Mozilla Security Blog

Window Snyder’s Blog

Archive for 'Musings' Category

Read past the headlines - Firefox is fixed faster

17 January 2008

Secunia released a report this week that discusses a few aspects of the security landscape for 2007.  Techworld ran a story based on this report with this headline: “Red Hat and Firefox more buggy than Microsoft.”  While the headline is misleading, the Techworld article actually tells an interesting story.
Counting security vulnerabilities to compare the security […]

3 Comments »

Critical Vulnerability in Microsoft Metrics

30 November 2007

Jeff Jones, a director of security strategy at Microsoft published a report today about counting bugs. I blogged a few months ago about why I think counting bugs is less than useful:
Since all software has bugs, it’s more important to consider how long it takes to get a fix out when a security […]

14 Comments »

Time to Deploy improvement of 25 percent

18 June 2007

Since all software has bugs, it’s more important to consider how long it takes to get a fix out when a security issue is discovered than it is to count bugs. Number of vulnerabilities identified is a function of how many bugs are present, but is probably more influenced by things like who is […]

7 Comments »