On MovieTome: See the 'Prince of Perisa' Trailer!
BNET Business Network:
BNET
TechRepublic
ZDNet

December 3rd, 2007

Mozilla: Critical vulnerability in Microsoft flaw-counting

Posted by Ryan Naraine @ 2:34 pm

Categories: Apple, Botnets, Browsers, Data theft, Exploit code, Firefox, Google, Microsoft, Mozilla, Patch Watch, Pen testing, Responsible disclosure, Spyware and Adware, Vulnerability research, Zero-day attacks

Tags: Vulnerability, Jeff Jones, Microsoft Internet Explorer, Microsoft Corp., Mozilla Corp., Window Snyder, Web Browsers, Security, Internet, Ryan Naraine

Critical vulnerability in Microsoft flaw-countingMozilla security chief Window Snyder has dismissed Jeff Jones’s IE vs Firefox flaw-counting exercise as a useless public relations exercise that ignores tons of bugs that aren’t fixed until Microsoft ships service packs and major browser updates.

Snyder (left), a former Microsoft security strategist, said Jones use of publicly available data in his side-by-side comparison of the two browsers is not an accurate measurement of a browser’s security profile.

“Unfortunately for Microsoft (and for anyone trying to use this report as analysis of useful metrics) he does not count all the security issues. If he were able to count them all, Microsoft could get credit for all the bugs they fixed. He counts only the public issues, because that is all Microsoft will tell us about. Microsoft is worried that if it ever says it has fixed X security issues, the world will focus on that it had X vulnerabilities in the first place, not that they are now fixed and no longer a risk for users,” Snyder said in a hard-hitting response to Jones’s study.

Snyder, a pen-testing specialist who was responsible for security sign-off for Microsoft’s Windows XP SP2 and Windows Server 2003,  argues that the data used by Jones is a “small subset of all the vulnerabilities” affecting Internet Explorer.

[ SEE: IE vs Firefox: Microsoft crunches security numbers ]

“[The] vulnerabilities that are found through the QA process and the vulnerabilities that are found by the security folks they engage as contractors to perform penetration testing are fixed in service packs and major updates. For Microsoft this makes sense because these fixes get the benefit of a full test pass which is much more robust for a service pack or major release than it is for a security update,” she explained.

However,  Snyder adds, this means IE users have to wait sometimes a year or more to get the benefit of the QA work.

“That’s a lot of time for an attacker to identify the same issue and exploit it to hurt users. Sometimes it just takes time to put in a complicated fix. Anyone that has shipped a major piece of software can relate to that. But this is not the case for every internally found security issue. Extending this process to include fixes that are ready and just sitting on the tree waiting for the preferred vehicle to ship increases risk for users. But it sure keeps those bug count numbers down,” she added.

[ SEE: Firefox narrows patch deployment window

“If we as an industry would just acknowledge that counting bugs is useless then vendors could feel safe talking about what they are doing to protect users. At Mozilla we fix our bugs openly. When you count Mozilla security bugs you are seeing not just those that are reported externally, but also the ones that would be considered internal if we acted like most other software vendors,” Snyder said.

Mozilla vice president of engineering Mike Schroepfer also used his blog to offer a sharp response to Jones and call attention to the absence of real data on actual bugs affecting Microsoft products:

[T]here is no way for anyone outside of Microsoft to confirm how many vulnerabilities ever existed in Internet Explorer. In an earlier post the author of the study touts the benefits of the Software Developement Lifecycle (SDL) at Microsoft as a reason Vista is more secure. Surely one of the goals of this process is to identity and fix security bugs right? How many bugs were identified and fixed using the SDL during development? Your guess is as good as mine.

“Bug counts are meaningless, what matters is whether you are at risk or not,” Schroepfer declared.

Instead of counting bugs, Mozilla has long suggested that the time it takes to release — and deploy — software patches should carry more weight.   Snyder has proposed a “time to deploy” metric a better way  to measure a software vendor’s approach to securing customers.

“Time to deploy” is the length of time it takes for users to get a patch installed once the fix is available from the vendor.  This in effect gives Firefox a major advantage over IE because the browser’s default auto-updating mechanism significantly cut down on the time it takes to push a security upgrade down to end users.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 39 Talkback(s)
Well goody goody goody!
You can copy and paste. When did you learn
that?

You may not be insane (I never said you
were, did I?), but you might as well be,
judging by your ability to face reality.

You... (Read the rest)
Posted by: Ole Man Posted on: 12/05/07 You are currently: a Guest | | Terms of Use
I agree that vulnerability counts are mostly meaningless  NonZealot | 12/03/07
Actually  nilotpal_c | 12/03/07
One thing  Azriphale | 12/04/07
As we say in Hawaii . . . "mo beh tah"  brian ansorge | 12/04/07
Defense in depth requires defense.  Resuna | 12/04/07
What Else Is New?  itanalyst | 12/03/07
You are so clueless...  No_Ax_to_Grind | 12/03/07
And You're The ZDNet Jackass  itanalyst | 12/03/07
New York, New Haven, New Jersey, New Mexico, New Hampshire, New ....  D. T. Schmitz | 12/03/07
And I think the OSS will not accept any metric that...  ye | 12/03/07
Isn't that what Microsoft did ?  Intellihence | 12/03/07
NOBODY would ever admit being worse than Microsoft  Ole Man | 12/03/07
Not accept???  Update victim | 12/04/07
Grains of salt  No_Ax_to_Grind | 12/03/07
Grains of salt are like vulnerabilities  Ole Man | 12/03/07
Yes! 87% of statistics are made up on the spot. (NT)  I am Gorby | 12/03/07
RE: Grains of salt  NCWeber_z@... | 12/03/07
RE: Mozilla: Critical vulnerability in Microsoft flaw-counting  Intellihence | 12/03/07
Only untl the URI handler is handled  Intellihence | 12/03/07
And todays winner...  Cardinal_Bill | 12/03/07
Too funny. When the ABMers were "winning" vulnerability comparisons were...  ye | 12/03/07
Well...  ego.sum.stig@... | 12/03/07
He has demonstrated repeatedly  Ole Man | 12/03/07
I always love these opportunities to prove you wrong:  ye | 12/03/07
Well goody goody goody!  Ole Man | 12/05/07
Lower error rate by what metric?  ye | 12/03/07
Coverity  ego.sum.stig@... | 12/03/07
What makes Coverity the authoritative source?  ye | 12/04/07
Quality...  C4Ever | 12/03/07
Re:When the ABMers were "winning" vulnerability counts...  nilotpal_c | 12/04/07
Seriously, at a bare minimum  D. T. Schmitz | 12/03/07
But then, did not  GuidingLight | 12/03/07
Don't think so...  SpikeyMike | 12/04/07
RE: Mozilla: Critical vulnerability in Microsoft flaw-counting  MrViklund | 12/04/07
Does anybody actually believe these reports  rahn@... | 12/04/07
RE: Microsoft's "bug" numbers  bfilipiak@... | 12/04/07
Has anyone tried to compare...  Ginevra | 12/04/07
I just like Firefox  HapGail_HomeInMd@... | 12/04/07
More flackery  spincitysd@... | 12/05/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads