of cross-selling and marketing opportunities are getting shorter. To deal with these issues and new requirements, firms need to be able to react quickly to changes in data. Quick reactions require near-instant access to data, risk analysis and deeper computational analysis for effective decision making. View this webcast to learn how to achieve real-time awareness by managing ever-increasing data volumes and transaction rates.
This video webcast is designed to help those with little to no virtualization experience understand why virtualization and VMware are so important to driving down both capital and operational costs. The session will start with the introduction of the key concepts and technologies of virtualization, introduce the vSphere Hypervisor, and build up to an overview of VMware vSphere® 5, the world's most robust and complete virtualization platform. This session will also discuss new solutions such as the vSphere Storage Appliance and VMware GO that are making it easier than ever before to get started with virtualization.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center