Re: UK Government's documentation on Firefox security

Chris Hofmann <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <CA+zsDHASVthkWRPnb73asa91UsZ9UeHa-_iYoJYXLc4RY67sAQ@mail.gmail.com>
on
8) No separation between Internet and Intranet pages

and

8c) old and vulnerable plugins needed in an Intranet can be invoked by
     Internet content

These both seem to be writing of requirements based on Microsoft's security
zone feature.
That feature is typical MS marketing from the 90's where you have a set of
capabilities
that can be used to reduce security, and they marketed and FUD'ed there way
to convince
folks this was a 'security feature.'

The complexity of taking 22 features, and trying to implement and
administer each of those
across different behaviors in 4 differently defined 'security zones' has
led to more security
problems that it has solved.  If there is evidence and research that the
security
zone feature in IE is widely, or effectively, used then we ought consider
it, but
I suspect its actually the reverse.    In fact Firefox's first significant
bump in marketshare
in 2004 was due to a privilege elevation bug in the IE security zone
feature that led to
download of a remote plugin and  execution of code without user
intervention or knowledge
that logged and forwarded keystrokes on banking sites back to the
attacker's server.

As Gijs mentioned we have ways to block plugins, and we should encourage
enterprises
to  particpate in the blocking scheme if they know of vulnerable plugins.

-chofmann


On Tue, Nov 3, 2015 at 8:43 AM, Gervase Markham <[email protected]> wrote:

> On 03/11/15 11:50, Gijs Kruitbosch wrote:
> > IOW, I am not convinced it makes sense to add this as a feature, beyond
> > the obvious NSPR and NSS logging which we already have.
>
> On this point (number 9), I agree. But I think some of the others are
> worth doing.
>
> Gerv
>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.