Showing posts with label browser. Show all posts
Showing posts with label browser. Show all posts

Sunday, 25 August 2013

Chrome, Firefox edge IE in browser reliability test

Recent versions of Google's Chrome and Mozilla's Firefox are measurably less prone to crashes and errors than Microsoft's Internet Explorer 10, a new analysis by applications testing firm Sauce Labs has found.

If this looks like another stick to beat Microsoft's browser with, it is worth pointing out that the firm's study of around 55 million tests run using the Selenium platform found that all browsers showed extremely low levels of errors, in the order of 0.12 percent or lower for the "worst" performer, Apple's Safari 6.

On the same scale, Opera 12 scored 0.08 percent, IE10 at 0.05 percent, Chrome 27 under 0.02 percent, with Firefox was so low it effectively achieved a remarkable zero, that is to say no errors at all. IE lagged its main rivals but at levels that were already extremely low.

As interesting as the reliability figures was the level of improvement shown by these recent versions, some only months or even weeks old.

Internet Explorer 6 (released in 2001 with XP) and 7 (2007) had previously been the worst performers on 0.3 percent each, behind Firefox on Opera 10 (2009) and Firefox 7 (2011) and IE8 (2009) on just under 0.25 percent. It is remarkable that all of these are still used by small percentages of global browser users, but they are also aging software vulnerable to issues more serious than how often they might crash.

SpeedyPC Pro"Half of the browser versions we analyzed had error rates lower than 0.07 percent. That's pretty low, and suggests that browsers are getting more reliable as more versions come out," said Luren Nguyen of Sauce Labs.

Despite lagging slightly, IE had also shown major improvement over time.

"Microsoft has really been pushing their new version of Internet Explorer as the most modern and high-performing version of IE. You've may have seen their nostalgia-tinged IE 10 commercial. The data we have on browser error rates suggests that their claims may have quite a bit of merit," she said.

The absolute level of errors in these tests is an imperfect way to measure browser reliability some might argue (can the errors be proved to be the browser's fault and not the testing suite's?), but the comparative measurement won't be coincidence. Errors, which usually result in a crash of some kind, are caused by bugs in the browser code.

Do error rates really matter? Only when they occur, which seems to be rarely these days. 

Tuesday, 6 August 2013

Browser privacy tools still lack bite, security analysts say

Browser vendors continue to implement privacy in a halfhearted way, with Internet Explorer's default use of cookie "do not track" technology being the best of a weak job, a new assessment by NSS Labs has argued.

Currently, the latest versions of all four leading browsers—IE, Firefox, Chrome, and Safari—implement Do not track - but only Internet Explorer 10 installs it switched on by default, NSS Labs' latest Comparative Analysis found.

The cookie-tracking setting can be enabled in the other three, but only by locating an option in a menu setting. The authors are especially critical of Chrome, which requires users to find and expand a nested Advanced Settings tab to enable the feature.

Even Microsoft treats the do not track as a design afterthought, burying the settings where only the most curious non-expert users might chance upon it.

NSS Labs interprets this lack of enthusiasm for the setting as revealing each vendor's "philosophical views on consumer privacy," while accepting that do not track remains ineffective as a privacy control while advertisers remain free to ignore it as they please.



browsers
"Until legislation is passed that will mandate compliance with the user intent of Do not track, the feature will remain a polite request that will be ignored by the advertising industry," write authors Randy Abrams and Jayendra Pathak.

With third-party cookies, Safari and IE are given the thumbs up, with the former blocking all by default, and IE implementing a partial block. Although Firefox and Chrome don't activate this setting by default, Firefox in particular offers granular control over a setting that is vital to automate access to many commonly used sites.

Other privacy features—the ability to control geolocation, private browsing, and tracking protection lists—all fall down to some extent.

Controlling geolocation (the ability for a site to detect a user's country location), all four browsers prompt as required, but in order to disable the setting completely Firefox forces users to access the technically demanding about:config page.

Uniquely, IE9/10 allows Tracking Protection lists from third-party vendors, essentially lists of sites for IE to block third-party cookies automatically unless the setting is overridden by the user.



Overall, then, IE comes out on top for privacy thanks to the relative simplicity of its slider controls and privacy templates, but none of the four are given a ringing endorsement.

It remains unclear to what extent browser privacy and features such as do not track are valued or even understood by users. A YouGov poll from late last year found that consumers valued ease of use more highly than the ability to block cookies, although the same survey admitted that many disliked targeted ads which follow users even when they have left sites.

Do not track has certainly upset some advertisers, with the Digital Advertising Alliance (DAA) recently lobbying a W3C discussion on how to standardize the way that not track should work.

Thursday, 11 July 2013

Alert! Study finds Internet users heed browser warnings

Security warnings displayed by Web browsers are far more effective at deterring risky Internet behavior than was previously believed, according to a new study.

The study looked at how users reacted to warnings displayed by Mozilla's Firefox and Google's Chrome browsers, which warn of phishing attempts, malware attacks and invalid SSL (Secure Sockets Layer) certificates.

It was widely thought that most users ignored the warnings, based on several studies released between 2002 and 2009. However, in the past four years, browser warnings have been redesigned, but the effect of the new designs on users had not been studied.

For example, toolbars that warned of possible phishing attacks have been replaced with full-page warnings that may have influenced people's behavior, the researchers who conducted the study wrote.

More than 25 million warning impressions displayed by Chrome and Firefox in May and June were analyzed. The data was collected from telemetry programs used by Mozilla and Google, which collect what the researchers term 'pseudonymous' data from the browsers of consenting users.

In the case of both browsers, less than 25 percent of users opted to bypass malware and phishing warnings, and only a third of users cruised through the SSL warnings displayed by Firefox.

"This demonstrates that security warnings can be effective in practice; security experts and system architects should not dismiss the goal of communicating security information to end users," according to the paper, which was submitted to the Usenix Annual Technical Conference 2013 in San Jose, California, late last month.

The analysis uncovered other interesting details. It appears that more technical users bypassed security warnings more often. The researchers considered technical users as those who used Linux and pre-release browsers.

"Technically advanced users might feel more confident in the security of their computers, be more curious about blocked websites or feel patronized by warnings," the paper said.

Despite the positive influence of the warnings, the researchers found users clicked through more than 70 percent of Google's SSL warnings. By contrast, Firefox users clicked through them just 33 percent of the time.

There are a few thoughts why Chrome's SSL click-through rate is higher. Users can bypass Chrome's warning with a single click, whereas Firefox requires three clicks. Firefox displays a more stern warning, showing an image of a policeman and using the word "untrusted" to describe the site.

There may also be other mitigating factors, the researchers said. Nevertheless, Chrome's high SSL click-through rate "is undesirable," they wrote. "Our positive findings for the other warnings demonstrate that this warning has the potential for improvement."

The study was written by Devdatta Akhawe of the University of California, Berkeley, and Adrienne Porter Felt, a research scientist at Google.

Thursday, 27 June 2013

Simplify browser use with keyboard shortcuts

Solutions, Tips and Answers for PC Problems from Lincoln Spector

 




The mouse may be the most intuitive way to control a browser, but it's not the most efficient. As MLStrand56 learned on the Answer Line forum, browser shortcuts can be valuable.
I'd like to tell you that nothing can speed up your Web browsing like a few basic keyboard shortcuts. But that's not really true. They won't speed things up nearly as much as a faster Internet connection.
 [Email your tech questions to answer@pcworld.com or post them on the PCW Answer Line forum.]
But the keyboard shortcuts will speed it up in an entirely different way. They won't bring up a new page any faster, but once the page is up, they can get you to the top or bottom immediately, change tabs in the blink of an eye, and toggle full-screen mode.
And unlike a faster connection, they don't add to your monthly bills.
 

Follow me on Twitter @sajilpl

Wednesday, 26 June 2013

Firefox 22 browser update supplies web-calling capability

Mozilla Tuesday shipped Firefox 22, which enables the in-browser audio-video calling standard WebRTC, and switches on a new JavaScript module that promises to speed up web apps.

 

The update also includes patches for 17 security vulnerabilities, seven of them marked “critical.”

 

Mozilla highlighted several of the changes in Firefox 22, notably the default support for WebRTC (Web Real-Time Communications), an open-source API (application programming interface) that web applications can call for in-browser audio and video communications without requiring specialized plug-ins like Adobe’s Flash.

 

WebRTC traces its roots to Google, which acquired the VP8 video codec in 2010 from a company called On2, open-sourced the technology, and pushed for its adoption as a standard by the Worldwide Web Consortium (W3C). Mozilla engineers have been also working on the project to implement WebRTC in Firefox.

 

Google’s Chrome supports WebRTC, and Opera Software developers are also involved in the initiative. In February, Google and Mozilla announced that their browsers were interoperable, letting users of Chrome and Firefox communicate with each other.

 

Mozilla has also made WebRTC a foundation of its mobile phone strategy, which relies on Firefox OS, a lightweight browser-based operating system that will power low-cost phones from several carrier and handset partners. The latter includes FoxConn, the world’s largest contract electronics manufacturer best known as an assembler of Apple’s iPhones and iPads.

 

Firefox 22 also comes with a new JavaScript subset, dubbed “asm.js,” that promises to significantly boost the execution of JavaScript code and web apps written in the popular scripting language.

 

Mozilla calls its asm.js module “OdinMonkey,” a tip to the name “SpiderMonkey” used for its current JavaScript engine. According to Mozilla, developers who use cross-compilers that produce asm.jm code—Emscripten for example—can generate optimized JavaScript with near-native code performance.

 

“Native code” refers to programs designed for a specific processor’s or processor family’s instruction set. Windows 8, for example, is native code for the Intel x86 and x64 instruction sets.

 

Mozilla’s OdinMonkey is an answer of sorts to Google’s Native Client, a technology that lets developers turn applications written in C and C++—software originally intended to run in, say, Windows—into ones that execute entirely within desktop Chrome and Chrome OS.

 

Like Mozilla, Google claims that Native Client code runs almost as fast inside the browser as the original did outside.

 

Both Mozilla and Google have highlighted JavaScript-written games as a key target for their native code projects.

 

“Developers [now] have a low-cost solution to bring high-performance games and applications to the Web with technologies like JavaScript, Emscripten and WebGL,” Mozilla wrote on its top-tier company blog announcing Firefox 22. WebGL is another open-source extension to JavaScript; it allows developers to render interactive 3-D graphics content.

 

Firefox for Android was also updated Tuesday to improve WebGL rendering—a similar enhancement landed in Firefox 22 on the desktop—and to guarantee that smaller-sized tablets displayed the browser’s full interface.

 

Along with the usual slate of new features and improvements, Firefox 22 also patched 17 vulnerabilities, seven rated critical, Mozilla’s highest threat ranking. Six others were labeled “high,” three were marked “moderate” and one was tagged as “low.”

 

One of the critical bugs was reported by Nils, the second consecutive Firefox update contribution by the German researcher. Nils, a noted vulnerability researcher, was on a two-man team that won $100,000 in March for hacking Chrome at the Pwn2Own contest.

 

Also patched was yet another vulnerability in the Mozilla Maintenance Service on Windows, which powers the browser’s silent updates. Mozilla patched different bugs in the same service in both April (Firefox 20) and May (Firefox 21).

 

Security researcher Abhishek Arya, a Google engineer better known as “Inferno,” was credited with reporting three memory corruption flaws. Inferno and others on Google’s security team have reported scores of vulnerabilities to Mozilla based on their “fuzzer” stress testing.

 

Windows, Mac, and Linux editions of Firefox 22 can be downloaded manually from Mozilla’s site, while already installed copies will upgrade automatically. Users of Firefox for Android can retrieve the update from the Google Play store.

 

The next version of Firefox is set to ship August 6.