On GameSpot: $299 PS3 Slim and price cut announced!
BNET Business Network:
BNET
TechRepublic
ZDNet

June 28th, 2006

Maybe Firefox doesn't have a security edge after all

Posted by Ed Bott @ 6:00 am

Categories: Firefox, Internet Explorer, Security

Tags:

Kvetching about Microsoft security flaws is so 2002.

That thought came to mind today when I read a misleading and disingenuous post by Firefox evangelist Asa Dotzler. Now, Asa just got back from a trip halfway around the world. So I’m going to assume that it was jet lag that caused him to write and publish a post entitled microsoft security manager calls users stupid, which contained these fightin’ words:

A couple of months ago, Mike Danseglio, the Program Manager for the Security Solutions group at Microsoft blamed users for the Windows security nightmare, saying "there really is no patch for human stupidity."

Nice one, Mike.

Actually, Mike, there really is no patch for that kind of blame shifting. We make software and it’s our job to make it work. Designing and building software is an extremely complex process but it is not magic and it is not only possible to make it safe, it’s a requirement.

[...]

At Mozilla, we put the user first. Always. We spend our days working to improve the Web for users and to protect them from the bad guys. At Microsoft, at least some have decided it’s better spend their time calling users stupid and blaming them for the problem.

Zing! Boy, Asa, you really showed him, didn’t you? Too bad you took the quote completely out of context. Did Danseglio "blame users for the Windows security nightmare"? Judge for yourself. Here’s the full paragraph from Ryan Naraine’s eWeek article:

"Social engineering is a very, very effective technique. We have statistics that show significant infection rates for the social engineering malware. Phishing is a major problem because there really is no patch for human stupidity," [Danseglio] said.

Oh. Phishing is what we’re talking about here? (To their credit, several commenters on Asa’s post pointed out the same thing.) So how good is Firefox at handling phishing attempts? After all, one of the rotating text blurbs on the Firefox Start page boasts: “Browse the Web with confidence. Firefox protects you from viruses, spyware, and phishing.” Curiously, the linked page doesn’t mention phishing even once.

So I put it to the test. I just copied a link from one of the many phishing attempts I receive in my e-mail inbox every day and opened it in Firefox. Guess what? It opened right up, with no indication from Firefox that the site was suspicious or that I shouldn’t enter my Paypal login credentials there. In other words, if I do something stupid, I’m going to pay the consequences and maybe have my Paypal account cleaned out.

See for yourself:

eb_phish_firefox1.png

Looks pretty legit, doesn’t it?

I clicked on the Help menu in Firefox and typed in phishing. Nothing. I guess Firefox hasn’t gotten around to recognizing that phishing is a problem. Oh, wait, they have. But it’s only available in alpha code right now, not in a stable beta or a released version.

Now, IE6 doesn’t have any anti-phishing features, either. But what happens if I open the same page in IE7, which is available as a stable public beta? The results are pretty dramatically different:

eb_phish_ie7_1a.png

Internet Explorer blocks navigation to the page with a bright red warning icon and a clear explanation. The address bar turns red too, and clicking the Phishing Website badge to the right of the address displays this additional information:

eb_phish_ie7_2a.png

Advantage IE, at least for now.

Asa’s not the only one to grossly distort Mike Danseglio’s comments, as I’ve noted before. But the fact is that social engineering is still a brutally effective way to get people to download and install stuff that ultimately is going to harm them. And you can use just about any software to do it. It’s hard to engineer security that protects people from being fooled into doing stupid things. That’s true on the street, if you happen across a three-card monte game. It’s true on the web, too.

And as long as we’re talking irony, let’s talk about ActiveX. Most of the substance of Asa’s post is about ActiveX support in IE. He says:

For years, Mozilla struggled with website compatibility issues because it did not support Microsoft’s ActiveX technology, another major vector for security attacks on users. Not only would it have been a lot of work to reverse engineer and build Mozilla support for ActiveX, it would have opened Mozilla up to some of the worst threats on the Web. It would have been a bad idea.

So, what do I see when I open Asa’s home page in IE7?

eb_mozilla_activex.png 

Ha! (The ActiveX control used on his page is QuickTime, by the way, and don’t get me started.)

Once upon a time, Firefox had a big security advantage over IE. Today, not so much. Firefox has had four updates in the seven months since it was released. Each of those updates fixed one or more major security issues that could result in a user clicking a link or viewing a webpage and installing hostile code. If you miss an update, you’re vulnerable, even if you’re not stupid. In other words, Firefox isn’t so secure, either, and its developers are only human. (And don’t talk to me about Firefox’s Auto Update. I just checked the version of Firefox running on this machine. It’s 1.5.0.3, which means I’m a release behind and in mortal danger of getting zapped if I don’t update right away.)

But don’t take my word for it. Ask Adam Shostack, who has forgotten more about computer security than most so-called security experts know. He also knows a thing or two about phishing, as a quick perusal of his August 2005 essay, Preserving the Internet Channel Against Phishers, will attest. Adam just went to work for Microsoft, a development that raised lots of eyebrows in the security community. He explains:

In the past, I’ve heaped scorn on Microsoft’s security related decisions. Over the last few years, I’ve watched Microsoft embrace security. I’ve watched them make very large investments in security, including hiring my friends and colleagues. And really, I’ve watched them produce results.

In making this decision, I’ve had conversations with many people and organizations. The one theme that stands out was the difference in the conversations I had with Microsoft versus other software producers. Some of things that Microsoft does and are looking to improve haven’t even made it in rudimentary form anywhere else.

Ironically, some early versions of that essay appeared as posts on Shostack’s Emergent Chaos blog, under the titles Don’t Use Email Like a Stupid Person and More on Using Email Like A Stupid Person.

He’ll fit right in at Microsoft.

Ed BottEd Bott is an award-winning technology writer with more than two decades' experience writing for mainstream media outlets and online publications. See his full profile and disclosure of his industry affiliations.

Email Ed Bott

Subscribe to Ed Bott's Microsoft Report via Email alerts or RSS.

  • Talkback
  • Most Recent of 297 Talkback(s)
Test
URL www.zdnet.com (Read the rest)
Posted by: RealNonZealot Posted on: 03/26/07 You are currently: a Guest | | Terms of Use
Firefox doesn't have ActiveX...  ju1ce | 06/28/06
I forgot to add...  ju1ce | 06/28/06
Since I started using Firefox 0 viruses  Uralbas | 06/29/06
That might have been true in 2002  Ed BottZDNet Moderator | 06/28/06
I have  dragosani | 06/28/06
What would you suggest?  rapson | 06/28/06
Easy answer...  ju1ce | 06/28/06
By "it"...  rapson | 06/28/06
I can swear...  ju1ce | 06/28/06
Well...  rapson | 06/28/06
Know your browser  jmccormick79 | 06/28/06
If you are using IE 6.. It's two and the steps are quick and fast..  ju1ce | 06/28/06
An explicit problem...  ju1ce | 06/28/06
The other thing I've noticed...  ju1ce | 06/28/06
Stop running your machine as an admin....  toadlife | 06/28/06
Although I agree with your premise....  ju1ce | 06/28/06
Now what would be neat...  ju1ce | 06/28/06
Running as admin...  PB_z | 06/28/06
Bad analogy....  ju1ce | 06/28/06
That's a terrible analogy.  A_Pickle | 06/28/06
Windows Defender updates  PB_z | 06/28/06
Easy to disable ActiveX installations  Ed BottZDNet Moderator | 06/28/06
The point I'm making Ed...  ju1ce | 06/28/06
Right  Ed BottZDNet Moderator | 06/28/06
I agree on that point for sure...  ju1ce | 06/28/06
WHOA ED!!! WHOA!!!!!! STOP RIGHT THERE!!!!  ghekko | 06/28/06
Step away from the Caps Lock key  Ed BottZDNet Moderator | 06/28/06
What are you talking about ghekko?  Cayble | 06/28/06
Message has been deleted.  ghekko | 06/28/06
and another thing you losers have no clue about  ghekko | 06/28/06
Yes it is.....A BIG BAD one!  linux for me | 06/28/06
Uhm...  ju1ce | 06/28/06
Who cares about functuality!?!?  linux_for_me | 06/28/06
Asking the user is not secure  interlocutor | 06/28/06
What about everyone else  nomorems | 06/28/06
And what about Firefox?  Ed BottZDNet Moderator | 06/28/06
Ed... Now seriously...  ju1ce | 06/28/06
Again...  ju1ce | 06/28/06
IE5 is still supported  PB_z | 06/28/06
And that is some sort of defence because?  ju1ce | 06/28/06
I was responding to your sentence that mentioned IE5  PB_z | 06/28/06
You're just tryin' to get people stirred up, aren't ya Ed?  ghekko | 06/28/06
Not everyone uses XP sp2  IceTheNet@... | 06/29/06
And Is Still True Today  Lynne's Honey | 07/01/06
Not the point.  carlino | 07/02/06
open source and their social engineering.  zzz1234567890 | 06/28/06
wrong wrong wrong  ghekko | 06/28/06
Nice response  xuniL_z | 06/29/06
And your post gave us what knowledge  IceTheNet@... | 06/29/06
IE Still allows drive-by installs of spyware...  BitTwiddler | 06/28/06
Nonsense  Ed BottZDNet Moderator | 06/28/06
The users allow it, at least. IE allows them to.  johnay | 06/28/06
Excellent points!  NonZealot | 06/28/06
Big difference...  jasonp@... | 06/28/06
Big difference indeed  NonZealot | 06/28/06
In the life cycle of programming...  ju1ce | 06/28/06
Prove this, Ed.  Raymond Danner | 06/28/06
Raymond - Check your facts!  ScottKin | 06/28/06
You're wrong about everything  Ed BottZDNet Moderator | 06/28/06
Comaparing stable release of firefox to a BETA of IE7  zmud | 06/28/06
I have occasional crashes with Firefox  Ed BottZDNet Moderator | 06/28/06
Does the word BETA mean anything to you?  zmud | 06/28/06
ain't it cute how we can't criticize Vista though?  Spicoli the Cannoli | 06/28/06
Firefox 2 is not in beta, it's in Alpha  Ed BottZDNet Moderator | 06/28/06
Why include anything in beta?  jasonp@... | 06/28/06
Mike Cox does. wink (NT)  ju1ce | 06/28/06
Boy Ed...  nomorems | 06/28/06
FF2 = IE7 EOS....  ju1ce | 06/28/06
Ju1ce and Ed  OmegaFirebolt | 06/28/06
Actually quite the opposite...  ju1ce | 07/04/06
well..  Spicoli the Cannoli | 06/28/06
Gold code is gold code...  jasonp@... | 06/28/06
thanks...  bghost | 06/28/06
At This Point ED....  Systemic Chaos | 06/28/06
that was my 1st thought  fireman949 | 06/29/06
No, it doesn't.  PB_z | 06/28/06
IE's phishing protection question  tic swayback | 06/28/06
More info  mdemuth | 06/28/06
It doesn't come from reports -  Confused by religion | 06/28/06
Access  tic swayback | 06/28/06
cute Milly  Spicoli the Cannoli | 06/28/06
Yes, Jeffie -  Confused by religion | 06/28/06
I think you can still download it from MS  tic swayback | 06/28/06
Pong Rocks!!  Confused by religion | 06/28/06
No, Milly  nomorems | 06/28/06
Yellow bar for suspicious sites  Ed BottZDNet Moderator | 06/28/06
Thanks  tic swayback | 06/28/06
Can you show th FULL URL in the URL FF box in your example ?  michael_t | 06/28/06
I'm not going to provide a link to a bad site  Ed BottZDNet Moderator | 06/28/06
So you clicked on "www.paypal.com.Iwillripyouoff.org" ? Didn't you?  michael_t | 06/28/06
Lookout Ed!!!  NonZealot | 06/28/06
and especially you only know too well... happy don't you ? nt  michael_t | 06/28/06
Hey Milky! Hows it going?  Cayble | 06/28/06
Sigh...  Ed BottZDNet Moderator | 06/28/06
Message has been deleted.  ghekko | 06/28/06
How do you figure that?  Shelendrea | 06/28/06
Just try to read my entire OP.  michael_t | 06/28/06
Hey Milky! Let it go! You lose this one!  Cayble | 06/28/06
flamefest! Flamefest! Gayble is flaming!  ghekko | 06/28/06
Hahahahaha!!  Spicoli the Cannoli | 06/28/06
OK, you clicked on "www.paypal.com.ebaysecurity-burb-.com"  michael_t | 06/28/06
Heuristics and reporting  Ed BottZDNet Moderator | 06/28/06
No, Ed.  nomorems | 06/28/06
Ha ha ha ho ho ho  Ed BottZDNet Moderator | 06/28/06
Bwah ha ha he he heee!  nomorems | 06/28/06
Seriously: only encryption and authentication can  michael_t | 06/28/06
Message has been deleted.  ghekko | 06/29/06
as always...  strykrforce | 06/29/06
Indeed...  JDThompson | 06/28/06
I've explained this repeatedly...  Ed BottZDNet Moderator | 06/28/06
Yup.  JDThompson | 06/28/06
You're still missing the point  Ed BottZDNet Moderator | 06/29/06
Hey Milky!  Cayble | 06/28/06
So in other words...  Ed BottZDNet Moderator | 06/28/06
Message has been deleted.  ghekko | 06/29/06
Test  RealNonZealot | 03/26/07
Test  RealNonZealot | 03/26/07
IE Phishing  Piper8 | 06/29/06
1) EVEN IF we accept that in this respect IE behaves "better" than  michael_t | 06/28/06
Nothing "carefully hidden"  Ed BottZDNet Moderator | 06/28/06
I find that hard to believe  JDThompson | 06/28/06
Believe what you want  Ed BottZDNet Moderator | 06/29/06
re Nothing "carefully hidden"  itsjazzy | 06/29/06
IE 7 Beta 3 Phishing detection  johnfatz@... | 07/01/06
so, you think the author is lying?  bghost | 06/28/06
I tried to reply but I got a  michael_t | 06/28/06
No.  JDThompson | 06/28/06
yes, it's true Ed can't build a simple site, let alone a phishing one  ghekko | 06/29/06
Emails  ArthurDent | 06/28/06
and I agree wiith you 110% here, but his point was that  michael_t | 06/28/06
Not true  Ed BottZDNet Moderator | 06/29/06
Calm Down Milky, your getting excited again! Ha!  Cayble | 06/28/06
a comparison to beta software  Spicoli the Cannoli | 06/28/06
Who said that?q  Ed BottZDNet Moderator | 06/28/06
It's ZDNet MO  Spicoli the Cannoli | 06/28/06
I am not ZDNet  Ed BottZDNet Moderator | 06/28/06
I realize that..  Spicoli the Cannoli | 06/28/06
You said that, if you Agreed to the License Agreement  mejohnsn | 06/28/06
Nothing like that in the license  Ed BottZDNet Moderator | 06/29/06
Who CARES !!!  nomorems | 06/28/06
They don't want you.  John Zern | 06/28/06
Spyware is the biggest problem, not phising  DarthRidiculous | 06/28/06
YOUR fault  Confused by religion | 06/28/06
You pretty much HAVE to run as admin...  BitTwiddler | 06/28/06
What???  NonZealot | 06/28/06
Absolutely right  Ed BottZDNet Moderator | 06/28/06
The problem with limited...  ju1ce | 06/28/06
Keep old computers/OSes around for legacy software  PB_z | 06/28/06
I have a few suggestions  Mark Miller | 06/28/06
Absolutely not true  rapson | 06/28/06
HUH?  Confused by religion | 06/28/06
Any competant IT department must have NON-admin users.  PB_z | 06/28/06
Gerald is absolutely right.  BitTwiddler | 06/28/06
Show me a drive-by install in XP Sp2  Ed BottZDNet Moderator | 06/28/06
WGA  nomorems | 06/28/06
WGA is not driveby, the user explicitly agrees to install it (NT)  PB_z | 06/28/06
Sure they do, they click on everything they see without reading it (nt)  CobraA1 | 06/28/06
WGA is not driveby, the user explicitly agrees to install it (NT)  siarad | 06/28/06
It may be spyware, but you agreed to it  PB_z | 06/28/06
All Sorts of Them  SecurityGeek_z | 06/28/06
And that's why you run as limited user  PB_z | 06/28/06
I totally agree  SecurityGeek_z | 06/29/06
Not quite true  k12IT | 06/28/06
Here come the appoligists.  No_Ax_to_Grind | 06/28/06
Apologist  baggins_z | 06/28/06
"you kill my father,  Spicoli the Cannoli | 06/28/06
ROTFL  Shelendrea | 06/28/06
Sorry, No_Ax.  nomorems | 06/28/06
Walk the talk Ed  Langalibalene | 06/28/06
blame the criminals  corticus | 06/28/06
ActiveX is not on Asa's site  red_wolf(at)nospammail.net | 06/28/06
Oh, I see...  Ed BottZDNet Moderator | 06/28/06
Weak response, Ed  anthroguy | 06/28/06
I never called anyone a pimp  Ed BottZDNet Moderator | 06/28/06
you're right ed, you're not a pimp...  ghekko | 06/28/06
Fair and balanced response  anthroguy | 06/29/06
Ed's just fanning flames  ghekko | 06/28/06
Weak Question buddy  Cayble | 06/28/06
Who died and made you god, you're just Eds' neobuddy  ghekko | 06/28/06
Read your own post man  Cayble | 06/28/06
I tried to find it  tombalablomba | 06/28/06
See the code below  Ed BottZDNet Moderator | 06/28/06
small question Ed  tombalablomba | 06/29/06
Yes, but...  Ed BottZDNet Moderator | 06/29/06
Ah indeed  tombalablomba | 06/29/06
Yes it is. Here is the code from the page  Ed BottZDNet Moderator | 06/28/06
Bad Ed...  OmegaFirebolt | 06/29/06
You don't think it's ironic...  Ed BottZDNet Moderator | 06/29/06
No, not ironic at all  OmegaFirebolt | 06/29/06
Did you just get back from a long flight?  red_wolf@... | 06/29/06
Maybe it's a Windows thing  JDThompson | 06/28/06
Pretty simple  tombalablomba | 06/28/06
Actually, it looks like a third-party extension  Ed BottZDNet Moderator | 06/28/06
Nope  tombalablomba | 06/28/06
How true!  msdead | 06/28/06
outlook 2007  einsteintech | 06/28/06
Nothing to tell you that the site is fake?  JDThompson | 06/28/06
Spoofstick  JDThompson | 06/28/06
Several IE extensions as well  Ed BottZDNet Moderator | 06/28/06
Again, the user has to look at the address bar  Ed BottZDNet Moderator | 06/28/06
The problem with that...  JDThompson | 06/28/06
You need to try it before you make statements like that  Ed BottZDNet Moderator | 06/28/06
Is that anything like...  ghekko | 06/28/06
You can continue if you want to.  jskline0@... | 06/28/06
Don't judge a book by its cover...  MyChangedLife777 | 06/28/06
You Can't Fix Stupid  davidr69 | 06/28/06
IE7 isn't out yet.  CobraA1 | 06/28/06
Actually, IE7 is out  Ed BottZDNet Moderator | 06/28/06
Incorrect  SecurityGeek_z | 06/28/06
Research before you write  Ed BottZDNet Moderator | 06/28/06
YOU need to be doing research, Ed  SecurityGeek_z | 06/29/06
Sigh  Ed BottZDNet Moderator | 06/29/06
Ha! So what.  Cayble | 06/28/06
Message has been deleted.  ghekko | 06/28/06
Yah, Flawless...  OmegaFirebolt | 06/29/06
Correction  OmegaFirebolt | 06/29/06
crashing every 15 min?!?!?!  corticus | 06/29/06
Fully out, as in released, or still just beta?  CobraA1 | 06/28/06
You should be designing your page around IE7 now  Ed BottZDNet Moderator | 06/28/06
I know, and it's great, but . . .  CobraA1 | 06/28/06
that's ok they'll wait a year or two to..  ghekko | 06/29/06
I'm not a moderator here  Ed BottZDNet Moderator | 06/29/06
Message has been deleted.  ghekko | 06/29/06
How about we design around a standard?  spmtrapr@... | 06/29/06
Amen  red_wolf@... | 06/29/06
My webpage works in FF, IE6, IE7, no stupid HTML hacks  CobraA1 | 06/29/06
Why spend your time reading when you could be browsing with Firefox  IceTheNet@... | 06/29/06
Update, it worked, but IE7 was unstable.  CobraA1 | 06/29/06
Please Ed  tombalablomba | 06/29/06
RE: You should be designing your page around IE7 now  kenw@... | 07/01/06
Nonsense  Ed BottZDNet Moderator | 07/01/06
A Smith and Wesson beats 4 aces  Resuna | 06/28/06
powered by evil huh?  ghekko | 06/29/06
Hmmm...  msdead | 06/28/06
maybe not....  bluestreak_z | 06/28/06
this is a stupid rant  ghekko | 06/28/06
foolish comment  EndUserMike | 06/29/06
anybody can be biased  yogeee | 06/29/06
what decision?  EndUserMike | 06/29/06
The point of the article was...  yogeee | 06/29/06
at times Firefox is very vulnerable  jimk_z | 06/28/06
and sad and lonely and ...  michael_t | 06/28/06
gawrsh I skeeered  ghekko | 06/28/06
crescit eundo  not of this world | 06/28/06
You from New Mexico?  Ed BottZDNet Moderator | 06/28/06
Neener Neener, sure showed them upstarts!  spmtrapr@... | 06/28/06
Message has been deleted.  ghekko | 06/28/06
Upstarts?  solri | 06/30/06
Message has been deleted.  bullduck | 06/28/06
Message has been deleted.  ghekko | 06/28/06
Get the plugin! (Speaking of stupidity)  Sioen | 06/28/06
IE has these add-ons too  Ed BottZDNet Moderator | 06/29/06
Who are you trying to convince.  IceTheNet@... | 06/29/06
You just hate MS  theraven_z | 07/19/06
Exaggeration and Misquotation  mejohnsn | 06/28/06
Message has been deleted.  ghekko | 06/28/06
Thinking about this  tombalablomba | 06/28/06
Message has been deleted.  ghekko | 06/29/06
Comparing an IE7 beta to a Firefox release!?!?  ihatelinux | 06/29/06
Gates dosn't work here anymore, actually he never did.  IceTheNet@... | 06/29/06
Silly silly silly  Ed BottZDNet Moderator | 07/01/06
Quoting out of context  alpha_server | 06/29/06
Check what you say  marinip | 06/29/06
Dragon  IceTheNet@... | 06/29/06
ED, HOW DARE YOU??  victor@... | 06/29/06
Ada's credit just went to crap in my book!  BillyG_n_SC | 06/29/06
I think in all our books  IceTheNet@... | 06/29/06
Not living in any of those countries  oreillysa | 06/29/06
Message has been deleted.  ghekko | 06/29/06
Message has been deleted.  ghekko | 06/29/06
Thanks  TN-Limey | 06/29/06
Don't be so hard on users  oreillysa | 06/29/06
Voice of reason  TN-Limey | 06/29/06
Alas, Some Truth!  MyChangedLife777 | 06/29/06
No Your Right  IceTheNet@... | 06/29/06
Bravo!  anthroguy | 06/29/06
Message has been deleted.  yogeee | 06/29/06
Not ideal but still better  TripleII | 06/29/06
I agree!  MyChangedLife777 | 06/29/06
"there really is no patch for human stupidity."  Reverend MacFellow | 06/29/06
Why does it seem that ZDNet is on MSFT's Payroll?  JGetchel | 06/29/06
What about netscape?  yogeee | 06/29/06
stable beta vs. unstable beta  geno_zd | 06/29/06
Firefox isn't the best thing  yogeee | 06/29/06
Probably but it is better than the alternatives.  IceTheNet@... | 06/29/06
Stupid is the wrong word.  papatator | 06/29/06
core values (firefox is unfit?)  yogeee | 06/29/06
CNET Especialy on these boards has thrown that out the window.  IceTheNet@... | 06/29/06
Phishing is a bad problem, IE does have advantage for now...  LilBambi_z | 06/29/06
Don't believe everything you read here.  IceTheNet@... | 06/29/06
Newsflash, Bott: Firefox kicks IE's ass on security any day of the week!!  DeepFreeze3 | 06/29/06
Thanks for the advice  Ed BottZDNet Moderator | 06/29/06
Do you use a wheelbarrow and shovel...  Cayble | 06/29/06
Valid Criticism  TN-Limey | 06/30/06
RE: Maybe Firefox doesn't have a security edge after all  kenw@... | 06/30/06
so how does this protect the "average user"?  ~doolittle~ | 07/01/06
Message has been deleted.  myfevertoy | 10/22/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

advertisement

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here