On mySimon: Cotton Pajamas: Style While Lounging
BNET Business Network:
BNET
TechRepublic
ZDNet

By Michael Kanellos
Posted on ZDNet News: Mar 22, 2005 9:28:00 PM

SCOTTSDALE, Ariz.--Even with increased popularity, the Firefox Web browser won't face as many security problems as Internet Explorer, according to the president of the Mozilla Foundation.

"There is nothing that will be perfect," said Mitchell Baker, president and chief lizard wrangler of the Mozilla Foundation, during a panel discussion at PC Forum here. (PC Forum is owned by CNET Networks, publisher of News.com.)

Still, Firefox, developed by the Mozilla Foundation, won't harbor nearly as many security flaws as those that have Microsoft's Internet Explorer, and increasing popularity won't change that, Mitchell predicted.

Some critics challenge that assumption. Symantec CEO John Thompson and other security executives have claimed that open-source programs will become more vulnerable as they pick up more users, because more hackers will become attracted to it.

Last month, Mozilla issued a major security update to fix several flaws, including one that would allow domain spoofing.

"There is this idea that market share alone will make you have more vulnerabilities," Baker said. "It is not relational at all."

Part of Firefox's better security profile comes from how it is developed, compared with Internet Explorer, she said. "Not being in the operating system is a phenomenal advantage for us," Baker said.

Another benefit, Baker said, comes from the fact that Firefox does not support Active X plug-ins. For years, some consumers and analysts have dinged Firefox because it couldn't run Active X.

"It turns out it is only less convenient until you get hacked," she said. "Then it becomes a disadvantage."

Mozilla is part of an industry effort to create an Active X alternative that would let plug-in applications such as Macromedia Flash run within the Web browser without the security risks associated with Active X. Others involved in that effort include browser makers Opera Software and Apple Computer, and plug-in makers Sun Microsystems, Macromedia and Adobe Systems.

In general, classic code flaws tend to be fairly easy to fix once they are found, she said. More difficult problems to guard against are the ones that exploit human behavior, like phishing.

"In some of these cases, the solution is very difficult to determine," she said. "There are some circumstances where the speed won't be as fast."

On another note, Baker added that the open-source movement still faces some growing pains. Large commercial customers are often not completely comfortable with open-source licensing, particularly because they are familiar with traditional licensing models.

She also said that new forms of public licenses are inevitable, as are conflicts and inconsistencies between different public licenses.

"If someone comes up with something, they have the right to determine the terms under which they give it away," she said.

CNET News.com reporter Paul Festa contributed to this report.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 174 Talkback(s)
Bigger work pool bigger standard
The richest man in the world Bill Gates got his money via Microsoft the big bad Corp. After these years of being on top and charging what they charge for software, if any Win PC or Win Server doesn't ... (Read the rest)
Posted by: Hrothgar - PCLinuxOS User Posted on: 03/30/05 You are currently: a Guest | | Terms of Use
YES! Take THAT Microchumps!  Jeff Spicoli | 03/22/05
Mooooo  vdraken | 03/22/05
You've been having a bad week Victor!  Jeff Spicoli | 03/22/05
So Are You Stoned Now, Jeff?  PMC-CON | 03/22/05
"All I need are some tasty waves and cool buds..  Jeff Spicoli | 03/23/05
So you must be stoned.  nucrash | 03/23/05
Well you really didn't expect ...  ShadeTree | 03/22/05
Well..  Jeff Spicoli | 03/22/05
Where...  robradina@... | 03/22/05
Sure did. Right here.  raven1_z | 03/22/05
My point exactly . . .  Sheeva | 03/23/05
The only problem with what you said  htotten | 03/23/05
It's called peer review  Chad_z | 03/22/05
Reversed Logic  PMC-CON | 03/22/05
Source not needed to crack  uno@... | 03/22/05
Problem with your line of reasoning  NonZealot | 03/22/05
Granting your argument...  maxo_z | 03/23/05
maybe that's not entirely true  vladsim | 03/25/05
a web browser is not science  nrlz | 03/26/05
What is Science?  Hrothgar - PCLinuxOS User | 03/30/05
The Evidence of Apache  jg1013 | 03/22/05
Shhhhhhhh!  Jeff Spicoli | 03/22/05
good...  jdahs@... | 03/22/05
Why is it the users fault?  Richard Flude | 03/22/05
Uh oh, hope you like the taste of crow!  NonZealot | 03/22/05
It tastes just as I remembered  Richard Flude | 03/22/05
Now you've gone and made me feel bad  NonZealot | 03/22/05
Don't feel bad ...  PMC-CON | 03/22/05
It works as advertised  gitmo | 03/23/05
Home...  thutchins | 03/23/05
uh...  jdahs@... | 03/22/05
Really?  Richard Flude | 03/22/05
You're too amateurish to Post  PMC-CON | 03/22/05
PMC-CON writes  Richard Flude | 03/22/05
re:  jdahs@... | 03/22/05
Intuit Stuff, Even Microsoft Money, Office 2000  PMC-CON | 03/22/05
Think stupid  Hrothgar - PCLinuxOS User | 03/30/05
STOP MAKING SENSE!!!!!  sokushi jonez | 03/22/05
Certifications make no difference  GreatInca | 03/22/05
I believe they are called "Paper Tigers"  Xunil_Sierutuf | 03/22/05
What a fallacy  NonZealot | 03/22/05
Hmmmmm......Could it be  osreinstall | 03/22/05
I was thinking more of jihadists...  jdahs@... | 03/22/05
I was trying not to open a second front!  osreinstall | 03/22/05
conventional wisdom because it's true!  nrlz | 03/26/05
Comparitive to what degree?  Hrothgar - PCLinuxOS User | 03/30/05
We're just less targeted and we don't use MS's OS-embedded middlware  GreatInca | 03/22/05
So are you a ...  PMC-CON | 03/22/05
RIAA Question  Hrothgar - PCLinuxOS User | 03/30/05
Mozilla Security  hjrich | 03/22/05
Just two words: NO ACTIVEX  jones172 | 03/22/05
Ive listened and firmly don't believe  chris.savage@... | 03/22/05
LOL.. if you want to use your analogy.. read a "Consumers" magazine  Xunil_Sierutuf | 03/22/05
For years MS supporters have been asserting MS products superior ...  George Mitchell | 03/22/05
I dunno...  jdahs@... | 03/22/05
Bigger work pool bigger standard  Hrothgar - PCLinuxOS User | 03/30/05
Not A Basher But ,,,  PMC-CON | 03/22/05
As someone who...  BitTwiddler | 03/23/05
Story about IE  PBWizard | 03/28/05
Using the car analogy...  maxo_z | 03/23/05
you must work for microsoft  GillesR | 03/25/05
And since when this is news? (nt)  michael-t | 03/22/05
Only a lowlife M$hill would say otherwise..  Xunil_Sierutuf | 03/22/05
Now that's funny...  dhammond@... | 03/22/05
Mozilla is the better choice  pinpintalk@... | 03/22/05
Interesting...  robradina@... | 03/22/05
Great Response  PMC-CON | 03/22/05
This is propaganda, not fact.  PMC-CON | 03/22/05
It's the marketshare of Microsoft haters!  pzw@... | 03/22/05
Not quite  ejhonda | 03/23/05
Unsafe in any form  Moxie_z | 03/24/05
Mozilla Security  daring08 | 03/22/05
browsers  levbarg | 03/24/05
Just in case you haven't noticed......  wkeairns | 03/22/05
M$ WON  PBWizard | 03/28/05
Do you remember....  mikey55 | 03/22/05
May be safer but after adding 3rd party extensions & ...  tedman | 03/22/05
And Those Extensions ...  PMC-CON | 03/22/05
Reminds me of Netscape  tedman | 03/22/05
Mozilla? Safe?  benf_z | 03/22/05
25 million+ downloads later  Monkey_MCSE | 03/22/05
Where Did You get That Figure  phi_alpha_nu@... | 03/22/05
~  uno@... | 03/22/05
Right here on ZDNet  ejhonda | 03/23/05
Web Logs  PMC-CON | 03/22/05
Real usage statistics  Hrothgar - PCLinuxOS User | 03/30/05
W3C compliant  RicD_ | 03/22/05
W3C Compliancy is correct  Phoenix_1160BC | 03/23/05
A browser that works....  gumby830@... | 03/23/05
web pages working  PBWizard | 03/28/05
Mozilla  Bionator@... | 03/22/05
Mozilla - More secure than Microsoft IE  mike_elliott_sr@... | 03/22/05
Like comparing pickup trucks to electric cars  pcsupport@... | 03/22/05
Problematic analogy  ab@... | 03/23/05
Piclups and Eletric Cars  cybrangl | 03/24/05
Is Mozilla more secure than IE?  ab@... | 03/22/05
Philanthropic endeavors, my eye!  techboy_z | 03/23/05
Of Course Firefox is more secure  Digitalcomet | 03/22/05
Imagine, Symantec making any  bjbrock | 03/22/05
Imagine, Symantec making any  Moxie_z | 03/23/05
1.000.000 Times Better, Explorer is "GARBAGE  azshane | 03/22/05
Explorer is garbage...I agree..  msdiagnosed | 03/23/05
I Agree  GillesR | 03/25/05
I don't get it  wresnick | 03/23/05
Don't get it??  jeflars@... | 03/23/05
1,000,000 x 0 =?  Roger Ramjet | 03/29/05
We're More Secure  rsterrell3@... | 03/22/05
Does this even deserve comment  ab@... | 03/23/05
We're More Secure  Moxie_z | 03/23/05
Club Shepherd 2005 v1.00, I am Bridge_SMASH  Bridge_SMASH | 03/22/05
NO viruses Since Installing Mozilla  lvlybnch@... | 03/22/05
Mozilla? Safe?  windy@... | 03/22/05
Microsoft? Honest?  Moxie_z | 03/24/05
Firfox is slow, but safe  Joshivs | 03/22/05
Try extension  wexwimpy@... | 03/23/05
Re: Firefox  Scrat | 03/23/05
Trying to remain polite...  Googey10 | 03/23/05
Re: Trying to remain polite...  Scrat | 03/23/05
Link to statistics please?  jezter~ | 03/23/05
Re: Firefox Usage in Europe  Scrat | 03/23/05
It the User  voska | 03/23/05
re: it the User  79spitfire | 03/23/05
Amen!  ibkathy2008 | 03/25/05
Place your bets  ab@... | 03/23/05
Re: Anger?  Scrat | 03/24/05
Re: Re: Anger  ab@... | 03/24/05
What a moron.  Immanuel Tranz-Mischen | 03/25/05
Great, another loud-mouthed idiot....  Scrat | 03/29/05
Malware-free? Are you SURE about that?  Joel R | 03/23/05
Re: Malware-free  Scrat | 03/24/05
You are so full of crap your eyes are turning brown!!!  gumby830@... | 03/23/05
Re: LMFAO  Scrat | 03/24/05
Re: Firefox speed (or the lack thereof)  Scrat | 03/24/05
TalkBack: Reply to message Re: Firefox speed (or the lack thereof)  Zarel | 03/24/05
I sense some hostility  ab@... | 03/23/05
online debates?  ab@... | 03/23/05
Re: Hostility?  Scrat | 03/24/05
Re: Firefox  Moxie_z | 03/24/05
Re: Firefox  Moxie_z | 03/24/05
error 404  TokyoPete | 03/26/05
bread  PBWizard | 03/28/05
Not only more secure, more reliable...  msdiagnosed | 03/23/05
Well duh!!! We've been saying that M$ sucks for a while now!!  supoman | 03/23/05
The biggest flaw of all...  WillemGrooters | 03/23/05
Yeah, but...  ejhonda | 03/23/05
a couple of questions  wexwimpy@... | 03/23/05
Mozilla Security  subhunee | 03/23/05
Re: Mozilla / Firefox  Scrat | 03/23/05
IE sucks....Firefox rules  Ollis_z | 03/23/05
Yah....but  durban | 03/23/05
More secure than microsoft.  rhammock | 03/23/05
IE is proprietary, but  sauerb01@... | 03/23/05
Re: Education  Scrat | 03/24/05
Firefox  armandb2@... | 03/23/05
Yes, but don't pitch your IE just yet!  support@... | 03/23/05
What I like about Mozilla is...  MepisLINUXuser | 03/23/05
Reasons to switch to Firefox  wexwimpy@... | 03/23/05
Dude, Rock and Roll...  gumby830@... | 03/23/05
IE is integrated inextricably into Windows  dhecksel@... | 03/23/05
Security of web browsers  stevem_001 | 03/23/05
An oh so easy to update  housemd | 03/23/05
It is...  Zarel | 03/24/05
IE versus Netscape/Firefox/Mozilla  gmmonko | 03/23/05
Does this report have the correct by line.  agottschald | 03/23/05
We're More Secure  Moxie_z | 03/23/05
White or Yellow?  Hrothgar - PCLinuxOS User | 03/30/05
MS will always be more insecure  nnigam | 03/24/05
Firefox and Zone Alarm - Killer Security!  chris40 | 03/24/05
SP2 made IE too nosy  Cor Gutter | 03/24/05
Use IE! Viruses, crashes, pop-ups - all yours! happy  Yarichek | 03/25/05
Mozilla Firefox vs IE  ibkathy2008 | 03/25/05
Slow???????  ibkathy2008 | 03/25/05
I disagree with your statement  angelronny | 03/25/05
They are both unsafe  Wagadonga | 03/28/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads