I’m writing this to set the record straight on some statements made earlier this month by Jeff Jones, a security strategy director at Microsoft. In analysis published on his Technet Security Blog and at cio.com, Jeff picked apart research I conducted in 2007, which found that Microsoft’s Internet Explorer browser was unsafe for 284 days in 2006. According to Jones’s analysis, Firefox users were instead more “at risk” than their IE counterparts in 2006 — albeit just by a single day — 285 days in 2006, he concludes. What Jones neglected to mention was that in my analysis I only examined the longevity of unpatched browser vulnerabilities that by each company’s definition earned the most dangerous security ratings. In the case of Internet Explorer, for example, I counted only flaws that Microsoft said were “critical,” for one or more versions of the browser or closely-tied component of the Windows operating