NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
Home / News / Microsoft / Internet Explorer

Internet Explorer


Security in 10 F**king Days Not a Mozilla Policy to Beat Internet Explorer

Just an indication of the commitment to protect users

By Marius Oiaga, Technology News Editor

7th of August 2007, 09:28 GMT

Adjust text size:



Enlarge picture
Mozilla's Firefox is generally perceived by end users as a browser delivering superior security in comparison to Internet Explorer. In fact, security has been the backbone of Firefox's adoption, and a constantly ascendant uptake rate, eroding IE's domination on the browser market. However, at Black Hat 2007 in Las Vegas, Mozilla's Director of Ecosystem Development, Mike Shaver took it one step further and apparently made the promise that
the corporation will take only 10 days to patch any critical security vulnerability in the open source browser.

"Mike Shaver threw down the gauntlet. He gave me his business card with a hand written note on it, laying his claim on the line. The claim being - with responsible disclosure Mozilla can patch and deploy any critical severity holes within 'Ten F**king Days'," revealed Robert Hansen.

Window Snyder, Chief Security Officer at Mozilla, explained Shaver's gesture. "Mike Shaver handed his business card to Robert Hansen (RSnake) on Wednesday night at Black Hat. On it he wrote "ten f-ing days." When I asked him about it, he said he meant to communicate to Robert that since Mozilla got a recent security update out in only ten days, that there was no reason for Robert to post details of vulnerabilities publicly before a patch was available. Since we're among the most responsive software vendors, security researchers do not have to resort to full disclosure to get us to patch bugs quickly. Well, whatever he meant, his statement has taken on a life of its own," Snyder explained.

This however, is not a new Mozilla security strategy designed to bring Internet Explorer on its knees. Currently, Microsoft releases patches on a monthly basis. The Redmond company diverges only seldom from its monthly patch cycle. The exceptions are connected with critical vulnerabilities that pose great risk to users. Otherwise, security updates are released for IE, and the additional Microsoft products on the second Tuesday of each month. If Mozilla took the patching process down to just 10 days, it would narrow down the attack window on the browser, and further increase the perception of security. But this is not the case.

"This is the official Mozilla word: This is not our policy. We do not think security is a game, nor do we issue challenges or ultimatums. We are proud of our track record of quickly releasing critical security patches, often in days. We work hard to ship fixes as fast as possible because it keeps people safe. We hope these comments do not overshadow the tremendous efforts of the Mozilla community to keep the Internet secure," Snyder added.

TAGS:

Mozilla | Firefox | IE


Rating:
Good (3.8/5) 5 vote(s) so far    

Read by 767 user(s) | Add comment | Link to this article
Subscribe to news | Print article | Send to friend

© Copyright 2001-2008 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


IE7, Firefox 2.0 and Safari 3.0 Share Security Vulnerability on Windows Vista

Mozilla Recommends Firefox 2.0 and Not Internet Explorer 7

Mozilla: Firefox Just As Vulnerable As Internet Explorer

Firefox 2.0 Updated and Available for Download

Firefox Users Deserting to Safari, IE Still Top Dog

IE7 Up! Firefox 2.0 Up! Safari 3 Up!

Mozilla Slaps Apple with New Firefox 3.0 Alpha 7

User opinions:


Comment #1 by: Lost Angel on 07 Aug 2007, 09:42 GMT reply to this comment

"But this is not the case." - the following quote in your article doesn't actually disprove the 10 days patch claim.

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 






SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM