i originally saved this for another post. yet when i came back to that post it had 115 reply`s and was locked.
Release Notes for Debian GNU/Linux 6.0 (squeeze), 32-bit PC
http://www.debian.org/releases/squeeze/ ... ase-notes/5.4. Security status of web browsers
Debian 6.0 includes several browser engines which are affected by a steady stream of security vulnerabilities. The high rate of vulnerabilities and partial lack of upstream support in the form of long term branches make it very difficult to support these browsers with backported security fixes. Additionally, library interdepencies make it impossible to update to newer upstream releases. As such, browsers built upon the qtwebkit and khtml engines are included in Squeeze, but not covered by full security support. We will make an effort to track down and backport security fixes, but in general these browsers should not be used against untrusted websites.
For general web browser use we recommend browsers building on the Mozilla xulrunner engine (Iceweasel and Iceape), browsers based on the Webkit engine (e.g. Epiphany) or Chromium. Xulrunner has had a history of good backportability for older releases over the previous release cycles.
Chromium —while built upon the Webkit codebase— is a leaf package, i.e. if backporting becomes no longer feasible, there's still the possibility of upgrading to a later upstream release (which is not possible for the webkit library itself).
Webkit is supported by upstream with a long term maintenance branch.