Re: UK Government's documentation on Firefox security
Chris Hofmann <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CA+zsDHASVthkWRPnb73asa91UsZ9UeHa-_iYoJYXLc4RY67sAQ@mail.gmail.com> |
on
8) No separation between Internet and Intranet pages
and
8c) old and vulnerable plugins needed in an Intranet can be invoked by
Internet content
These both seem to be writing of requirements based on Microsoft's security
zone feature.
That feature is typical MS marketing from the 90's where you have a set of
capabilities
that can be used to reduce security, and they marketed and FUD'ed there way
to convince
folks this was a 'security feature.'
The complexity of taking 22 features, and trying to implement and
administer each of those
across different behaviors in 4 differently defined 'security zones' has
led to more security
problems that it has solved. If there is evidence and research that the
security
zone feature in IE is widely, or effectively, used then we ought consider
it, but
I suspect its actually the reverse. In fact Firefox's first significant
bump in marketshare
in 2004 was due to a privilege elevation bug in the IE security zone
feature that led to
download of a remote plugin and execution of code without user
intervention or knowledge
that logged and forwarded keystrokes on banking sites back to the
attacker's server.
As Gijs mentioned we have ways to block plugins, and we should encourage
enterprises
to particpate in the blocking scheme if they know of vulnerable plugins.
-chofmann
On Tue, Nov 3, 2015 at 8:43 AM, Gervase Markham <[email protected]> wrote:
> On 03/11/15 11:50, Gijs Kruitbosch wrote:
> > IOW, I am not convinced it makes sense to add this as a feature, beyond
> > the obvious NSPR and NSS logging which we already have.
>
> On this point (number 9), I agree. But I think some of the others are
> worth doing.
>
> Gerv
>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>