internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
Ad-Aware 2008 Free
Internet Explorer 7
QuickTime for Windows
Paint Shop Pro
Mozilla Firefox Portable Edition 3
AVG Anti-Virus Free
Windows XP Service Pack 3
Ashampoo WinOptimizer
Adobe Flash Player
Windows Live Suite

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Security Debate Centers on Firefox And IE
Advocates of Top Two Browsers Spar Over Security
Sean Michael Kerner

Microsoft Internet Explorer developer Dave Massy responded to a Mozilla Foundation claim that Firefox will "always" be more secure.

On a blog post today, Massy referenced reported comments made by Mozilla Foundation chair Mitchell Baker two days ago.

"Mitchell Baker, president and chief lizard wrangler of the Mozilla Foundation, is quoted as saying Mozilla is and always will be more secure than IE," Massy wrote.

One reason Mozilla claims it will always be more secure is related to the fact that it is separate from the operating system, as opposed to IE, which is tightly integrated.

"The issue of not being part of the operating system is an interesting one, though that is frequently the subject of misunderstanding," Massy blogged. "IE is part of the Windows operating system so that parts of the OS and other applications can rely on the functionality and APIs being present. IE in turn relies on operating system functionality to do its job."

Massy argues that since the operating system APIs (define) that are used by IE are all part of the platform SDK (define) and are all documented by the Microsoft Developer Network (MSDN), they are also available to any other software that will run on the Windows OS.

"The security of any browser is irrelevant if it is part of the operating system," Massy states. "If we are to debate the security of browsers then let's bring in relevant arguments and accurate details about different possible attacks rather than rely on the irrational fear that because IE is part of the operating system it must be exposing OS functionality to the Web."

"This is not the case, as any software has access to the same set of OS APIs and can therefore expose the same set of OS functionality as IE," Massy added.

Security experts queried by internetnews.com, however, were not as definitive about the lack of risk posed by IE due to its tighter OS integration.

Ioana Spiridonica, spokesperson for European software vendor BitDefender, disputes Massy's assertion.

"The argument presented in the blog — 'any software has access to the same set of OS APIs and can therefore expose the same set of OS functionality as IE' brings the man's whole argumentation down," Spiridonica told internetnews.com. "Because unlike IE, although Firefox has access to those APIs, it does not expose them to the Web like IE does."

Patrick Hinojosa, CTO of security vendor Panda Software, however, doesn't think the fact that Mozilla Firefox is "separate" from the Windows OS necessarily shields it better from threats than IE.

"I do think that an exploited vulnerability in IE could have more serious ramifications for the system as a whole because of the tight integration," Hinojosa told internetnews.com. "The distinction is important because, given the same vulnerability in IE and Firefox, you might end up with different bad effects on the rest of the system. It is probable that this would be worse in favor of IE."

In October, IE got an unexpected endorsement from a security researcher who noted that IE was more secure than its alternative counterparts in certain respects.

With Firefox popularity on the rise, however, Hinojosa asserts that there will be more malicious users searching for vulnerabilities to exploit in the upstart open source browser.

"I feel this will result in some lowering of security in the sense that holes will be found and exploited," Hinojosa explained. "The biggest area where Firefox is more secure is that it doesn't have the ability to run ActiveX. I know this is now turned off by default in the latest IE, but there are millions of users not using the latest version.

"So, for the time being, I feel Firefox delivers a better experience security-wise to the average user that is on the net."

A quick review of the current status of reported, but unpatched, vulnerabilities as listed by security vendor Secunia also shows the disparity between Firefox and IE.

For Firefox, which was just patched yesterday (v1.0.2), the security firm has four out of 13 advisories marked as unpatched. For IE, the number of unpatched is 20 out of a total of 79 advisories.

News courtesy of internetnews.com

March 25, 2005

Download Mozilla Firefox Now!Download

Download Internet Explorer Now!Download

View All Web Browsers

Contents:
1. Advocates of Top Two Browsers Spar Over Security


Additional Articles:

  • Microsoft Fights for Browser Plug-Ins
  • Zero-Day Exploit Targets IE Flaws
  • What Users Want in IE Upgrade
  • IE Drag-and-Drop Flaw Warning
  • IE Fights Back, Sort Of
  • Another Slide in IE's Market Share
  • IE 7.0: Missing the Search Boat?
  • IE Phishing Exploit Reported
  • New Internet Explorer Gets Tabs
  • IE COM Flaw Exposed
  • More CSS in IE 7, But Is It Enough?
  • IE7: Built for Feeds
  • IE Changes To Avoid Eolas IP
  • Security, Patent Tweaks For Internet Explorer
  • Hackers Attack ActiveX Flaw in IE




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

    Solutions
    Whitepapers and eBooks
    IBM eBook: Planning a Service Oriented Architecture
    IBM eBook: Choosing the Right Architecture--What It Means for You and Your Business
    Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
    Avaya Article: Using Intelligent Presence to Create Smarter Business Applications
    Intel Go Parallel Article: Getting Started with TBB on Windows
    Microsoft Article: 7.0, Microsoft's Lucky Version?
    Avaya Article: How to Feed Data into the Avaya Event Processor
    IBM Article: Developing a Software Policy for Your Organization
    Microsoft Article: Managing Virtual Machines with Microsoft System Center
    Intel Go Parallel Article: Intel Threading Tools and OpenMP
    HP eBook: Storage Networking , Part 1
    Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
    MORE WHITEPAPERS, EBOOKS, AND ARTICLES
    Webcasts
    HP Video: StorageWorks EVA4400 and Oracle
    HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
    Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
    MORE WEBCASTS, PODCASTS, AND VIDEOS
    Downloads and eKits
    Red Gate Download: SQL Toolbelt and free High-Performance SQL Code eBook
    Iron Speed Designer Application Generator
    MORE DOWNLOADS, EKITS, AND FREE TRIALS
    Tutorials and Demos
    Silverlight 2 App and Walkthrough: Leverage Silverlight 2 with SQL Server and XML
    IBM Article: Enterprise Search--Do You Know What's Out There?
    HP Demo: StorageWorks EVA4400
    Microsoft Article: The Progress and Promise of Deep Zoom
    Microsoft How-to Article: Get Going with Silverlight and Windows Live
    MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES