Firefox flaws make up 44% of all browser bugs?
But numbers game ignores the big picture
Firefox flaws accounted for nearly half (44 per cent) of all browser bugs in the first half of 2009 - according to a survey which fails to factor in the seriousness of browser flaws.
A study by web application security firm Cenzic makes a decent fist of providing an overview of server-side web, but blots its copy-book with a brief foray into commenting on browser bugs. Of the browser vulnerabilities mapped by Cenzic, Firefox racked up 44 per cent of the total, with Safari bugs making up a 35 per cent slice of the browser vulnerabilities. Internet Explorer was third, with 15 per cent, with Opera copping for six per cent.
Cenzic's one-paragraph treatment of browser security suggests the number of Safari bugs was mainly due to vulnerabilities reported in iPhone Safari, and not much else. In particular, Cenzic fails to mention that the seriousness of flaws and the availability of exploits has a big bearing on how comparatively safe a browser choice might turn out to be.
The majority of media reports on Cenzic's survey fail to make the point that counting vulnerabilities alone is a bit pointless.
"For a proper and fair comparison one needs to dig a lot deeper than just looking at the numbers," Thomas Kristensen, CTO on web security notification firm Secunia, told El Reg.
http://www.theregister.co.uk/2009/11/10/web_security_survey/
Firefox flaws account for 44% of all browser bugs, Apple's Safari takes second, with 35%, IE in third with 15%, says vulnerability tally
According to California-based Cenzic, Mozilla's browser had the largest percentage of Web vulnerabilities over the six-month span, while Apple's Safari had the dubious distinction of coming in second. Microsoft's Internet Explorer (IE) was third, while Opera Software's flagship browser took fourth place.
The Cenzic report can be downloaded from the company's site (download PDF).
More with interview with CenZic's CTO in
http://www.computerworld.com/s/article/9140582/Firefox_flaws_account_for_44_of_all_browser_bugs