<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: IE More Secure Than Firefox?</title>
	<atom:link href="http://mozillalinks.org/2006/10/ie-more-secure-than-firefox/feed/" rel="self" type="application/rss+xml" />
	<link>http://mozillalinks.org/2006/10/ie-more-secure-than-firefox/</link>
	<description>Your source for Mozilla news, tips, reviews, and more.</description>
	<lastBuildDate>Sat, 24 Mar 2012 19:31:28 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: percy</title>
		<link>http://mozillalinks.org/2006/10/ie-more-secure-than-firefox/comment-page-1/#comment-251</link>
		<dc:creator>percy</dc:creator>
		<pubDate>Fri, 06 Oct 2006 12:44:22 +0000</pubDate>
		<guid isPermaLink="false">http://mozillalinks.org/wp/2006/10/ie-more-secure-than-firefox/#comment-251</guid>
		<description>Andrew, in the article I don&#039;t try to establish which browser is more secure but  instead mention just a few factors that should be considered and it&#039;s more about questions rather than answers.

You point to the number of security vulnerabilities patched during this year and numbers are fine and OK. The problem is how can you conclude which one is more secure based on this fact alone. 

Say Firefox have had and accrued 60 vulnerabilities since it shipped 1.0. Today it would be perfectly secure according to those numbers. If IE had the same numbers of vulnerabilities it would still have 30 flaws. 

What if Firefox really had 100 flaws? Then there are 40 around and yes IE is more secure even when patching less.

The problem is without knowing the total number of flaws a software has, you can&#039;t know how many flaws are left.

Also you aren&#039;t factoring how critical each flaw is. It&#039;s one thing to have a crash (Denial of service) than allow remote execution which could in fact make a zombie of your computer. 

Then what about attack surface. What exactly can an attacker do once your browser is possessed? Can it take full control of your computer or just browser functionality?

I am no security expert and just try to make my best decision based on as much information I can get and understand. I guess we all try to do that. I would really like to hear about better ways to measure a browser security.</description>
		<content:encoded><![CDATA[<p>Andrew, in the article I don&#8217;t try to establish which browser is more secure but  instead mention just a few factors that should be considered and it&#8217;s more about questions rather than answers.</p>
<p>You point to the number of security vulnerabilities patched during this year and numbers are fine and OK. The problem is how can you conclude which one is more secure based on this fact alone. </p>
<p>Say Firefox have had and accrued 60 vulnerabilities since it shipped 1.0. Today it would be perfectly secure according to those numbers. If IE had the same numbers of vulnerabilities it would still have 30 flaws. </p>
<p>What if Firefox really had 100 flaws? Then there are 40 around and yes IE is more secure even when patching less.</p>
<p>The problem is without knowing the total number of flaws a software has, you can&#8217;t know how many flaws are left.</p>
<p>Also you aren&#8217;t factoring how critical each flaw is. It&#8217;s one thing to have a crash (Denial of service) than allow remote execution which could in fact make a zombie of your computer. </p>
<p>Then what about attack surface. What exactly can an attacker do once your browser is possessed? Can it take full control of your computer or just browser functionality?</p>
<p>I am no security expert and just try to make my best decision based on as much information I can get and understand. I guess we all try to do that. I would really like to hear about better ways to measure a browser security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew</title>
		<link>http://mozillalinks.org/2006/10/ie-more-secure-than-firefox/comment-page-1/#comment-248</link>
		<dc:creator>Andrew</dc:creator>
		<pubDate>Fri, 06 Oct 2006 03:36:45 +0000</pubDate>
		<guid isPermaLink="false">http://mozillalinks.org/wp/2006/10/ie-more-secure-than-firefox/#comment-248</guid>
		<description>Read these:

www.firefoxmyths.com

http://poptech.blogspot.com/2006/09/internet-explorer-6x-more-secure-than.html</description>
		<content:encoded><![CDATA[<p>Read these:</p>
<p><a href="http://www.firefoxmyths.com" rel="nofollow">http://www.firefoxmyths.com</a></p>
<p><a href="http://poptech.blogspot.com/2006/09/internet-explorer-6x-more-secure-than.html" rel="nofollow">http://poptech.blogspot.com/2006/09/internet-explorer-6x-more-secure-than.html</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

