Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Last Visible Dog
Now that statement is complete nonsense. FireFox has been around for about a month or two and they have already found a serious vulnerability.

Not true. Firefox has been around for as Beta's for at least a year. I think I first installed Firebird Circa Oct 2003.

The issue is the IE can run in the Local zone. Compromise a module in IE, quite often you've compromised windows. The same cannot be said for Firefox. I'm not saying it's immune. By it's nature however it's more secure by default.

As to vulns in Firefox, there were a number that hit in the beta. The one you're referring to is a Phishing Vuln. Using Spoofstick would alert you to the issue. The other is that you have to go to a site and download some Malware.

This is quite a different issue than IE where the Malware folks just crossscript a site, download the Malware in the background for you and you havn't a clue anything happened at all. Orders of magnitude in difference.

226 posted on 01/06/2005 5:40:46 PM PST by Malsua
[ Post Reply | Private Reply | To 224 | View Replies ]


To: Malsua
This is quite a different issue than IE where the Malware folks just crossscript a site, download the Malware in the background for you and you havn't a clue anything happened at all. Orders of magnitude in difference.

I agree but cross-zone scripting exploits are not easy to do in IE (just conceptually possible) and MS plugs the holes fairly quickly. MS is just trying to tightly integrate the browser with the desktop - this is something FireFox is not even attempting. At this point one would think MS would decide it is not worth it to tightly integrate the browser with the desktop or maybe MS could create two browsers - one that does and one that does not. I have written systems that tightly integrate the browser with the desktop (and they are pretty cool) but my target has always been Intranets. Most people do not want that level of integration.

249 posted on 01/07/2005 12:17:55 PM PST by Last Visible Dog
[ Post Reply | Private Reply | To 226 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson