A report published this week by software vulnerability watcher Secunia promises to stoke the ever-smoldering embers of the debate over which major Web browser is more secure. In trying to draw conclusions from the data, though, I hope readers will look past the sheer numbers of security holes that each browser maker fixed this past year, to the metric that in my opinion matters most: How long did it take each browser maker to address security flaws once those vendors knew about them? Secunia’s study (PDF) found that 115 security flaws were reported in 2008 for Mozilla’s Firefox browser, almost four times as many flaws as other popular browsers. In contrast, Secunia said, 31 vulnerabilities were reported for versions of Microsoft’s Internet Explorer, while Opera and Safari claimed at least 30 and 32 reported security holes in 2008, respectively. But the Secunia study also measured how nimbly Microsoft and Mozilla