[Pc_Support] If you haven't switched ... unpatched Firefox v. MS IE
...
Bryan J. Smith
b.j.smith at ieee.org
Mon Feb 13 15:12:46 EST 2006
Firefox has bugs and _can_ be hit by spyware by less savvy users as
well ...
... sent their crawlers to 45,000 Web sites ... 1.6 percent of
the domains infected the first IE configuration, the one
mimicking a naïve user blithely clicking 'Yes;' ... In the same
kind of configurations, Firefox survived relatively unscathed.
Only .09 percent of domains infected the Mozilla Corp. browser
when it was set, like IE, to act as if the user clicked through
security dialogs ...
But when the user _denies_ downloads ...
about a third as many domains (0.6 percent) did drive-by
downloads by planting spyware even when the user rejected the
installations ... no domain managed to infect the Firefox-
equipped PC in a drive-by download attack.
Let's read that again, out of approximately 45,000 web sites NO
DOMAIN MANAGED TO INFECT THE FIREFOX-EQUIPPED PC IN A 'DRIVE-BY
DOWNLOAD ATTACK'.
In other words, even _unpatched_ Firefox 1.0 results in *0* spyware
infections when you are not prompted out-of-the-box. Not *1* site
out of 45,000!
"Locked down" MS IE _still_ results in 0.6% of sites infecting you --
literally 270 sites out of the approximately 45,000 -- 1 out of every
163 sites you hit, even when MS IE has security turned _way_up_!
--
Bryan J. Smith Professional, Technical Annoyance
b.j.smith at ieee.org http://thebs413.blogspot.com
----------------------------------------------------
*** Speed doesn't kill, difference in speed does ***
More information about the Pc_support
mailing list