<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The Problem with Browser Security</title>
	<atom:link href="http://www.andyitguy.com/blog/?feed=rss2&#038;p=824" rel="self" type="application/rss+xml" />
	<link>http://www.andyitguy.com/blog/?p=824</link>
	<description>The voice of reason in a world of FUD</description>
	<lastBuildDate>Wed, 01 Sep 2010 17:20:42 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Security Briefing &#8211; November 13th : Liquidmatrix Security Digest</title>
		<link>http://www.andyitguy.com/blog/?p=824&#038;cpage=1#comment-11845</link>
		<dc:creator>Security Briefing &#8211; November 13th : Liquidmatrix Security Digest</dc:creator>
		<pubDate>Fri, 13 Nov 2009 14:20:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.andyitguy.com/blog/?p=824#comment-11845</guid>
		<description>[...] The Problem with Browser Security  &#8211; Andy, IT Guy [...]</description>
		<content:encoded><![CDATA[<p>[...] The Problem with Browser Security  &#8211; Andy, IT Guy [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Allen Baranov</title>
		<link>http://www.andyitguy.com/blog/?p=824&#038;cpage=1#comment-11825</link>
		<dc:creator>Allen Baranov</dc:creator>
		<pubDate>Fri, 13 Nov 2009 08:43:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.andyitguy.com/blog/?p=824#comment-11825</guid>
		<description>(Firefox fanboi - read below with pinch of salt)

Remember that Firefox is Open Source so bugs are out there for all to see. IE *may* have the same amount of bugs or more or less - who knows.. they would be buried in secret code. 

Hackers, generally, are very lazy guys who really only target bugs that are well known and usually patched. The guys who target bugs that are not generally well known are scary but are the exception. 

So, your risk measurement is not really &quot;how many bugs are there&quot; but &quot;how long are known bugs unpatched for&quot;. Firefox is really good at patching - I&#039;d be browsing and a pop-up will happen that says &quot;new version downloaded and applied, reboot&quot; and voila - I am sorted. Extensions are not automatically downloaded and applied but I do get notifications when updates are available. The new feature that checks plug-ins is very new and green but has lots of potential.

The nice thing is that when I started my browser the other day it complained to me in big letters (friendly but not vague) that I must upgrade my flash plug-in. Very nice. 

I haven&#039;t used IE7 or IE8 for very long but IE 6 has none of those lovely features even if it is covered by &quot;Patch Tuesday&quot;.</description>
		<content:encoded><![CDATA[<p>(Firefox fanboi &#8211; read below with pinch of salt)</p>
<p>Remember that Firefox is Open Source so bugs are out there for all to see. IE *may* have the same amount of bugs or more or less &#8211; who knows.. they would be buried in secret code. </p>
<p>Hackers, generally, are very lazy guys who really only target bugs that are well known and usually patched. The guys who target bugs that are not generally well known are scary but are the exception. </p>
<p>So, your risk measurement is not really &#8220;how many bugs are there&#8221; but &#8220;how long are known bugs unpatched for&#8221;. Firefox is really good at patching &#8211; I&#8217;d be browsing and a pop-up will happen that says &#8220;new version downloaded and applied, reboot&#8221; and voila &#8211; I am sorted. Extensions are not automatically downloaded and applied but I do get notifications when updates are available. The new feature that checks plug-ins is very new and green but has lots of potential.</p>
<p>The nice thing is that when I started my browser the other day it complained to me in big letters (friendly but not vague) that I must upgrade my flash plug-in. Very nice. </p>
<p>I haven&#8217;t used IE7 or IE8 for very long but IE 6 has none of those lovely features even if it is covered by &#8220;Patch Tuesday&#8221;.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
