Skip to main content

Reports find Firefox faces upgrade lag, security debate

The Mozilla Foundation’s Firefox browser has been facing a bit of a crisis, with the organization’s search deal with Google in limbo — and with it, most of the public foundation’s funding. While Mozilla and Google are reported to still be working on a new version of their search deal, new reports show Firefox is facing new challenges:Many Firefox users are failing to keep up with Mozilla’s rapid release schedule for the browser, and Google may be deliberately trying to undermine Firefox by commissioning security reports that tout Chrome at Firefox’s expense.

First, a new report from advertising analytics firm Chitika finds that while the majority of Firefox users are embracing Mozilla’s new rapid release methodology (which sees a new major version of Firefox every couple months), as many as a quarter of Firefox users are three or more major revisions behind, with nearly 23 percent of Firefox’s user base still using Firefox 3.0 or 3.x. The current version — this week —  is Firefox 8.

Chitika-Firefox-versions-Dec2011
Image used with permission by copyright holder

“While a majority of Firefox users have the current version of the browser, there is a significant portion—at least a quarter—who are at least three releases behind,” wrote Chitika’s Haze Jayachandran. “Firefox’s plans to allow silent updates may help this problem, though they aren’t scheduled to debut until version 12 is released.”

A “silent upgrade” feature won’t automatically migrate users of very old versions of Firefox (like Firefox 2 and 3) to new versions—the support simply isn’t in those older versions of the browser, and in some cases Mozilla no longer makes a version of Firefox for the platform. For instance, while Firefox still supports Windows XP, it left PowerPC-based Macs in the dust with Firefox 4.

Chitika also underscores the value of Mozilla’s search deal with Google, finding that nearly 80 percent of Firefox users have Google as their default search engine, as measured across impressions last week.

In the meantime, accusations are flying that Google may be trying to stack the deck against Firefox (and other browsers) by commissioning a report on browser security from Accuvant. Accuvant named Google’s Chrome the browser most secure against attacks. Accuvant’s senior research scientist claimed the test were “completely different and more extensive methodology than previous, similar studies,” and considered anti-exploitation technologies and browsers’ security methodology.

However, at least one other security firm is crying foul: NSS Labs has released its own response to Accuvant’s report (PDF), saying it appears Google may have set the testing parameters to Chrome’s advantage, in part because the test methodology completely ignored some Firefox security technologies such as frame poisoning and particular JIT hardening techniques employed by Firefox.

NSS Labs doesn’t question Accuvant’s expertise or that Chrome is working hard to be secure. In fact, NSS Labs lauds Accuvant’s discussion of JIT hardening and sandboxing tchnologies, and says it found Chrome increased its protection against traditional malware nearly fivefold just from November 22 to December 2. But NSS Labs pulls no punches about why it thinks Chrome won in Accuvant’s testing: “Google paid product reseller Accuvant to publish a report comparing browser security. However, given the deficiencies in the methodology it would appear that the main aim of the report was to undermine confidence in Firefox.”

Of course, NSS Labs is no stranger to commissioned security reports itself: A year ago, NSS Labs was commissioned by Microsoft to test IE9’s anti-malware features…and NSS Labs declared IE9 the most secure browser available.

Editors' Recommendations

Topics
Geoff Duncan
Former Digital Trends Contributor
Geoff Duncan writes, programs, edits, plays music, and delights in making software misbehave. He's probably the only member…
I write about tech for a living — these are the browser extensions I install on every PC
A person using a laptop on a desk with a web browser showing the HubSpot marketplace on their screen.

I write about tech for a living, so you probably won’t be surprised to learn that I spend an unreasonable amount of time browsing the internet (those dog videos aren’t going to watch themselves). Over my many years of surfing the web, I’ve used a huge number of browser extensions to tune up my online experience.

Some have been better than others, but I've carefully curated a list that can elevate your internet experience and help take it to the next level. If you’re after some new extensions for Chrome, Safari, Firefox and all the other best web browsers, these are my own personal recommendations.
1Password

Read more
I found a Chrome extension that makes web browsing bearable again
Google Drive in Chrome on a MacBook.

GDPR cookie consent notices were meant to hand privacy control back to ordinary internet denizens. Instead, they’ve unleashed a tidal wave of deception, with unscrupulous website owners using any means necessary to trick you into letting them harvest your private data for resale and profit.

It wasn’t meant to be like this. But while things might have not gone so well for GDPR, there’s still a way to protect your privacy and banish those annoying pop-ups in one fell swoop. Instead of rage-clicking Accept just to get the damned pop-ups to go away, I’ve found a much better way: the Consent-O-Matic browser extension.

Read more
This Google Chrome feature may save you from malware
Google Chrome app on s8 screen.

There are probably hundreds of thousands of Google Chrome extensions out there, and with so many options to choose from, it can be hard to know whether the plugin you want to install is hiding malware nasties.

That could become a thing of the past, though, as Google is testing a feature that will warn you if an extension you installed has been removed from its Chrome Web Store.

Read more