Home | Articles, Firefox, Mozilla Project | On Firefox security
-->

On Firefox security

Published: September 15th, 2006
  •  Print

Window Snyder pictureOn a recent interview to Window Snyder, Mozilla's recently appointed chief security officer, she has revealed that among other strategies for tightening Firefox security they will remove any "death code" (like for unused features) from its source code in order to reduce any attack surface. They will also aim to implement technologies for better memory management that will difficult software exploitation.

This comes after last week Adam Harrison's announcement that Klocwork, a source code scanner, had identified 655 bugs and 71 security vulnerabilities in Firefox 1.5.0.6. Though the numbers have been disputed by Harrison himself and most recently by Robert O'Callahan. The problem is that reports by an automated tool, Klocwork or any other including Coverity (used by Mozilla) must be reviewed by humans to ensure proper identification, and this hasn't been the case with Harrison's report. According to O'Callahan, Firefox developers are working on the list and as of this writing 4 bugs have been reported, 3 of them confirmed.

These news along with yesterday's seventh Firefox update since its latest release in November 2005, outlines much of what makes Firefox apart in the security front: the possibility for anybody to audit the source code and report his findings; these reports are welcomed and reviewed; and as remarked by Snyder: "Mozilla will respond quickly to vulnerabilities, fix all bugs with a security impact, and when we add features we will always look at the security impact." 

You can leave a response, or trackback from your own site.

1 Comments on “On Firefox security”

Subscribe to this post's RSS feed

  1. 1. David Naylor
    September 17th, 2006 at 6:57 pm

    Very interesting writeup!

    [Reply]

0 Trackbacks/Pings (Trackback URL)

Leave a Reply




Comment:

Firefox 3

Links

  • Online Shopping
  • Document Scanning Services
  • 5GB free for your music
  • Voucher Codes & Discount Codes
  • CyberDefender Software
  • Recent Entries

    Recent Comments