Technology Review - Published By MIT
Advertisement

TR Editors' blog

Insights, opinions, and our editors' analysis of the latest in emerging technologies.

Blog Topics

Recent Posts

Recent Comments

  • fiberman : How amusing. A contributor to the WSJ suggests eating your fellow man. Well, isn't that just what...
  • kstauff : I believe the deficit left by the Bush administration for fiscal '08 was around $500 billion. ...
  • kstauff : You're right, I overestimated the number of democrats in both houses, although I believe that the...
  • kstauff : Are you as angry at Roosevelt, Truman, Kennedy, Johnson and Clinton for the wars they prosecuted?...
  • kstauff : The Obama administration told us it would be 8% without the stimulus.  You tell me if he and his...
  • ... : Just to make it apparent, there's already a Chromium browser which uses the Chrome codebase for...
  • Adalast : people keep throwing around the "New Deal" and saying that it was horrible and didn't help our...
  • ... : All of these careful studies and delays in taking up a form of energy that is far superior to the...
  • Gary... :    While 10% unemployment is unacceptable, to say the stimulus did not help the employment...
  • skingw : History also tells us: too many human beings for too little resources --> great wars (killing a...
Advertisement
Thursday, September 21, 2006

Is Internet Explorer More Secure than Firefox?

A new model predicts that more vulnerabilities are to be found in Firefox than in Internet Explorer.
By Kate Greene

New research suggests that there are more flaws yet to be found in the current version of the Firefox web browser (version 1.5) than in the current version of Internet Explorer (version 6, and its updates). Furthermore, the researchers say, a larger proportion of Firefox's vulnerabilities are severe.

However, the researchers also determined that more vulnerabilities in Firefox are corrected with software patches than flaws in Internet Explorer, which could mitigate the effects, says computer scientist Yashwant K. Malaiya of Colorado State University and his team. The findings will be presented in November at the International Symposium on Software Reliability Engineering in Raleigh, NC.

The researchers' predictions are somewhat surprising, since Firefox is generally perceived to be more secure than Microsoft's Internet Explorer. Indeed, security is a popular reason why many people have switched over to the open-source browser in recent years. Firefox's market share almost tripled, from 4.6 percent to 12.9 percent, between November 2004 and July 2006.

But of course this increased popularity may be one reason why the number of detected flaws in Firefox has been increasing, says Malaiya. From November 2005 to July 2006, 73 vulnerabilities were found in Firefox, 33 of them critical. The number of vulnerabilities detected in Internet Explorer was smaller during a far longer period: from August 2001 to July 2006, it was 60, 15 of them critical.

To get a sense of the number of future vulnerabilities in the two Web browsers, the researchers applied a mathematical model that predicts the rate of detection. The model is based on previous data from software flaws found in operating systems and Web servers, and from earlier detected vulnerabilities in both Web browsers. Using the model, Malaiya and his team now project that Firefox will continue to have roughly 12.4 detected flaws per month, compared with Internet Explorer's projected 3.5. From the paper:

The available data suggests a higher number of new vulnerabilities can be expected in Firefox 1.5 compared with IE 6.x in the near future; they are also more likely to be of higher severity.

However, the paper adds, the process of finding flaws is only one piece of the security equation. The act of fixing the flaws is an important component--and this is where Firefox seems to have the edge over Internet Explorer. Again, from the paper:

Firefox developers are much better in developing patches with a significantly higher patch rate, thus significantly compensating for the higher vulnerability detection rate.

Malaiya and his team conclude that the evaluation of competing products needs to be repeated periodically so that the most recent data can be used to tweak their models and assess current and future risks.

Comments

  • Firefox game
    Have you ever thought about challenging browsers face to face? Now you can do it. Firetron 0.1 is new Firefox game – Try it! More information on: http://www.miscproject.com/blog/firefox-game-firetron/
    Rate this comment: 12345

    melon
    09/25/2006
    Posts:1
Advertisement

Log In

Forgot your password?     Register »
Advertisement
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
•  Subscribe
Save 36%
•  Table of Contents
•  MIT News
» Gift Subscription
» Digital Subscription
» Reprints, Back Issues
» Subscribe
» Table of Contents
» MIT News

More Technology News from Forbes

Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.