Google Chrome tops 'Dirty Dozen' vulnerable apps list
networkworld.com
networkworld.com
This leaves aside the question of what is more secure - an app where you get security fixes every day - or one where the makers deny there are any faults.
Reported by Google's bug tracker and security team, if the random sampling of vulnerabilities I looked at are any indication.
Seems like the secret to "winning" this list is to just hide everything in-house. I wonder what the list would look like if Microsoft's bug trackers were public viewing.
I couldn't believe when I read this article that in related content, the top item was "IE9 tops Chrome, Firefox in HTML5 Compatibility"[2]. That's what made me research if there was any connection between Network World and Microsoft.
[1] http://techrights.org/2010/06/11/idc-idg-and-propaganda/
The fact that they use roughly the same engine doesn't count for very much. It's the implementation that matters.
This is a very-very weird article.
Does most number of bugs reported mean anything? No. I can NOT report the bugs because I don't have the IE source code. I can report 2 bugs a year, and never have them resolved, so I'm secure I guess, yet I'm actually worse off. How fast from report to release does a bug take on average to be fixed? How much of chrome's reported vulnerabilities reside inside the sandbox vs leaking outside the sandbox (this is a big one, if the answer is none then chrome is still insanely secure)? What about the fact that many security problems in chrome likely are problems in Safari except without the niceties of the sandbox?
This is all crap.
If it was the former, Google is being shown in a positive light and they don't have any sort of "dubious distinction", and if it was the latter, then Google has an explanation for that. Lots of bugs are found in Chrome since Google pays developers a lot of money to find bugs in Chrome (not really sure about the others).
From the same site: http://www.networkworld.com/news/2010/110110-google-offers-b...