Mozilla Counters "Dirty Dozen" Criticism of Firefox Security
Bit9, self-professed leader in enterprise application whitelisting, recently included Mozilla's Firefox browser among "the Dirty Dozen" applications with critical security vulnerabilities. Mozilla's security expert Jonathan Nightingale disputes that critique.
The Waltham, MA company has been issuing annual reports on Windows applications with the highest critical security problems. The most recent press release identifies "the Dirty Dozen," among which Firefox versions 2.x and 3.x rank at the top of the list, followed by Adobe Acrobat 8.1.2 and 8.1.1, Microsoft Windows Live (MSN) Messenger 4.7 and 5.1, Apple iTunes 3.2 and 3.1.2, and Skype 3.5.0.248.
According to Bit9, these applications have a few things in common. They run on Windows, are popular among users, and IT organizations don't consider them potentially malicious. The critical factors that put them on the Dirty Dozen list are that (a) at least one security hole was found, (b) they usually rely on users rather than IT admins to apply upgrades or patches, and (c) they can't be centrally updated with free enterprise tools. For the latter, Bit9 gives Microsoft's Systems Management Server (SMS) and Windows Server Update Services (WSUS) as examples.
Jonathan Nightingale from Mozilla's Human Shield group vehemently counters Bit9's assessment in a blog. He asserts that the "critical vulnerability reported in 2008" label penalizes software companies, such as Mozilla, with an open reporting policy about security problems. "To suggest that this openness is a weakness because it means that we have 'reported vulnerabilities' is to miss the reality: that software has bugs," he writes. For Nightingale, a more meaningful assessment would be to base "a product’s responsiveness to those bugs and its ability to contain them quickly and effectively."
Nightingale asserts that the vulnerabilities Bit9 found have long since been fixed, with most fixes within days of the announcement. He also considers Bit9's criticism of the lack of WSUS updating as ignoring real world experience in that Firefox's built-in update service spares users the trouble. "We consistently see 90% adoption within six days of a new update being released," he writes.
Comments
comments powered by DisqusIssue 261/2022
Buy this issue as a PDF
News
-
KaOS 2022.06 Now Available With KDE Plasma 5.25
The newest iteration of KaOS Linux not only adds the latest KDE Plasma desktop but sets LibreOffice as the default.
-
Manjaro 21.3.0 Is Now Available
Manjaro “Ruah” has been released and includes the latest Calamares installer, GNOME 42, and much more.
-
SpiralLinux is a New Linux Distribution Focused on Simplicity
A new Linux distribution, from the creator of GeckoLinux, is a Debian-based operating system with a focus on simplicity and ease of use.
-
HP Dev One Linux Laptop is Now Available for Pre-Order
The System76/HP collaboration Dev One laptop, geared toward developers, is now available for pre-order.
-
NixOS 22.5 Is Now Available
The latest release of NixOS with a much-improved package manager and a user-friendly graphical installer.
-
System76 Teams up with HP to Create the Dev One Laptop
HP and System76 have come together to develop a new laptop, powered by Pop!_OS and aimed toward developers.
-
Titan Linux is a New KDE Linux Based on Debian Stable
Titan Linux is a new Debian-based Linux distribution that features the KDE Plasma desktop with a focus on usability and performance.
-
Danielle Foré Has an Update for elementary OS 7
Now that Ubuntu 22.04 has been released, the team behind elementary OS is preparing for the upcoming 7.0 release.
-
Linux New Media Launches Open Source JobHub
New job website focuses on connecting technical and non-technical professionals with organizations in open source.
-
Ubuntu Cinnamon 22.04 Now Available
Ubuntu Cinnamon 22.04 has been released with all the additions from upstream as well as other features and improvements.
bit9 miss the platform and point
"free" enterprise tools..
"free" tools my a.. as far as I know at least you need some heavy investments in various windows products. Please advise me where I can get all this for "free"...
Central updates
Have you seen the bit9 website?
You guys at Firefox/Mozilla ought not to worry about this one. Who can take bit9 seriously?
Missing the Point
Bit9 is an idiot