Showing posts with label firefox. Show all posts
Showing posts with label firefox. Show all posts

Saturday, August 15, 2009

IE8 more secure than Firefox

A report on Browser Security testing by NSS Labs shows that Internet Explorer 8 security is far better than Firefox, catching 81 percent of "live threats" vs. only 54 percent caught by Firefox 3, which came in second place.

The tests include rating the browser's protection against malicious software using socially engineering and phishing attacks.

The lab tested the most recent versions of Microsoft's IE8, Mozilla Firefox, Apple Safari, Google Chrome, and Opera. Opera caught a mere 2 percent of the threats.

Saturday, December 20, 2008

Firefox less secure?

Firefox has often been touted as fundamentally "more secure" than Internet Explorer. If you have been led to believe that, you need to look at some cold, hard facts:
  • From March to September 2005 (yes, even as early as 2005), FireFox had 40 vulnerabilities to IE's 10. [ZDNet article]
  • From April through September 2005, the number of published Firefox exploits was 11 compared to IE's 6.
  • The most recent FireFox-related security problem is that some Russian criminals are using it to add malicious software as a "Plug-In". The malware detects when you connect to any of over 100 banks and then steals your account name and password, sending them to the criminals. [read the SC Magazine article]
  • In terms of vulnerability numbers reported in March 2008, Opera had the most, followed by Safari, FireFox, then Internet Explorer.

The biggest problem with malware is not the browser, it's the person using the browser. People are either too trusting of links and unknown sites or just think they will never get attacked.

Monday, June 16, 2008

Firefox 3 leaps ahead

While not revolutionary or even truly evolutionary, version 3 of the Mozilla Firefox web browser looks very good. Some of its new features may even get me to use it as my default, which is now Microsoft Internet Explorer 7. Some of the new features I look forward to most relate to security and ease of use:

  • Site ownership. The "Passport Officer" lets you know who really owns a web site. This helps reduce accidental visiting of malicious sites.
  • Malware protection. A "Reported attack site!" message box with a red background pops up when the site you asked to visit is on a list of malware sites. Firefox blocks access and you must select the "Ignore" link if you really want to visit that URL. I also like that the link is small, in the lower right corner, and not a normal button. The two buttons are "Get me out of here" and "Why was this site blocked". This is a good security precaution.
  • Page zoom now zooms both text and images.
  • Multiple text select. You can now use the Control key to select and copy multiple blocks of text on a web page.

Features I an unsure about until I try them extensively include the new "keyhole" shaped navigation control. IE7 font rendering is better than FF2, so I am also curious about how well the font rendering in FF3 will work.

Features I already like in Firefox 2 include spell-checking in Web text areas, including Blogger, and the wide range of add-ons for blogging, editing, and web development.

I do wish Firefox would support the "standard" MSIE hot keys for such things as create a hyperlink (Ctrl+K), as using Firefox in Blogger is less useful than IE at this point (except for Spell-check).

It would help if at least Firefox and Mozilla had consistent hot keys. For example, Thunderbird uses Ctrl+L to insert a hyperlink. It doesn't match MSIE, but the Ctrl+L is easy to remember (L for "link"). But Ctrl+L in Firefox accesses its "Location Bar" (what IE calls the address bar. Bummer.

Monday, January 21, 2008

IE 7 Add-ons make surfing better

Internet Explorer 7 is a nice browser, but certainly not perfect. I also have Firefox installed on my PC, though I routinely use IE7. Among other things, online Blogger post editing seems to come out better than Firefox. No browser is perfect.

Case in point -- spell checking. I like the Firefox spell checking feature. Well, if you are an IE7 user, there's a free spell check add-on (but I like the Firefox implementation better). Actually, there are different add-ons that let you add features or customize IE7 more to your liking.

Here are a few IE add-ons that I wish Microsoft had included in IE7:

  • IE Spell (See IE7Pro below, though). Note that this spell check is only for form fields and similar ares to be filled in -- not for general web page views. It works fine within the Blogger post editing area, for example, though you have to manually force the check.
  • Inline Search (from IE Forge. See IE7Pro, below, though.)
  • Add Search Providers (surprisingly, from Microsoft)

Other handy Add-ons:

  • IE7Pro. IE7Pro adds several features, including Spell check and inline searching. The IE7Pro spell checks as you type, unlike the spell check on request method of "IE Spell" (above). That can be a blessing or a curse -- you decide.
    Note: IE7Pro didn't function well on my system, perhaps due to a couple of other browser helper objects installed. It crashed on use.
  • Web Developer Toolbar
  • Feed Folder. I prefer the IE7 Feed display in the left pane, but if you like Firefox's feed display better, check out Feed Folder.

Wednesday, October 24, 2007

Non-Microsoft security updates

Several security updates came out recently for products other than Microsoft ones, although a couple apply only if you are using Internet Explorer version 7. If you have the following software, make sure you get the patches:

  • Adobe Acrobat 8
  • Adobe Reader 8.1.1
  • Apple Quicktime 7.2
  • Mozilla Firefox 2.0.0.8

Tuesday, August 21, 2007

Outdated programs risky

Many programs these days need updates, not just your operating system (e.g. Windows). As an example, today's Windows Secrets points to the following common programs:
  • Adobe Reader
  • Macromedia Flash
  • Apple Quicktime
  • Sun Java
  • Mozilla FireFox

Most of these programs default to checking for updates. But if you ignore the update message or if it only checks once a month, you can be way behind in plugging security holes (a.k.a. "vulnerabilities").

What can you do about that? One very big help is the free Secunia Personal Software Inspector (PSI). You can try it online first and download if it serves as an eye opener for you -- it did for me.

For one thing, I discovered old versions of Sun Java on my system. Any "point" version needs to be updated to its most recent one. For example, the only currently secure versions of Sun Java JRE are version 5 update 12 and version 6 Update 2 (also known as 1.5.0_12 and 1.6.0_02)