Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Security as a Service: Is It Right for You? | Main | Google's Open Source Security Audit Tool »

Who Is Running More Secure Browser Still an Open Question

A recent study on which of the major browsers are more like to be up to date is generating a fair bit of discussion focused on the study's methodology. Critics are right that some assumptions may have biased the findings but there are easy ways to assess how much of a bias those assumptions introduced. The study isn't perfect but it is a step in the right direction.

The big problem according to critics, like Larry Seltzer at eWeek, is that Microsoft Internet Explorer provides only major release version information so anyone running IE7 is assumed to be running the latest version in the study. The results is that IE users look like they are more up to date on their patches.

Seltzer's point is well taken and the researchers could have addressed that by providing results assuming that IE7 users were using the earliest, not the latest, version. More realistically, they could have assumed that all possible versions of IE7 are in use and made some assumptions about the distribution, like the number of IE7 users with the latest version is proportional to the number of that versions download from Microsoft. Of course this would require data from Redmond; the rest of the data was primarily from Google logs.

The point is, the researchers have collected some interesting facts but we can't pass too many judgments yet. If we change the assumptions and get the same results we can be confident that IE users are more up to date with patches. I suspect that patter would not hold but we'll have to wait until the researchers re-run the statistics with different assumptions.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/778

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net