<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:series="http://unfoldingneurons.com/"
		>
<channel>
	<title>Comments on: Tweets: Firefox most vulnerable &#8211; Windows 7 news &#8211; Google browser security handbook</title>
	<atom:link href="http://4sysops.com/archives/tweets-firefox-most-vulnerable-windows-7-news-google-browser-security-handbook/feed/" rel="self" type="application/rss+xml" />
	<link>http://4sysops.com/archives/tweets-firefox-most-vulnerable-windows-7-news-google-browser-security-handbook/</link>
	<description>For Windows Administrators</description>
	<lastBuildDate>Fri, 19 Mar 2010 19:02:26 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Michael</title>
		<link>http://4sysops.com/archives/tweets-firefox-most-vulnerable-windows-7-news-google-browser-security-handbook/comment-page-1/#comment-121779</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Tue, 23 Dec 2008 20:15:36 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/?p=1974#comment-121779</guid>
		<description>Matt, the automatic update feature of Firefox is useless in corporate environments because end users should never ever have the rights to update software. If you allow this then you already have a serious security hole in your network. It wouldn&#039;t matter then what browser you use anyway. But of course you can use SMS or any other software deployment solution to update Firefox. I agree that there is no real difference between Firefox and IE when it comes to security. The biggest disadvantage of Firefox in corporate networks is its lousy support for Group Policy. If security is a top priority I would use Opera.</description>
		<content:encoded><![CDATA[<p>Matt, the automatic update feature of Firefox is useless in corporate environments because end users should never ever have the rights to update software. If you allow this then you already have a serious security hole in your network. It wouldn&#8217;t matter then what browser you use anyway. But of course you can use SMS or any other software deployment solution to update Firefox. I agree that there is no real difference between Firefox and IE when it comes to security. The biggest disadvantage of Firefox in corporate networks is its lousy support for Group Policy. If security is a top priority I would use Opera.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt A</title>
		<link>http://4sysops.com/archives/tweets-firefox-most-vulnerable-windows-7-news-google-browser-security-handbook/comment-page-1/#comment-121677</link>
		<dc:creator>Matt A</dc:creator>
		<pubDate>Sat, 20 Dec 2008 16:48:26 +0000</pubDate>
		<guid isPermaLink="false">http://4sysops.com/?p=1974#comment-121677</guid>
		<description>It would have been more accurate to say, &quot;Besides Internet Explorer, Firefox is the most vulnerable software in 2008&quot;. 

I have issues with the &quot;Criteria for the Vulnerable Applications List&quot;. Two of their criteria are false about Firefox, namely 
&quot;5) Relies on the end user, rather than a central administrator, to manually patch or upgrade the software to eliminate the
vulnerability, if such a patch exists.&quot;
AND 
&quot;6) The application cannot be automatically
and centrally updated via free Enterprise
tools such as Microsoft SMS &amp; WSUS.&quot;

These two points are false. 

Firefox has an automatic update feature. This feature is on by default. Updates are automatically downloaded in the background and then installed when the browser restarts. (The same can&#039;t be said for IE.)

The fact that Internet Explorer (any version) is not on the list at all seems highly suspect. 

While it is true that administrators *can* push out updates for IE, that&#039;s assuming you are operating in an enterprise environment. 

If we run IE through their six criteria, we get some interesting results:
1.) Runs on Windows - yup, installed by default
2.) Well known - yup, installed by default and still has a majority market share (over 89% last time I checked)
3.) Not classified as malicious - nope, IE is well trusted
4.) A: Contains at least one vulnerability reported after Jan 2008 - yes; B: registered at NIST - yes; C: given a severe security rating between 7-10 -- not sure, tool looked too complex. 
5.) Relies on the end user for patching rather than the administrator -- Enterprise users can patch, but home users are on their own. (Given how often people click &quot;cancel&quot; this seems like a poor metric).
6.) The application cannot be centrally updated via tools like Microsoft SMS - well, yes, IE can, but again you&#039;re assuming an enterprise environment. Home users are on their own to make use of Microsoft Update. 

So, according to those criteria, IE is just as vulnerable. 

Given that IE has a larger market share, AND that there are more exploits reported overall, I&#039;m really not that concerned about Firefox. 

In fact, the more I learn about IE, the scarier it is. A quick search of the vulnerability database at http://nvd.nist.gov returns the following statistics: IE: 696 results, Firefox: 400 results. Make of that what you will.</description>
		<content:encoded><![CDATA[<p>It would have been more accurate to say, &#8220;Besides Internet Explorer, Firefox is the most vulnerable software in 2008&#8243;. </p>
<p>I have issues with the &#8220;Criteria for the Vulnerable Applications List&#8221;. Two of their criteria are false about Firefox, namely<br />
&#8220;5) Relies on the end user, rather than a central administrator, to manually patch or upgrade the software to eliminate the<br />
vulnerability, if such a patch exists.&#8221;<br />
AND<br />
&#8220;6) The application cannot be automatically<br />
and centrally updated via free Enterprise<br />
tools such as Microsoft SMS &amp; WSUS.&#8221;</p>
<p>These two points are false. </p>
<p>Firefox has an automatic update feature. This feature is on by default. Updates are automatically downloaded in the background and then installed when the browser restarts. (The same can&#8217;t be said for IE.)</p>
<p>The fact that Internet Explorer (any version) is not on the list at all seems highly suspect. </p>
<p>While it is true that administrators *can* push out updates for IE, that&#8217;s assuming you are operating in an enterprise environment. </p>
<p>If we run IE through their six criteria, we get some interesting results:<br />
1.) Runs on Windows &#8211; yup, installed by default<br />
2.) Well known &#8211; yup, installed by default and still has a majority market share (over 89% last time I checked)<br />
3.) Not classified as malicious &#8211; nope, IE is well trusted<br />
4.) A: Contains at least one vulnerability reported after Jan 2008 &#8211; yes; B: registered at NIST &#8211; yes; C: given a severe security rating between 7-10 &#8212; not sure, tool looked too complex.<br />
5.) Relies on the end user for patching rather than the administrator &#8212; Enterprise users can patch, but home users are on their own. (Given how often people click &#8220;cancel&#8221; this seems like a poor metric).<br />
6.) The application cannot be centrally updated via tools like Microsoft SMS &#8211; well, yes, IE can, but again you&#8217;re assuming an enterprise environment. Home users are on their own to make use of Microsoft Update. </p>
<p>So, according to those criteria, IE is just as vulnerable. </p>
<p>Given that IE has a larger market share, AND that there are more exploits reported overall, I&#8217;m really not that concerned about Firefox. </p>
<p>In fact, the more I learn about IE, the scarier it is. A quick search of the vulnerability database at <a href="http://nvd.nist.gov" rel="nofollow">http://nvd.nist.gov</a> returns the following statistics: IE: 696 results, Firefox: 400 results. Make of that what you will.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
