On TechRepublic: Windows 7: Slower to boot than Vista?
BNET Business Network:
BNET
TechRepublic
ZDNet

August 3rd, 2006

IE7 or Firefox 2: Which browser is more secure?

Posted by Ed Bott @ 5:51 am

Categories: Firefox, Image Galleries, Internet Explorer

Tags:

In Focus » See more posts on: Vista Galleries

Microsoft and Mozilla are on a collision course, both racing to complete major updates to their flagship web browsers scheduled for release this fall. Over the past two years, Firefox has zoomed from nowhere to gobble a significant chunk of market share at Internet Explorer’s expense. The biggest selling point for Firefox is its generally better record on security issues; so it’s no accident that Microsoft has paid significant attention to beefing up security features in Internet Explorer 7.

Both browsers are officially out in widely available public beta releases (Internet Explorer 7 Beta 3 and Firefox 2 Beta 1), so it’s a good time to compare how well each one performs.

For this report, I’ve put together an image gallery that shows exactly how the Windows XP version of each browser performs when faced with common security threats.

And what are those threats? Basically, everyone who spends any significant time on the Internet has to be mindful of the following four threats:

  • Exploits that attack unpatched vulnerabilities in program code. This is the worst threat of all, because a successful attack can give an intruder complete control of your computer and every bit of information on it.
  • Deceptive downloads. Some of the nastiest bits of spyware and malware walk through the front door, disguised as or piggybacking along with benign or harmless-sounding programs.
  • Phishing attempts. The most popular form of browser-based crime in 2006 is the phishing e-mail, which tries to sucker its victim into filling in valuable personal information – bank passwords, credit card details – in a phony web form.
  • Hostile add-ons. A rogue program can be merely annoying – hijacking your home page and spewing unwanted pop-ups – or it can take the form of a Trojan horse or dialer that can drain its victim’s bank account.

Some of these threats are technical, but the majority take the form of social engineering. A computer user who has administrative rights over a computer can override any security feature or protective program. The challenge for the browser designer is to give the user enough information so that he or she can make an intelligent decision.

Let’s look at the two new browsers and compare how each one handles different threats.

EXPLOITS

There’s no shortage of vulnerabilities for either IE or Firefox. In the eight months since Firefox 1.5 was released, the Mozilla Foundation has published 56 security advisories, 26 of which involved vulnerabilities that “can be used to run attacker code and install software, requiring no user interaction beyond normal browsing.” Those flaws have been fixed in a series of six maintenance releases.

Counting the security bulletins for Internet Explorer is a little more difficult, because Microsoft doesn’t break them out neatly by product. Independent security researchers who’ve compared the two generally give the edge to Firefox; Secunia, for example, claims that 21 of 105 security advisories for Internet Explorer are currently unpatched, although only one is rated “highly critical.” By contrast, only three vulnerabilities are listed as unpatched for Firefox, and none of them are considered critical.

Brian Krebs, of the Washington Post, compared the records of Mozilla Firefox and IE6 and concluded:

For at least 38 days in 2005, IE was vulnerable to unpatched critical security flaws that were being exploited actively by viruses, worms and spyware. For at least 256 days last year, Internet Explorer contained unpatched vulnerabilities where the exploit method had been publicly disclosed but was not necessarily being used.

For Firefox, there were about 35 days in 2005 where exploit code for a known vulnerability was available for an unpatched flaw, and zero days when a worm or virus was known to be taking advantage of an unpatched flaw.

The theoretical edge goes to Firefox, but both companies have kept busy in recent years making updates available, and there’s no evidence that any widespread outbreak of malware has been attributable to unpatched vulnerabilities in either one.

Will IE7 improve this spotty record? Perhaps. According to Microsoft’s Tony Chor, a Group Program Manager on the Internet Explorer team, part of the problem was old, sloppy code. “Over time, IE had developed 13 or 14 different places in the code where we place URLs. Inconsistent results allowed us to get beat. This is where we rearchitected a big part of IE so that one routine evaluates the URL.” Microsoft is betting that the new URL parser will make it easier for developers to avoid vulnerabilities in the first place and to fix them more quickly when they do appear. But only time will tell whether that effort will pay off as expected.

DOWNLOADS

Both browsers put plenty of speed bumps in the way of any program code you want to download. Whether you use IE7 or Firefox 2, you’ll need at least three clicks (and sometimes several more) to download and install a program.

On this score, at least, IE has a better set of features to prevent users from being tricked into downloading a program they really don’t want. In IE7, a download dialog box will only appear if you click a link that leads directly to that download. If a website designer uses script to try to pop up a download box and force you to deal with it, IE intercepts the script and displays a prompt in the Info bar instead.

eb_ie7_download_01_small.png

The Info bar doesn’t interfere with navigation, and you can ignore it completely if you want to. By contrast, Firefox permits web pages to trigger a download dialog box that has to be dealt with.

 eb_ff_download_01.png

In addition, IE provides more information about the publisher of a program as well as whether the program is digitally signed. That’s not necessarily a big advantage for users, however, especially when dealing with publishers who are actively trying to deceive them. During the course of testing, I found one program that had been digitally signed using a legitimate certificate but phony information, and two others that had been signed using homemade certificates, including one from – no kidding – Joe’s-Software-Emporium.

eb_ie7_download_sig.png 

PHISHING

Both IE7 and Firefox 2 include features designed to prevent users from being tricked by phishing attempts. Neither set of features is completely new; Microsoft’s version appeared in its MSN toolbar for IE6 last year, while the Firefox equivalent first appeared as the Google Safe Browsing extension and later in the Google Toolbar for Firefox.

Both programs claim to use similar techniques, analyzing the URL, the page content, and the structure of the page. In addition, both programs use external blacklists that are updated regularly. Firefox displays this pop-up balloon:

eb_ff_phishing_01_small.png

While IE7 displays a blood-red badge and warning box:

eb_ie7_phishing_01_small.png 

It’s difficult to test any phishing filter with authority. ISPs shut down most phishing sites when they’re reported, so any link that’s more than a day or two old is likely to lead to a 404 error. The two “live” sites I visited in each browser hardly constitute a scientific sample, but it’s still worth noting that IE7 flagged both pages as confirmed phishing sites, while Firefox 2 missed them both. In my experience with IE7 over the past few months, it’s been consistently accurate, flagging suspicious sites with a yellow label and turning them into confirmed sites within a matter of hours. I haven’t spent enough time with the Firefox/Google code to form an opinion.

Update 4-August, 8:30AM PDT: To rule out the possibility that there was something wrong with my initial test platform, I've now retested the anti-phishing features in Firefox 2 Beta 1 on two different machines with four different phishing URLs. All of them were flagged by IE7 Beta 3, but Firefox wasn't able to identify any of them. I repeated the test with the Google Toolbar for Firefox on Windows XP with Firefox 1.5.0.6 with identical results. See this post for more details.

Update 4-August, 3:40PM PDT: A representative of Mozilla's PR agency contacted me and says that the anti-phishing feature in Firefox 2 Beta 1 "was intended to test the core Phishing Protection framework within the browser, not to provide a full list of suspected scam sites."

BROWSER ADD-INS

Last, but certainly not least, is this category, which includes IE7’s infamous ActiveX feature. Conventional wisdom blames most spyware installations on ActiveX prompts and “drive-by downloads,” but that reputation may be based on behavior from a bygone era.

First, some definitions. ActiveX controls are simply binary code that runs inside the browser. It’s a powerful way to bring the power of local computinfg resources into the browser; unfortunately, it’s also been a vector for unscrupulous software makers to push spyware, pop-ups, and home-page hijackers onto unsuspecting users’ machines.

Before Windows XP Service Pack 2, if you used IE to visit any web page that contained an ActiveX control, it could display a dialog box inviting you to install that software, and spyware vendors specialized in making those controls sound like essential system patches. Because the old-style ActiveX dialog box resembled a system prompt, it was easy to trick users into installing unwanted software by pitching it as a required update. And if the user said no, well, pop up that dialog box again, and keep doing it until you wear down his resistance.

In post-SP2 versions of IE, including IE7, ActiveX prompts appear in the Info bar, where they don’t interfere with navigation and can be safely ignored. In addition, a page can prompt the user only once – no more multiple requests to install a piece of software. In fact, the behavior is essentially identical to any other software download

In addition, IE7 adds a mechanism to prevent sites from exploiting controls that are already installed on your PC, such as those included with Windows. The so-called ActiveX opt-in provides a warning message when any page tries to use a control it didn’t install. In IE7, it’s literally impossible for an ActiveX control to do a “drive-by install” – it requires the, um, active participation of the user.

eb_ie7_activex_01_small.png 

Those changes make it far more difficult for spyware pushers to deceive an innocent and unsophisticated user, but they don’t eliminate ActiveX completely. And that’s probably a good thing. After all, at least a half-dozen high-profile Internet Explorer add-ins, including Macromedia Flash, QuickTime, and the iTunes Music Store use ActiveX controls – not to mention Windows Update and a host of small but useful tools like Crucial Technology’s System Scanner and the test suite from PC Pitstop.

And what about Firefox? It doesn’t do ActiveX, so it’s perfectly safe, right?

Well, not exactly. Firefox has its own add-on model with its own set of security issues. A poorly written or hostile Firefox extension can cause serious problems. The popular Greasemonkey extension had to be yanked last year after security researchers uncovered a serious security flaw. And a security researcher earlier this year wrote a simple extension that sniffs HTML forms in search of passwords and sends the results to an e-mail address specified in the extension. Yes, the user has to choose to install that extension, but the same is true of ActiveX controls. In fact, extensions can even be used to install executable programs, a technique that Sun uses with its Java installation.

As a Mozillazine article noted earlier this year:

[T]he Mozilla Foundation has never claimed that extensions willingly installed by users are safe and it's long been known to the savvy that extensions can do practically anything once they are running on a user's system. However, it's worrying that some users believe that extensions are implicitly safe.

And there’s the bottom line. Come this fall, when both browsers are officially released, the playing field will essentially be level. Both IE7 and Firefox 2 add extra layers of protection and provide additional information to users to help them make intelligent decisions. In the final analysis, though, no browser can force a user to make smart or sane decisions. They can only point the right way.

Ed BottEd Bott is an award-winning technology writer with more than two decades' experience writing for mainstream media outlets and online publications. See his full profile and disclosure of his industry affiliations.

Email Ed Bott

Subscribe to Ed Bott's Microsoft Report via Email alerts or RSS.

  • Talkback
  • Most Recent of 190 Talkback(s)
Opera Rules
Opera 9.02 is simply the best web browser I have ever used. It beats IE, Firefox, Safari, Konqueror and all the rest hands down.

If you want the best experience online, use Opera.... (Read the rest)
Posted by: WebThingy Posted on: 10/06/06 You are currently: a Guest | | Terms of Use
One thing you did not point out ...  bportlock | 08/03/06
Agreed. Microsoft needs competition in all things to ensure improvements.  OliverSeal | 08/03/06
Lazy  tero_t_vaananen@... | 08/04/06
Another comparison  dnmott@... | 08/03/06
Uh, why?  lrocket | 08/03/06
no few people want to hear the answer  galileon | 08/03/06
because.....  mypl8s4u2 | 08/03/06
I think you?re largely correct?  Cayble | 08/07/06
I couldn't agree more  mdsmedia | 08/07/06
Uh, why?  joe6pack_z | 08/03/06
Shows how little people know on this board  IceTheNet@... | 08/04/06
Seriously?  Cayble | 08/07/06
What about Opera? (NT)  Scrat | 08/03/06
Opera was never IE's competition....  bportlock | 08/03/06
Oper 6 rules!  kokuryu | 08/03/06
IE is older and gets attacked more and is more compatible though with sites  erniem1970@... | 08/03/06
User Education  dannystaple | 08/03/06
Older? By what clock?  Bill F. | 08/03/06
IE tab firefox extention  clockmendergb@... | 08/03/06
correct.  shryko | 08/03/06
IE Is the "big guy"  Gazok | 08/31/06
Really?  fallentech | 08/03/06
Microsoft did, interestingly enough on my system.  jlhenry62 | 08/03/06
what happens I have seen is that the JVM of IE is Vunarable  IceTheNet@... | 08/04/06
Rubbish  Gazok | 08/31/06
Automatic update...  j.dupont | 08/03/06
It is just so nice not to have to worrie about that anymore.  IceTheNet@... | 08/04/06
IE is not MORE compatible  glocks out | 08/07/06
I don't think that's the question anymore...  A_Pickle | 08/03/06
don't forget  fallentech | 08/03/06
"costomizable"?  rick@... | 08/03/06
spell checker  mdsmedia | 08/04/06
what if  wexwimpy@... | 08/04/06
question assumptions  gdstark13 | 08/03/06
The missing link  Mark_L | 08/03/06
RE: The missing link  gdstark13 | 08/03/06
no, there's an easier way  galileon | 08/03/06
RE: no, there's an easier way  gdstark13 | 08/03/06
Times have changed  dannystaple | 08/03/06
RE: Times have changed  gdstark13 | 08/03/06
you can have my  tombalablomba | 08/03/06
RE: you can have my  gdstark13 | 08/03/06
tried before...  xiaodre | 08/03/06
cd is slow  galileon | 08/03/06
absolutely right  jhwoods | 08/03/06
So what you're saying here...  Wolfie2K3 | 08/03/06
RE: TalkBack: Reply to message  gdstark13 | 08/03/06
It's Called the Internet.  klawsteve@... | 08/03/06
RE: It's Called the Internet.  gdstark13 | 08/04/06
Here's an example of why this won't work  Ed BottZDNet Moderator | 08/04/06
RE: Here's an example of why this won't work  gdstark13 | 08/04/06
No such thing as bug-free software  Ed BottZDNet Moderator | 08/04/06
RE: No such thing as bug-free software  gdstark13 | 08/07/06
Easy solution  FatherJ | 08/08/06
What i'm interested in  tombalablomba | 08/03/06
Approximately every 18 months  Ed BottZDNet Moderator | 08/03/06
*ahem* I heard that about OS releases, too, about five years ago...  Zeppo9191 | 08/03/06
Opera Beats IE and Firefox  stds | 08/03/06
Opera Beats IE and Firefox  mark.roberts@... | 08/03/06
tried opera...  xiaodre | 08/03/06
Yes they did almost 2 years ago.  h143570 | 08/03/06
Opera Rules  WebThingy | 10/06/06
I love the smell  Roger Ramjet | 08/03/06
I never understood  DemonX | 08/07/06
Please its not even close - Firefox vs. IE  rtdiaz | 08/03/06
A little exaggeration  JDThompson | 08/03/06
To the devil's advocate...  msolgeek | 08/04/06
Propaganda, Propaganda, Propaganda...  Wolfie2K3 | 08/03/06
Yes, your post os chock full of propaganda...  msolgeek | 08/04/06
Your credibility goes to zero  Ed BottZDNet Moderator | 08/04/06
OMg credibilty to Zero!  DarqueSocks | 08/04/06
DARNIT  DarqueSocks | 08/04/06
any chance ZD could add...  mdsmedia | 08/04/06
Previous Message and Next Message  Ed BottZDNet Moderator | 08/04/06
Schmingo.  snoobar | 08/04/06
I agree, but...  Ed BottZDNet Moderator | 08/04/06
RE: Previous Message and Next Message  barsteward | 08/04/06
No, as Barsteward says, ....  mdsmedia | 08/05/06
"security wars" miss the point  code_flogger | 08/03/06
Have you looked at IE7?  Ed BottZDNet Moderator | 08/03/06
Much improved, but still not up to par. wink (nt)  OliverSeal | 08/03/06
And then there's the "IE is only available on Windows" thing.  Zogg | 08/03/06
In case you haven't noticed...  Ed BottZDNet Moderator | 08/03/06
Gee, don't you want new readers?  Zogg | 08/03/06
New readers ARE welcome...  Wolfie2K3 | 08/03/06
blog about Microsoft products  clockmendergb@... | 08/03/06
Agreed, but...  Ed BottZDNet Moderator | 08/04/06
If this is a blog about only Microsoft  mosborne | 08/04/06
Read, please  Ed BottZDNet Moderator | 08/04/06
Re: Read, please  mosborne | 08/04/06
I don't "ignore other platforms"  Ed BottZDNet Moderator | 08/04/06
And if I decide I like IE7 so much...  barsteward | 08/04/06
yes, but...  mdsmedia | 08/05/06
A bit dismissive, aren't you?  mosborne | 08/04/06
Please read again  Ed BottZDNet Moderator | 08/04/06
Not dismissing what your blog concentrates on, BUT...  mdsmedia | 08/04/06
Well, OK, but  Ed BottZDNet Moderator | 08/04/06
I'm replying here because I couldn't ...  mdsmedia | 08/05/06
Kam badet vi.  snoobar | 08/04/06
You're right, it's not under my control  Ed BottZDNet Moderator | 08/04/06
I did read again. Opinion stayed the same  mosborne | 08/04/06
I still just don't get it  Ed BottZDNet Moderator | 08/04/06
Makes sense to test security on the most vulnerable OS wink  jjarman | 08/30/06
one more thought  jjarman | 08/30/06
What about Linux?  mypl8s4u2 | 08/03/06
Not my area of expertise  Ed BottZDNet Moderator | 08/03/06
Do you feel that you  barsteward | 08/04/06
Firefox on Windows is in my area of expertise  Ed BottZDNet Moderator | 08/04/06
Have you visited the Firefox dev team yet?  barsteward | 08/06/06
They don't answer my e-mails  Ed BottZDNet Moderator | 08/06/06
What would this prove?  Scrat | 08/04/06
Not testing vulnerabilities  Ed BottZDNet Moderator | 08/04/06
Digital certificate text.  Anton Philidor | 08/03/06
Agreed  Ed BottZDNet Moderator | 08/03/06
And when you can understand Microsoft's texts...  Anton Philidor | 08/03/06
I don't have such a problem with that...  Ed BottZDNet Moderator | 08/03/06
The FireFox version...  Anton Philidor | 08/03/06
That's cute, but...  Ed BottZDNet Moderator | 08/03/06
More difficult prose.  Anton Philidor | 08/03/06
Sorry for the confusion  Ed BottZDNet Moderator | 08/03/06
Thank you.  Anton Philidor | 08/03/06
Anton...  Ed BottZDNet Moderator | 08/04/06
the meaning is often silly.  plumnilly | 08/03/06
mmmmmm  barsteward | 08/04/06
What are you talking about?  Ed BottZDNet Moderator | 08/04/06
Anti-phishing  JDThompson | 08/03/06
I've written about Netcraft before  Ed BottZDNet Moderator | 08/03/06
OH Yaeee  Bob41 | 08/07/06
Which browser is more secure?  dataodo@... | 08/03/06
Credibility lost right here  Ed BottZDNet Moderator | 08/03/06
Interesting that you don't provide a source for any of these assertions.  not of this world | 08/03/06
You're joking, right?  Ed BottZDNet Moderator | 08/03/06
Really?  CobraA1 | 08/03/06
Guess what?  todbran@... | 08/07/06
so that it can be more compatable and more like IE  IronCladChicken | 08/08/06
Remember Emily Latella?  Ed BottZDNet Moderator | 08/08/06
Extensions, Plugins, ActiveX, and the like..  IAHawkeye | 08/03/06
That's how Windows Vista works  Ed BottZDNet Moderator | 08/03/06
That is a good development...  IAHawkeye | 08/03/06
Ed, did you compare  j.dupont | 08/03/06
ActiveX rant  CobraA1 | 08/03/06
Cobra...FF extensions just as insecure  Scrat | 08/04/06
Not exactly  Greenknight_z | 08/04/06
I'm not saying it's bulletproof  CobraA1 | 08/04/06
ActiveX is live and well  megame | 08/07/06
Easy answer which is driving change  rtb | 08/03/06
Believe that if you want to  Ed BottZDNet Moderator | 08/04/06
The one-dimensional cartoon world of IE7  whisperycat | 08/04/06
Nonsense  Ed BottZDNet Moderator | 08/04/06
Your requested link  whisperycat | 08/04/06
That's a quote from a reporter  Ed BottZDNet Moderator | 08/04/06
Off by default in Firefox, I meant to say  Ed BottZDNet Moderator | 08/04/06
You Can TURN IT ON!!  mdsmedia | 08/04/06
You miss the point  Ed BottZDNet Moderator | 08/04/06
another link  CobraA1 | 08/04/06
Still not adequate proof  Ed BottZDNet Moderator | 08/05/06
Your article attempts to seem unbiased..  mdsmedia | 08/04/06
Ahem  Ed BottZDNet Moderator | 08/04/06
the reasoning behind their opinions!!  mdsmedia | 08/04/06
And if the "facts" are completely wrong?  Ed BottZDNet Moderator | 08/05/06
I didn't say facts equal reasoning...  mdsmedia | 08/05/06
I have to agree  matth@... | 08/10/06
A good quote:  shryko | 08/03/06
What about Safari?  Anne Hiler | 08/04/06
I don't use a Mac  Ed BottZDNet Moderator | 08/04/06
Once again, it is NOT obvious....  mdsmedia | 08/04/06
Complain to the ZDNet editors, not to me  Ed BottZDNet Moderator | 08/04/06
point taken...  mdsmedia | 08/04/06
These Comments the Best Reading yet  OldTimer1 | 08/04/06
Hey, OldTimer1...  Jon N | 08/04/06
Couldn't agree more!!  mdsmedia | 08/04/06
This is really, really simple...  BitTwiddler | 08/04/06
I Don't Care  whoozhe@... | 08/04/06
funny  <--DaVoR--> | 08/05/06
Meta Issue  code_flogger | 08/07/06
It's right there in the third paragraph  Ed BottZDNet Moderator | 08/08/06
OPERA!!!!  r.adagio@... | 08/07/06
Digital signatures verification  thetargos | 08/07/06
No, IE is not Windows' shell  Ed BottZDNet Moderator | 08/08/06
Which browser is more secure?  Bob41 | 08/07/06
Lucky they have a broken sites option  TonyMcS | 08/07/06
But Opera works  TonyMcS | 08/07/06
Whats your companies website addy?  IronCladChicken | 08/08/06
Maxthon?  TonyMcS | 08/08/06
Firefox fan with a problem  bbbaldie_z | 08/08/06
I'm told it was a bug in 1.5.0.5  Ed BottZDNet Moderator | 08/08/06
I'll try again  bbbaldie_z | 08/08/06
Are you kidding me?  opensourcepro | 08/08/06
IE7 or Firefox 2  roboman1@... | 08/10/06
IE 7 B3 Installation Issues  jimjutte | 08/11/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here