On TV.com: BATTLESTAR Galactica Maxim Photoshoot
BNET Business Network:
BNET
TechRepublic
ZDNet

By Staff ZDNet UK
Posted on ZDNet News: Jan 7, 2005 7:30:00 PM

The news that the Firefox browser contains a flaw that could help cybercriminals to carry out phishing attacks stirred up plenty of reaction and discussion among readers.

Security firm F-Secure warned Wednesday that the vulnerability, which allows the URL in a Firefox download dialog box to be spoofed, could be exploited by online fraudsters.

Some ZDNet UK readers took issue with the experts, arguing that the flaw shouldn't be regarded as a security vulnerability, because a Firefox user would already have to have clicked on a phishing e-mail and been taken to a fake site to be at risk. "Where is the problem? I hardly think that a spoofed site would link you to a legit download area," commented Pete Molina, a PC and LAN administrator.

Related story
Firefox flaw raises
phishing fears
Browser bug opens
users up to scam artists.

"As far as a 'security hole,' it should be more of a user vulnerability, as only a dumb person goes clicking links in e-mails from odd places," argued another reader who went by the name Killian. "Granted, it's nice to know, but come on. Most of these 'announcements' just give the phishermen a reason to try to exploit it."

Mozilla's Firefox browser is proving popular with surfers who want an alternative to Microsoft's Internet Explorer, which has been prone to many security problems. Some readers were adamant that Firefox is still a much safer product than IE.

"Firefox, without a doubt, is the best and most secure browser on the market today, and no matter what propaganda is spread throughout the Net regarding its security in a negative way, those who actually know will continue to use Firefox and wait until the patch is complete, not actually even thinking nor caring whether it is released or not while using it," wrote one Web developer.

Some members of the Firefox camp weren't happy about any criticism of their favorite browser. "Thanks but no thanks for the information. We still trust and love FireFox," said Abe, an engineer. He did not reveal his last name.

But other readers pointed out the importance of holding all software to the same standards. "Firefox is undoubtedly a better and more secure browser than IE, but any site that reports on flaws or possible flaws in IE--and gives Firefox coverage--should report on Firefox's flaws too," said "Seb," an artist based in London. "Essentially, Firefox is better, but it's not perfect, and anyone who thinks or claims it, is as bad as anyone who gets taken in by (Microsoft Chairman Bill) Gates' marketing spiel."

A software developer from London wrote: "If this vulnerability had been identified in IE, the anti-Microsoft community would no doubt be quick to criticize the product as insecure. Users are smart enough to make up their own minds about which Web browser to use--and the more information that is available about all products on the market, including open-source efforts, the better."

One reader even took issue with the claim that Firefox is inherently more secure than IE. "Firefox may offer some 'security through obscurity,' but once it gets to any sort of critical mass, then it will be targeted. Since the hackers have the source code, their lives will be that much easier, and when a patched version is released, it will be easy for them to see where the vulnerability is and target older versions," said one London-based IT worker.

Another reader suggested that Firefox may have an uphill task breaking IE's dominance."Most users couldn't spell 'browser' without help. The only reason so many people use IE is because it is built into the operating system that was on the PC they bought," said "Philbert," a computer and electronics specialist.

Got a different view? Post a TalkBack below, or in the original story.

Ingrid Marson of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 107 Talkback(s)
Nobody wants to admit...
...when their baby's been bad. It's human nature to prefer to do otherwise. Look at Microsoft as a primary, gigantic example. It must be especially so for a company that carved their place by makin... (Read the rest)
Posted by: calkins@... Posted on: 02/27/05 You are currently: a Guest | | Terms of Use
Internet Explorer's fine.  Grayson Peddie | 01/07/05
Just two small questions...  Zogg | 01/07/05
questions  richhayes | 01/07/05
You're doing something wrong then dude  Jeff Spicoli | 01/07/05
Something is definitely wrong  nucrash | 01/07/05
Things wrong  richhayes | 01/08/05
settings?  JTR_z | 01/16/05
Spyware/adware..  vdraken | 01/07/05
And usually do.  IT Scion | 01/08/05
agreed.  linuxoverwindows | 01/08/05
Not that much...  Grayson Peddie | 01/07/05
IE vs FireFox on a Win box  ac2_z | 01/07/05
three?  JTR_z | 01/16/05
Just one question.  IT Scion | 01/08/05
spywarez  linuxoverwindows | 01/08/05
Just one teensy weensy question  Jeff Spicoli | 01/07/05
because...  vdraken | 01/07/05
Internet Explorer's Options dialog  Grayson Peddie | 01/07/05
I mostly do Alt+Tab between browsers.  htotten | 01/08/05
I don't care about the resources that much.  Grayson Peddie | 01/08/05
Hey Grayson  cdturri | 01/08/05
Is that you, bitty?  AmusedAtItAll | 01/08/05
Re: Is that you, bitty?  Grayson Peddie | 01/09/05
That's easy  boxmonkey | 01/09/05
Ctrl+Page up or Page Down  libertyaikido | 01/13/05
Partial Vision Loss  htotten | 01/09/05
Huh?  AmraLeo | 01/12/05
seriously  Jeff Spicoli | 01/07/05
Actually...  vdraken | 01/07/05
Or...  Real World | 01/07/05
Actually, IE loads faster and generally renders pages  htotten | 01/08/05
It's just a ******* browser!  htotten | 01/08/05
ActiveX  AmusedAtItAll | 01/08/05
Notice I Said INTRANET  htotten | 01/09/05
Microsofties??  wbutler@... | 01/14/05
not I  JTR_z | 01/14/05
LOL  linuxoverwindows | 01/08/05
I agree with your attitude  Junkmonkey | 01/09/05
Well said  akaralia | 01/16/05
No problem/no switching here either...  dfrench@... | 01/12/05
zdn still using dial-up?  Jack-Booted EULA | 01/07/05
Man, this needs to be taken seriously.  DonnieBoy | 01/07/05
I agree.  psm_z | 01/07/05
It's amazing..  d_jedi | 01/07/05
It is not..  Jeff Spicoli | 01/07/05
I agree in general  Michael Kelly | 01/07/05
agreed  Jeff Spicoli | 01/07/05
These Mozilla guys seem like real smart cookies  htotten | 01/08/05
yep  JTR_z | 01/14/05
What is so tough about it?  AmusedAtItAll | 01/08/05
The key word there is "Advanced"  Michael Kelly | 01/09/05
Nobody wants to admit...  calkins@... | 02/27/05
Okay, can a programmer help answer this question please?  Stellardyne | 01/07/05
Of course it it possible  rapson | 01/07/05
Nail, head, ouch  htotten | 01/08/05
Baloney  TrustMe_z | 01/13/05
Use Lynx!!!  nucrash | 01/07/05
I use link2  Michael Kelly | 01/07/05
im not a programmer...  linuxoverwindows | 01/08/05
btw  linuxoverwindows | 01/08/05
How about Firefox?  libertyaikido | 01/13/05
hmmm!  JTR_z | 01/16/05
nothing is idiot-proof  JTR_z | 01/14/05
Manual Broswer  smfriedland | 01/14/05
Pretty minor issue, but still should be addressed  ac2_z | 01/07/05
heres what i'd do  JTR_z | 01/14/05
A flaw is a flaw, report it, and not just on the company's forums  FilledOut | 01/07/05
Hi.  linuxoverwindows | 01/08/05
We advise all our co-workers to exercise their brain  FilledOut | 01/09/05
Let's put flaws into perspective...  qrdenameland1 | 01/08/05
My words exactly  davethebrave | 01/17/05
Firefox Flaw  chuck5406@... | 01/08/05
wah.  linuxoverwindows | 01/08/05
firefox  cardinal33 | 01/08/05
Do it.  PA-ITGuy | 01/08/05
as we tell our customers when they call...  linuxoverwindows | 01/08/05
Why a fiery debate?  IT Scion | 01/08/05
yeah  linuxoverwindows | 01/08/05
in a spoofed email, click a spoofed link to a.......  chiwawa | 01/09/05
Beware: Virus in your mail  dr_agon | 01/15/05
Use Firefox Because It's Better... Not Because It's More Secure  nikoli | 01/10/05
Better is subjective  rapson | 01/10/05
Better is not subjective  DeHaven | 01/16/05
Are you kidding?  Hey_Joe | 01/13/05
Extension starts solving spoofing problem  dl@... | 01/12/05
IE versus Firefox  mhjseiler@... | 01/13/05
Extension notifies user of faked sites  joeowens | 01/13/05
IE and FF flaws  cam3ca | 01/14/05
FireFox Vulnerability  DaveFeign | 01/14/05
How do I get FF securely?  BMoon | 01/14/05
its good  JTR_z | 01/14/05
what me worry?  BMoon | 01/14/05
IE6 "It's where the money is"  Baer | 01/14/05
Firefox vs. IE  rick.agolia@... | 01/14/05
Firefox vs. IE  rick.agolia@... | 01/14/05
Fire Fox  angelronny | 01/14/05
Security not the only issue  oldbilll | 01/14/05
Everything is better than IE  elreteipos | 01/15/05
Firefox=Hype  BobSchlesinger_z | 01/15/05
Silly comment  DeHaven | 01/16/05
The safety and useability of FireFox  rett@... | 01/15/05
The Problem with Open Source Programmers  jfreedle2@... | 01/16/05
And how long for tabs?  DeHaven | 01/16/05
Flaws- if everywhere choose the best  DeHaven | 01/16/05
Maxthon is Better than FireFox  BigFatLazyAss | 01/17/05
Notice from my isp re: port scan  casakl | 01/21/05
That's the problem  Jeffhs | 01/22/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here