Linked by Thom Holwerda on Thu 2nd Jul 2009 12:19 UTC
Thread beginning with comment 371310
To read all comments associated with this story, please click here.
To read all comments associated with this story, please click here.
They had two vulnerabilities in WebKit that allowed that one guy to win the Pwn2Own contest two years in a row. That's a HUGE number of vulnerabilities, especially compared to historically secure platforms like Internet Explorer.
In all seriousness, the WebKit team is pretty good at applying patches that people send in, but they have very little control over Safari's release schedule, since that depends more on Safari's proprietary interface and Apple's marketing schemes.
Any open source browser effort that uses WebKit is free to perform its own security vetting.







Member since:
2008-05-26
If KDE decides to move across to Webkit, they need to at least continue to support KHTML.
I will not use Webkit. Its biggest single developer is Apple, and Apple does not have a good track record for writing secure software. Apple's operating system has well-known design flaws that cause worrying security problems; as they are design flaws they cannot be fixed by "a patch" without breaking application compatibility.
I also have to put my hand up and say that KHTML currently works for everything I've tried it on.