On mySimon: Stephen King - Salem's Lot
BNET Business Network:
BNET
TechRepublic
ZDNet

August 22nd, 2006

Firefox developers need to accept Microsoft help

Posted by George Ou @ 5:19 pm

Categories: Security, Vista

Tags:

ZDNet UK reporter Colin Barker reports that Microsoft is reaching out to Firefox developers.  Even though this is a generous offer for four days of free lab space and free one-on-one help, the response from many Firefox advocates went along the lines of we don’t need no stinking help from M$.  At the end of Colin Barker’s story, he even asks the question: "Firefox already runs successfully on existing Windows, Linux and Macintosh operating systems. Testing by ZDNet UK Reviews found that it also runs well in Vista beta 2, so it’s not clear why Mozilla would need help from Microsoft".

The root cause of these attitudes is the misconception that Firefox is perfect to begin with and that it doesn’t need help, much less than Microsoft.  But nothing could be further from the truth since Firefox has been plagued with even more exploits than Microsoft Internet Explorer within the last year.  While Internet Explorer 6 and 7 beta have had recent zero-day exploits as well, Mozilla is not immune and has more than its share of vulnerabilities.  Some of these zero-day threats on Firefox have been so serious that even a simple ` character embedded in a URL could have obtained the shell on Linux while other proof-of-concept exploits attack the Mac as well as Windows.

The truth of the matter is that any web browser regardless of the creator is one of the biggest threats to the modern day Internet-connected desktop computer.   To deal with this threat, Microsoft created a protected mode for IE7 on Windows Vista which is often called IE7+ [Update: Ed Bott says this name has changed].  IE7 without the + designates IE7 running on Windows XP without the protected mode feature.  Protected mode allows the web browser to run inside of a sandbox.  While the use of non-admin users protect the operating system against exploits on the browser, it doesn’t protect the user’s files.  This means a hijacked browser will be able to steal, delete, or encrypt your personal data for ransom.  With Vista’s protected mode, an exploited browser will only be able to exploit that current browser session and sniff key strokes entered in to the browser but not outside of the browser where it can damage system files or precious user data.  While browser session key logging is still a big problem, it’s a lot better than system level infection, system level key logging, and compromised user data.  Furthermore, a browser infected in protected mode isn’t persistent and a restart of the application will flush the infection.

When I spoke with Microsoft before WinHEC, Microsoft told me that Vista’s protected mode is available to any other browser vendor and this is probably one of the key areas that Microsoft will help Mozilla with.  The offer from Microsoft’s open source labs is a generous one and Mozilla developers should accept the invitation with open arms (which they seem to be doing).  Microsoft could have simply allowed Mozilla to continue the status quo and run in the user space on Vista and claimed a distinct advantage for IE7+ over Firefox on Vista, but they chose to offer free help and free lab space to get Firefox up to par with Vista’s enhanced security features.  This would ultimately benefit all Windows Vista users regardless of the browser they chose and Microsoft’s effort to reach out should be applauded. [UPDATE 8/24/2006: Mozilla accepts offer]

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 101 Talkback(s)
and your story is full of...........
Then I guess the lawsuits IBM brought against Billy Boy to recover their code was just an illusion. And the fact that he had patented code that was IBM's behind their backs was also a misunderstand. ... (Read the rest)
Posted by: jt524 Posted on: 09/03/06 You are currently: a Guest | | Terms of Use
The best way for MS to help is simply allocate a develper or two to submit  DonnieBoy | 08/22/06
This isn't real work?  georgeou | 08/22/06
There are a number of ways MS could help, but they just need to allocate  DonnieBoy | 08/22/06
George , George , George , Firefox is Open Source .  Intellihence | 08/22/06
George_Ou does any of this look familiar ?  Intellihence | 08/22/06
Yes, our IT department loves OSS  georgeou | 08/22/06
Then why do you post such obvious lies!  IceTheNet@... | 08/23/06
And don't forget the patches for the patches  barsteward | 08/23/06
I don't know his point but George, yours  tyn | 08/23/06
Wouldn't work...  jcg_z | 08/23/06
Wouldn't happen...  Spikey_Mike | 08/24/06
Throwing eggs  jcg_z | 08/24/06
What's this?!?!?  Arthas | 08/22/06
Hey, that's almost a good Mike Cox impression  georgeou | 08/22/06
Thanks!  Arthas | 08/22/06
The women is foul though  georgeou | 08/22/06
Will Code for Womens  nucrash | 08/23/06
Does Mike Cox work with you fellas at ZDNET ?  Intellihence | 08/22/06
No, but I wish he did  georgeou | 08/22/06
I could see his blog now  nucrash | 08/23/06
Mike Cox? HARDLY!  Wolfie2K3 | 08/23/06
hahah  nhac | 08/23/06
Welcome to Planet Ou  GW Mahoney | 08/22/06
Again, MS needs to SHUT UP, roll up their sleeves and get to work. Anything  DonnieBoy | 08/22/06
That doesn't make any sense...  jcg_z | 08/23/06
Remember the good old days...  D. T. Schmitz | 08/22/06
P.S.  D. T. Schmitz | 08/22/06
Ridiculous  toadlife | 08/22/06
VMware alone doesn't secure you  georgeou | 08/22/06
Let's hop into the Wayback Machine, Sherman  dave.leigh@... | 08/23/06
um...  xiaodre | 08/23/06
No. Read it again.  dave.leigh@... | 08/23/06
Microsoft is offering free office and lab space plus support  georgeou | 08/23/06
Give us your details  D. T. Schmitz | 08/23/06
Yes, so rediculous  toadlife | 08/23/06
You miss a key point about ActiveX  georgeou | 08/22/06
I could live without Active X,  nucrash | 08/23/06
Elixir  D. T. Schmitz | 08/23/06
Active X is Windows specific, not cross platform  B.O.F.H. | 08/23/06
Wrong  pkrdk | 08/23/06
So you say that Microsoft needs more Mozilla code?  B.O.F.H. | 08/22/06
How...  rapson | 08/23/06
Everyone who has parnered with Microsoft has  B.O.F.H. | 08/23/06
In the Beginning..........  jt524 | 08/25/06
Your story and analogy are absurd!  B.O.F.H. | 08/26/06
and your story is full of...........  jt524 | 09/03/06
amazing  richvball44 | 08/23/06
Sorry George...Wrong Again!  linux for me | 08/23/06
MR Ou you see to forgot this easy idea  Quebec-french | 08/23/06
Wouldn't the Sandbox offer proprietary lock-in?  nucrash | 08/23/06
FireFox & MS  elainecleo | 08/23/06
Re: "I would be very uneasy letting MS get their hands on any code."  Scrat | 08/24/06
Microsoft needs Firefox even more...  alphawiz | 08/23/06
If Microsoft wanted to help its open source.  IceTheNet@... | 08/23/06
You  Linux User 147560 | 08/23/06
Misplaced faith in Microsoft  bitfuzzy | 08/23/06
Do look a gift horse in the mouth,  Dr_Zinj | 08/23/06
Update needed  Robert Crocker | 08/23/06
He is orchestrating this  tic swayback | 08/23/06
thx Robert and tic...  Arm A. Geddon | 08/23/06
Beware of Greeks baring gifts!  kim@... | 08/23/06
Beware of Greeks....  d.esposito@... | 08/23/06
hate to think if it was  Arm A. Geddon | 08/23/06
"Add our vulnerabilities to yours, Firefox"  MildlyAmuzed | 08/23/06
Gross distortion of some facts  Langalibalene | 08/23/06
Mozilla BEWARE, study your history  lostinlodos | 08/23/06
but..  nhac | 08/23/06
Why Do You Work HERE! Lies All Lies.  IceTheNet@... | 08/23/06
No, your the Eye-Dee-Ten-Tee  nucrash | 08/23/06
better link!!!  nucrash | 08/23/06
That was for Ou: But Your a Dumb Donky 2  IceTheNet@... | 08/23/06
Mind if I stand up against stupidity.  nucrash | 08/23/06
Yes when you use stupid 2005 stats its mid 2006 Dumb Donky  IceTheNet@... | 08/23/06
I went to Secunia  toadlife | 08/23/06
Oh but those numbers are skewed  nucrash | 08/23/06
I don't think you understand the terms  IceTheNet@... | 08/23/06
Right On Dewd  nucrash | 08/23/06
Hold on, you're counting advisories, not vulnerabilities  georgeou | 08/23/06
We didn't want to scare the poor kid  nucrash | 08/24/06
And your point George?  bitfuzzy | 08/24/06
Firefox is Open Source  pkrdk | 08/23/06
History repeating ITself, DeJaVu  Media-Ted@... | 08/23/06
Firefox is doing fine!!!  richdave | 08/23/06
Firefox developers need to accept Microsoft help.  Mr. Roboto | 08/23/06
Like Roboto needs a brain  TonyMcS | 08/23/06
Like TonyMcS would know sarcasm if...  Mr. Roboto | 08/23/06
Offered Help  abbett@... | 08/23/06
What a laugh  Time_Safari_Master | 08/23/06
It might let them render pages properly  TonyMcS | 08/23/06
If it works on Opera, then standards are not the issue (NT)  Scrat | 08/24/06
"Microsoft is reaching out to Firefox......."  Senlac_Hill | 08/23/06
Microsoft helps?? Yea right!!!  as901 | 08/24/06
Firefox -Microsoft  clockmendergb@... | 08/24/06
you're right  lostinlodos | 08/24/06
Congrats George  nucrash | 08/24/06
You have links to confirm?  georgeou | 08/24/06
You must be the last at ZDnet to know  nucrash | 08/24/06
On vacation today and tomorrow  georgeou | 08/24/06
What the hell are you checking in for  nucrash | 08/25/06
So, after 20 years, they finally got around to putting Explorer in a sandbo  heres_johnny | 08/25/06
Netscape Guilty of that too  nucrash | 08/25/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads