PDA

View Full Version : Study Ranks Mozilla Firefox Third for Browser Security, Chrome First



Teh One Who Knocks
12-11-2011, 03:18 PM
By David Murphy - PC Magazine


http://i.imgur.com/Xx7Dk.jpg

Raise your hand if you're running the most secure browser right now. Google Chrome users: Your arms are going to get tired. Internet Explorer users: You're close, but you can safely put your arms down. But Mozilla Firefox users, no need to wave your arms like a student trying to get a teacher's attention – according to a new browser security study from Accuvant, you don't have much to brag about at all.

Accuvant's study, released Friday, ranks the "big three" browsers in that order in terms of their overall security features: Chrome's first, IE's second, and Firefox is dragging along in third, with Accuvant rating four of the seven security features tested in Firefox either "unimplemented" or "ineffective." To note, the study – while independently and objectively assessed, said Accuvant – was funded by Google.

As for the raw details, Accuvant's study didn't just focus on the sheer number of published vulnerabilities that a browser has at the time of testing. Rather, Accuvant presumed that a browser vulnerability is going to be exploited in some fashion by a third-party: The security testing, therefore, focused on the strength of a browser's anti-exploitation measures after-the-fact – "the software with the best anti-exploitation technologies is likely to be the most resistant to attack and is the most crucial consideration in browser security," Accuvant wrote.

While Google's Chrome browser won the day in Accuvant's research, the browser didn't sail through with a perfect score. Accuvant noted that Chrome, along with the other two browsers in the test, failed to adequately offer up strong enough URL blacklisting to pass Accuvant's examinations – a daily comparison of roughly 6,000 malware-related URLs against either Microsoft's URL Reporting Service or Google's Safe Browsing List.

"Gathering intelligence about malware URLs is generally performed by running honeypots and spamtraps, and harvesting URLs from malware captured in the wild. Since no authoritative source exists, it is likely that each organization gathering data is getting one part of the overall picture," Accuvant wrote. "Based on Accuvant's analysis, no party is performing this data collection comprehensively."

That said, Chrome's apparent excellence in sandboxing, plug-in security, JIT hardening, and Address Space Layout Randomization, among other features, was enough to win it top honors. But Mozilla isn't letting Accuvant have the last word regarding the security of its browser.

"We invest in security throughout the development process with internal and external code reviews, constant testing and analysis of running code, and rapid response to security issues when they emerge. We're proud of our reputation on security, and it remains a central priority for Firefox," responded Jonathan Nightingale, director of Firefox engineering, in a statement to Forbes' Andy Greenberg

Goofy
12-11-2011, 03:45 PM
Rough translation - No browser is secure if the operator is an idiot :)

Godfather
12-11-2011, 08:36 PM
I just can't make the switch from Firefox to Chrome. Not a fan of it.

JoeyB
12-11-2011, 09:02 PM
Notice they ignored the safety king, Opera.

Teh One Who Knocks
12-12-2011, 01:01 AM
I just can't make the switch from Firefox to Chrome. Not a fan of it.

I've tried it a few times, I just don't care for it


Notice they ignored the safety king, Opera.

Because nobody cares about fringe browsers

DemonGeminiX
12-12-2011, 02:14 AM
:huh:

Fringe browsers? Opera's been around for a long time, dude. I haven't used it in a while, but when I was using it back in the day, nothing could compare to it's speed.

Teh One Who Knocks
12-12-2011, 02:15 AM
:huh:

Fringe browsers? Opera's been around for a long time, dude. I haven't used it in a while, but when I was using it back in the day, nothing could compare to it's speed.

Less than 2% market share, hence, it's a fringe browser

DemonGeminiX
12-12-2011, 02:16 AM
Who cares about the market share when it can wipe the floor with the competition?

Teh One Who Knocks
12-12-2011, 02:18 AM
Who cares about the market share when it can wipe the floor with the competition?

It can? I've used it before and I think it blows

IE9 is better than Opera

DemonGeminiX
12-12-2011, 02:20 AM
It can? I've used it before and I think it blows

IE9 is better than Opera

:hand:

That's your opinion.

Teh One Who Knocks
12-12-2011, 02:24 AM
And the opinion of a lot of people, or else more people would be using Opera ;)

Game, set, and match :banana:


See, Opera people are under the same false assumption that crApple people are....you know why nobody actively looks for Opera exploits? Because nobody uses it.

DemonGeminiX
12-12-2011, 02:27 AM
There's a lot more people using Opera than you realize.

Teh One Who Knocks
12-12-2011, 02:27 AM
If you say so ;)

Southern Belle
12-12-2011, 02:34 AM
I haven't tried Chrome yet, refuse to use IE and haven't had any problems with firefox so I'm sticking with it.

DemonGeminiX
12-12-2011, 02:43 AM
IE9's a lot better than the previous versions of IE. It really is an improvement. You may want to give it a whirl.

I haven't messed around with Chrome yet, either, but I may look into it after having read this article. Not that I buy into anything the article has stated, but it's got me thinking about it now.

Teh One Who Knocks
12-12-2011, 02:44 AM
Chrome is just way to 'utilitarian' for me

DemonGeminiX
12-12-2011, 02:47 AM
Chrome is just way to 'utilitarian' for me

:-s

How so?

DemonGeminiX
12-12-2011, 02:47 AM
P.S.

I'm using Opera right now after years of not using it and holy shit is it fast!

:lol:

Teh One Who Knocks
12-12-2011, 02:50 AM
:-s

How so?

It's still not as customizable as FF is and I don't like the 'feel' of it. I have it on my PC, I just rarely use it

DemonGeminiX
12-12-2011, 02:52 AM
It's still not as customizable as FF is and I don't like the 'feel' of it. I have it on my PC, I just rarely use it

Got ya. I'll check it out later and see how it runs.

Southern Belle
12-12-2011, 02:56 AM
I had a really bad experience with IE a few years ago and I have not doubt that it's improved but I don't want to risk a virus or adware or malware or the bs. I don't have any problems with ff and adblock plus. None whatsoever.

DemonGeminiX
12-12-2011, 03:07 AM
:-s

The chrome web store? Seriously?

Teh One Who Knocks
12-12-2011, 03:10 AM
:-s

The chrome web store? Seriously?

Gotta have a catchy name ;)

There's a lot more extensions available for it now than there used to be (I'm on Chrome now)

DemonGeminiX
12-12-2011, 03:13 AM
It seems like they're just copying Apple. And there are some things you actually have to buy.

I mean... seriously?

:lol:

Teh One Who Knocks
12-12-2011, 03:15 AM
I haven't seen any paid ones yet :-k

DemonGeminiX
12-12-2011, 03:16 AM
Mad Skills Motocross costs $4.99.

Teh One Who Knocks
12-12-2011, 03:19 AM
I don't count games :P

I found a NoScript type extension for Chrome and just added it...maybe I'll try out Chrome for awhile now. Seems pretty fast too

DemonGeminiX
12-12-2011, 03:27 AM
Well, it is fast...

JoeyB
12-12-2011, 06:54 AM
Because nobody cares about fringe browsers

Fringe users do.


:huh:

Fringe browsers? Opera's been around for a long time, dude. I haven't used it in a while, but when I was using it back in the day, nothing could compare to it's speed.

I like you.


Who cares about the market share when it can wipe the floor with the competition?

I really like you.


And the opinion of a lot of people, or else more people would be using Opera ;)

Game, set, and match :banana:


See, Opera people are under the same false assumption that crApple people are....you know why nobody actively looks for Opera exploits? Because nobody uses it.

Actually, Opera is very proactive in its security, whereas Apple tends to be somewhat complacent. But, and I've said the very same thing about Apple myself, being fringe is the best security of all.


There's a lot more people using Opera than you realize.

That's true because Opera is popular on phones, and also because the desktop version of Opera identifies itself as IE by default. I don't know why. But many web analytics do not correctly ID all versions of Opera.


IE9's a lot better than the previous versions of IE. It really is an improvement. You may want to give it a whirl.

I haven't messed around with Chrome yet, either, but I may look into it after having read this article. Not that I buy into anything the article has stated, but it's got me thinking about it now.

Chrome is a good second browser. It's not really primary browser ready unless you are far from picky. It is however, a really solid main browser for people who don't use the internet much and do not want to fuss about with settings.


P.S.

I'm using Opera right now after years of not using it and holy shit is it fast!

:lol:

Man hug~!! Are you using 11.60?

Teh One Who Knocks
12-12-2011, 01:14 PM
http://i.imgur.com/27iT9.png