Friday, April 2, 2010
Mozilla pegs worldwide Firefox share at 30%
On Wednesday, the open source outfit released its first ever quarterly analyst report (pdf), a collection of web-happy stats dubbed The State of the Internet. Crunching data from four separate online research houses - StatCounter, Quantcast, Net Applications, and Gemius - Mozilla says that its influence is the strongest in Europe, where it spans 39.2 per cent of the browser market.
Next comes South America at 31.1 per cent and then Africa at 29.7 per cent, with North America bringing up the rear at 26 per cent. Mozilla does not provide official numbers on Antarctica, but StatCounter says that on the bottom of the earth, Firefox has an 80 per cent share. Which only makes sense. Open source keeps you warm.
According to Mozilla, Firefox usage is growing most rapidly in Russia, where uptake spiked 20 per cent this quarter. Mozilla guesses this has something to do with chairperson Mitchell Baker's visit to the country in February. Now if we could only get her to visit all those companies still running IE6.
Russia, incidentally, is one place where Google is not the browser's default search engine. All those clicks are going to the native Yandex.
Indonesia, India, the Philippines, Australia, Mexico, and Turkey also showed Firefoxian growth in access of 15 per cent during the quarter. And according to the report, Asians are the most likely to beef up their browsers with add-ons - unless you consider that small sample size in Antarctica. Since January, Mozilla has seen 538 Antarctic add-on downloads from the continent's 1,000 inhabitants.
A recent Mozilla Labs study indicates that the average Firefox user has two to three tabs open at a time. But one unnamed participant went so far as to open 600. Presumably, none of the 600 were running Flash.
Mozilla pegs worldwide Firefox share at 30%
On Wednesday, the open source outfit released its first ever quarterly analyst report (pdf), a collection of web-happy stats dubbed The State of the Internet. Crunching data from four separate online research houses - StatCounter, Quantcast, Net Applications, and Gemius - Mozilla says that its influence is the strongest in Europe, where it spans 39.2 per cent of the browser market.
Next comes South America at 31.1 per cent and then Africa at 29.7 per cent, with North America bringing up the rear at 26 per cent. Mozilla does not provide official numbers on Antarctica, but StatCounter says that on the bottom of the earth, Firefox has an 80 per cent share. Which only makes sense. Open source keeps you warm.
According to Mozilla, Firefox usage is growing most rapidly in Russia, where uptake spiked 20 per cent this quarter. Mozilla guesses this has something to do with chairperson Mitchell Baker's visit to the country in February. Now if we could only get her to visit all those companies still running IE6.
Russia, incidentally, is one place where Google is not the browser's default search engine. All those clicks are going to the native Yandex.
Indonesia, India, the Philippines, Australia, Mexico, and Turkey also showed Firefoxian growth in access of 15 per cent during the quarter. And according to the report, Asians are the most likely to beef up their browsers with add-ons - unless you consider that small sample size in Antarctica. Since January, Mozilla has seen 538 Antarctic add-on downloads from the continent's 1,000 inhabitants.
A recent Mozilla Labs study indicates that the average Firefox user has two to three tabs open at a time. But one unnamed participant went so far as to open 600. Presumably, none of the 600 were running Flash.
Monday, February 8, 2010
Google offers bounty on browser bugs
The company will pay $500 per bug found in Chromium, the open-source code that powers the company's Chrome Internet browser, Google stated in a blog post published on Thursday. For extremely critical issues, as judged by the company's security team, Google will pay $1,337 -- a play on hackerspeak for "leet" or elite.
"We are hoping that the introduction of this program will encourage new individuals to participate in Chromium security," Chris Evans, a member of Google's Chrome security team, stated in the blog post. "The more people involved in scrutinizing Chromium's code and behavior, the more secure our millions of users will be."
The search giant is far from the first company to agree to pay security researcher who find and privately disclose bugs. Google's program is based on browser maker Mozilla's bug bounty. In addition, security firms TippingPoint and iDefense both pay for critical bugs in other companies' software, using the information to protect their own customers.
In the blog post, Google's Evans appeared to indicate that only responsibly disclosed vulnerabilities would be considered for a reward and that bugs publicly disclosed without giving Google developers time to fix would not be considered.
"We encourage responsible disclosure," Evans wrote. "Note that we believe responsible disclosure is a two-way street; it's our job to fix serious bugs within a reasonable time frame."
Bug bounties allow researchers to receive a small amount of cash for their research, but pale in comparison to the fees that critical issues can command from cybercriminals and government cyber programs. Exploits for a serious flaw in a popular program can sell for more than $100,000.
Sunday, February 7, 2010
40,000 More Extensions!
Ever since the beginning of the Chromium project, friends and coworkers have been asking me to add support for user scripts in Google Chrome. I’m happy to report that as of the last Google Chrome release, you can install any user script with a single click. So, now you can use emoticons on blogger. Or, you can browse Google Image Search with a fancy lightbox. In fact, there’s over 40,000 scripts on userscripts.org alone.
Installation is quick and easy, just like installing an extension. That’s because under the covers, the user script is actually converted into an extension. This means that management tasks like disabling and uninstalling work just like they do with extensions.
Note that user scripts are powerful software and have full access to your private data on any web site. So, for example, they could read all your web mail or access your online bank. Be sure to read the comments on any user scripts in order to decide whether you trust the author with this power.
Also keep in mind that some user scripts won’t work in Google Chrome yet, because of differences between it and Firefox. Based on some analysis that the current maintainers of Greasemonkey did, I expect between 15%-25% of scripts to not work in Google Chrome. If you find such a script, you should consider letting the author know. There may be something he or she can do to easily fix the problem. In the meantime, we’ll keep working on bugs on our side to bring our implementation closer to Greasemonkey.
Have fun trying out the thousands of available scripts. And don’t worry - If you get bored, there’s lots more extensions at Google Chrome’s extension gallery.
source : http://www.hacking-news.com/
Saturday, December 12, 2009
More Secure Web Browsing
Recently I had a conversation with my Dad about some things that can be done to be more secure whilst web browsing. I explained to him that a common attack vector is through the web browser and that a lot of the risks can be mitigated by using a different browser than Internet Explorer and by turning off scripting by default.
The purpose of this post is to give my Dad instruction on where to get and how to install the browser I recommend and which add-ons might help keep him more secure.
Before I begin, it would be useful to point out something which I think is as applicable here as it is within the realm of network monitoring. Prevention Always Fails. At some point you will get owned because your information or your computing resourse (think botnet) is worth something to somebody else. You can impliment as many safeguards as you want, but the fact is the Internet is a dangerous place and although these safeguards will raise the bar and might prevent many attacks being successful eventually something will fail, and when it does the next action you need to take is detection. Now, it's very difficult to know when your preventative methods have failed so my advice would be to assume they already have. By making this assumption I would then begin to use the detection tools, monitor bank statements, credit card statements and look at traffic leaving your network etc....
Anyway, now to getting the bar raised and becoming more secure online....
The Web Browser
Firstly I recommend using Firefox. Firefox is an open source browser that is fast and lightweight. Yes there have been vulnerabilities with Firefox but these have been patched quickly and Firefox updates itself automatically.
To download Firefox I recommend Googling "Mozilla Firefox" and downloading it directly from the Mozilla site. Once downloaded simply install using the default options.
The Add-ons
Once installed, you will want to install a couple of add-ons. Add-ons are little programs that add extra functionality to Firefox. They are simple to install and there are hundreds of them freely available. One word of warning through. As there are so many add-ons it is really easy to go over the top and install a whole load of them, and some add-ons may make your system less secure so just install what you need and maybe research them too.
The add-ons I recommend are:
- NoScript
After installing NoScript all scripting will be off. This does break some pages and they will not display properly. If this is the case, right click the NoScript icon in the bottom right corner of your browser and select to temporarily allow scripting for the site you are on. The NoScript icon in the bottom of the screen changes depending on the settings you have selected. It's a good idea to enable and disable sites and make a mental note of how the icon has changed.
- Customize Google
- Formfox
To install new add-ons or enable / disable them once you are in Firefox, click on the tools menu and then select add-ons. From here you can select whether to enable or disable the add-on and adjust any settings for it or you can click the "Get Extensions" link to be taken to the site where you can download new add-ons. Once installed Firefox may prompt you to restart the browser.

You can also install Themes to change the look and feel of Firefox or install plugins if they are missing such as Flash, Adobe Acrobat Reader etc...
This blog post only touches on what Firefox can do. It is very extensible and feature packed. i don't know anyone who has gone back to Internet Explorer after using Firefox.
The one thing I will say is very few websites don't work well with Firefox, for example my bank doesn't. So I use I.E for that site only and do 99% of my browsing through Firefox with scripting off.
Hope this Helps.
Update:
01-05-08 - One last tip, but a really important one. As most browsers use tabs these days, it allows you to log into one site and then open a new tab and log into another. This is really bad practice as a site from one tab can run code to execute actions on the site on the other tab. So if you do banking or email remember to log out and close the tab before you do other stuff.
Links