top | item 932492

Firefox flaws account for 44% of all browser bugs

24 points| novicecoder | 16 years ago |computerworld.com | reply

21 comments

order
[+] jacquesm|16 years ago|reply
I think a better measure of this would be to count the total number of days exploits are 'open'.

So, if there are three exploits, one is patched after 48 hours, the second in 24 and one in a week that should count as 10 bug days.

Then do the same for all browsers.

[+] lucumo|16 years ago|reply
While I agree that that's probably a good measure, I don't think it's feasible. Many exploits are reported privately to the company first, so they have time to fix them. After the fact reporting by the company would create an incentive to underestimate the amount of time it took. Finding the reporters may be hard, and even if they are inclined to comment on when they found it, you can't really trust them, since their incentives aren't clear either. They may love the browser, or hate it...
[+] rbranson|16 years ago|reply
Is this an article from The Onion? I am trying to come up with a cute little one-liner that equals the "roll-eyes" level of this article, but nothing compares.
[+] krakensden|16 years ago|reply
There's really not much information either in the article, or in the PDF it's summarizing. I mean yes, the count is higher, but why? They also say that the number of 'safari' bugs has skyrocketed because of vulnerabilities found in the iPhone version- does this mean they're double counting webkit problems, or are there actually unique vulnerabilities in the iPhone specific libraries?

In any case, that's not a security report so much as it is a long form advertisement for Cenzic, whoever they are.

[+] didroe|16 years ago|reply
>Firefox accounted for 44% of all browser bugs reported in the first half of the year.

And what about the ones that closed source IE and Opera didn't report?

[+] ErrantX|16 years ago|reply
It's not unexpected: - more releases - open source code

exploits and bugs are easier to find. It doesn't really say much about the safety of FireFox (provided your up to date :))

With all that said it does raise a few questions about Mozilla's code auditing and security procedures. Surely this is something they should take note of to increase the amount of time spent testing new and old code in releases.

[+] bediger|16 years ago|reply
Hey, wait! Where's the "Market Share" argument when you need it (and it works against IE)?

Doesn't Doctrine and Dogma inform us that a larger share of the flaws just mean a larger market share? I mean, I hear that all the time about Windows incarnations.

[+] unknown|16 years ago|reply

[deleted]

[+] andreyf|16 years ago|reply
Hi novicecoder,

Looks like you're new here. Welcome, and thanks for sharing the story :)

Your comment here is on the story directly, even though you're addressing specific responses. Next time, please click on the 'reply' links right below the message you're replying to, and skip the @notation. Also, since there might be hundreds of people looking at what you write, try to avoid one-liners intended for one person, or generally any messages without interesting content. The rest of us will try to do the same :) Cheers!

[+] ableal|16 years ago|reply
I like using two browsers - one of them with just HTML (and CSS, no plugins, no javascript and cookies turned off), for general reading, search and scouting.

A good portion of the web is still readable, usually the better part, and works much faster. Make image loading optional for extra speed. It's amusing how some sites fire volleys of 6 or 7 cookies at you (if you choose notifications about that). And some even manage to be annoying with just CSS and images.

[+] b05us|16 years ago|reply
well you want "release early, release often", then you live with bugs

clearly ff should pay more attention to quality, but i don't want to go to an IE-like model of only updating the browser every 2.5 years...its likely this lagged release model coupled with microsoft's closed source that also results in fewer bug reports

opera in last is no shock, no one uses it

no one should be surprised that the two browsers with the most releases, access to source and the shortest development cycles have the most bugs...they also have the most features

[+] blasdel|16 years ago|reply
WebKit has a dramatically faster development cycle than Firefox, much less Gecko itself. They also have a much larger and more diverse community of people hacking on and interfacing with the rendering engine, since it's actually palatable to link against without the XUL ball-and-chain.
[+] endtime|16 years ago|reply
>opera in last is no shock, no one uses it

Ahem, I use it. I'm actually surprised the count's so low, since I have minor but consistent issues with sites such as Facebook. Or perhaps those sorts of bugs aren't included (and I suppose it might be Facebook's fault, since O10 does pass Acid3).

[+] c00p3r|16 years ago|reply
You can also read directly at microsoft.com to get a fair and unbiased information about web browsers.

Is there aren't Google Chrome around?