Firefox is Vulnerable But Secure
I was reading an article on arstechnica by Eric Bangeman about the Number of browser vulnerabilities rising. The post is based on a recent study by Symantec and show Firefox in the top browsers of vulnerabilities discovered with 47 bugs, Internet explorer came in the second place with 38, then Safari and Opera. Certainly more vulnerabilities is bad, but the issue that the report don't talk about is that Firefox is patched quicker as soon as a bug is discovered.
According to the most recent update to security-firm Symantec's biannual Internet Security Threat Report, the last six months saw a significant uptick in the number of security vulnerabilities found in web browsers. Leading the way was Firefox, with 47 bugs discovered. Researchers and hackers discovered 38 vulnerabilities in Internet Explorer, 12 in Safari, and seven in Opera.
Also a very important point in the article is that Internet explorer still in top of attacks
That said, Internet Explorer remains the most popular target for attacks, with 69 percent of all browser attacks targeted specifically at that browser alone. 20 percent of the attacks monitored during the period in question were targeted at Firefox.When it comes to patching, all of the browsers are improving. Firefox is the fastest to get its patches out, with a one-day window of exposure. Opera had a two-day window of exposure, down from 18 days during the last half of 2005. The window of exposure for Safari is up to five days (from zero), while Internet Explorer typically has a nine-day window, down from 25 days in the previous study.
But if we go back to the study and the way it have been done, you should know that such studies are based on discovered bugs. And while Firefox is open source, Internet explorer is proprietary sources and have lot of bugs which remain unkown for the public, used for attacks and never been patched.
If you check Firefox vulnerabilities that the report was talking about you'll find them all fixed and patched in the latest release. Now check the IE bugs and try to find out a patch or a fix !! I remember the last patch IE released, few days later they released another patch to patch it !!
With Firefox I feel more secure for many reasons, first the code is open and bugs are easy to find and fix, secondly as soon as a vulnerability is discovered its quicker patched, and finally the Community of Firefox users is very large which make discovering bugs and make them fixed more easy. While Opera and Safari the community of users still very small compared to IE and Firefox, that's why reporting the number of vulnerabilities only is not relevant information at all. Firefox even vulnerable, it's more secure browser !

Subscribe to Firefox Magazine's feed