The Mac Observer

Skip navigational links

You're viewing an article in TMO's historic archive vault. Here, we've preserved the comments and how the site looked along with the article. Use this link to view the article on our current site:
Study: Firefox Most Secure Browser

Study: Firefox Most Secure Browser

by , 4:10 PM EDT, July 1st, 2008

One way to evaluate the security of a Web browser is to determine what percentage of its users are using the latest version. In a study released on Tuesday by S. Frei et al, it was found that Firefox users are most likely to be up to date.

Now that modern software and hardware firewalls have blocked incoming intrusions via TCP/IP ports, the most favored method of attack on computers connected to the Internet is via data returned to the Web browser that exploits browser code or plug-in vulnerabilities. As a result, keeping the browser updated to the latest version these days is paramount.

The authors, in their paper, "Examination of vulnerable online Web browser populations and the 'insecurity iceberg'" look at the rates of adoption of the latest browser versions and the impact it has on users.

Their definition of the most secure browser was as follows. "...the most secure browser designates the latest official public release of a vendor's Web browser at a given date. Beta versions are not considered an official public release."


From the Authors' Paper

The chart above shows the rate of adoption of the latest major version of each browser, for example Firefox 2 or IE 7.

By this standard, Firefox is the most secure browser because 83.3 percent of the users have the very latest version. Safari was ranked second at 65.3 percent, Opera third with 56.1 percent and IE 7 last at 47.6 percent. Note that, unlike the chart above, these numbers speak to the very latest version, for example Safari 3.1.2.

The paper raises some interesting questions. It's understandable how IE could lag thanks to corporate rules and compatibility testing with internal products. That can slow dow the rate of adoption. However for users who can use automatic update notifications, like Safari, Opera and Firefox, there are key difference in the methodology.

For example, the update mechanism of Firefox was considered noteworthy: "We believe the auto-update mechanism as implemented within Firefox to be the most efficient patching mechanism of the Web browsers studied. Firefox's mechanism regularly polls an online authority to verify whether a new version of the Web browser is available and typically prompts the user to update if a new version exists....

"With a single click (assuming that the user has administrative rights on the host), the update is downloaded and installed. Just as importantly, Firefox also checks for many of the currently installed Firefox plug-ins if they are similarly up to date, and, if not, will prompt the user to update them," the authors noted.

In contrast, the authors pointed out that "While Firefox and Opera check for updates when the browser is used, Safari relies on an external Apple-updater that appears to only poll for new updates at scheduled regular intervals while Internet Explorer gets updated as part of the monthly distributed Windows patches."

This scheduled updates for Safari can be as seldom as "never" if the user elects to uncheck the "Check for Updates box" in the Software Update. In addition, the Adobe Flash plug-in has no automatic update feature, and users must attended to that update manually. TMO notes that all this could explain the lag Safari has compared to Firefox.

There is much more detail in the paper, including a discussion of plug-in vulnerabilities. While some of the content is quite technical, any user interested in browser security should take a look at this report.

Observer Comments

Show: Subjects Only | Full Comments
Close Name:Mikuro Posts: 457 Joined: 15 Jun 2002
Subject:

It's an interesting way of looking at it, but it seems like a stretch to equate it so directly with "security". Who's to say the newest version of Firefox has fewer vulnerabilities than the previous version of Safari, or vice-versa? If Mozilla releases an update to Firefox tomorrow, that will not suddenly make the current version of any other browser more secure than today's version of Firefox.

I'll bet a VERY high percentage of IE for Mac users are using the latest version. That doesn't make it secure.

Close Name:geoduck Posts: 1922 Joined: 30 Dec 2003
Subject: I'm inclined to agree

How current the installed base is more a function of factors other than security. Firefox was pushing for a record number of downloads to speed its adoption plus it still has an air of 'geek cred'. IE has not been updated for the Mac in years so nearly everyone has "the latest version" even though it's not very current. IE7 has been a slow update because (such as at my company) some corporations have not approved it's adoption yet.

I think it's a stretch to assume that, as Mikuro pointed out, latest=most secure. I also think it's a stretch to assume that people update primarily because of security.

Given these two, what I view as unwarranted logical assumptions I'm skeptical of the papers conclusion.

Close Name:Guest
Subject: Lame Hypothesis

This is a very, very lame analysis. Or rather, the analysis was perhaps thorough, but the original hypothesis is utter garbage. I could propose that the first version of Mosaic from the mid-90's is the most secure web browser and prove it based on the fact that the only thing it could display was text and inline graphics. This would contradict the "latest is most secure" theory, thus proving it invalid.

Ridiculous? Yes. But no more ridiculous that what this paper concludes.

Close Name:JonGl Posts: 113 Joined: 12 Jan 2006
Subject: Not absurd

The hypothesis is most certainly not absurd. Remember the pwn to own contest? It utilized a known weakness in Safari that hadn't been patched yet--at least on the computer being used in the contest (I don't remember the specifics at this moment). The premise is that any discovered holes--that attackers would be aware of--are typically fixed in the latest release, thus, by virtue of the plugging of known holes, it is more secure. Of course, the one downside of this approach to security is that no one knows if some cracker/thug already knows about some unpatched hole, and is preparing to deploy something to exploit this unknown hole. However, since most people who do these things are rather lame, and not so technicially capable as that, I suppose it's not so much a worry as it could be.

However, in any case, the hypothesis is _not_ absurd. Read the second paragraph again:

Quote
Now that modern software and hardware firewalls have blocked incoming intrusions via TCP/IP ports, the most favored method of attack on computers connected to the Internet is via data returned to the Web browser that exploits browser code or plug-in vulnerabilities. As a result, keeping the browser updated to the latest version these days is paramount.


It's the rest of the premise that has me curious.... It's more about a critique on the various update methods used by the various browsers. Firefox _has_ to use the update method it uses, because it's not connected with an OS. By virtue of it's being third-party, it will always win such "contests." It was not by design that Firefox is more "secure" in this manner.

-Jon

Close Name:Guest
Subject: Browser with unpatched holes can`t be most secure

Browser with unpatched holes can`t be most secure at all. Now all FireFox 2/3 versions have upatched highly critical vulnerability that "can be exploited to execute arbitrary code e.g. when a user visits a specially crafted web page". See Secunia advisory for details at http://secunia.com/advisories/30761/

Close Name:LaurieF -   TMO Forum Mod Posts: 3547 Joined: 15 Jun 2001
Subject:

OK - tell me about these "specially crafted web pages". Where are they? Are there any genuinely malicious ones around? How come I'm not tripping over them all the time?

And when I get there, will my computer spontaneously burst into flames? will my bank account be sucked dry? will my wife leave me for another operating system?

When the breakins exist at a rate of more than one part in infinity, I'll start getting worried.

In the meantime I will continue to practise safe hex. As we all should. But frightened I am not.

Close Name:Guest
Subject: Chart doesn't agree with analysis

Did anyone look at the chart? Opera seems to be in second place, currently.

Comment on this Article


You cannot edit your comments.   You cannot delete your comments.

Comments are currently closed. Please email the author instead.


Recent Headlines - Updated November 7th

Sat, 7:58 PM
News - Apple TV 3.0.1 Update Fixes Missing Content Bug
Fri, 7:45 PM
Rumor - Taiwan Leak Shows Verizon UTMS/CDMA iPhone for Q3 2010
6:40 PM
News - iPhone Moves Into RadioShack
6:30 PM
News - Apple to Open Stunning Paris Apple Store in Le Louvre on Saturday
5:43 PM
Free on iTunes - Dictionary, Dictionary, Dictionary, And More
4:09 PM
John Martellaro's Blog - Particle Debris (week ending 11/6) Failure IS an Option
3:32 PM
Games - The Latest App Store Games: Gravity Sling, RocketBird, Ground Effect, Checkers!
2:25 PM
Games - Star Soccer 2010 for Mac Puts Gamers in Role of Up-and-Coming Player
2:15 PM
How-To - The Mysteries of Rosetta Housekeeping
1:33 PM
News - iPhone Game Developer Sued for Collecting User’s Cell Numbers
1:17 PM
Games - Warhammer Online Expands Trial Play Option
11:19 AM
Rumor - Apple May Be Bringing RFID to the iPhone

The Mac Observer Reader Specials

  • TypeStyler For Mac OS X is Now Shipping! Download The Free Fully Functional 60 Day Tryout at www.typestyler.com
  • RamJet Memory: Mac Pro 8-core 8GB Kit $199.99, 4GB Kits $109.99! Sale on MacBook and MacBook Pro 8GB kits $549.99! New MacBook DDR3 2GB for $49.99. iMac and Mac mini 4GB Kits for $79.99! 1TB SATA Hard Drives for $109.99! Click here
  • OWC: Plug & Play Hardware RAID up to 8.0TB. High Performance, Data Redundant Solutions. FireWire 800, FireWire 400, USB2, or eSATA. Hot Swappable Bays, Data Rates over 200MB/s. Click here
  • Poker Mac If you're using a Mac, then you've gotta check out Full Tilt Poker for Mac. This Full Tilt Poker bonus code does the unthinkable, it actually rewards!
  • For the latest Apple products use Ciao, a price comparison website, to find laptops like MacBook Air. Then find the best prices on MP3 players and use our comparison tool to evaluate mobile phones like the Apple iPhone.

  • Laptop Hardware Provided by TechRestore - Overnight Mac & iPod Repairs.
  • __________
  • Buy Stuff, Support TMO!
  • Podcast: Mac Geek Gab
  • Podcast: Apple Weekly Report
  • TMO on Twitter!