Re: UK Government's documentation on Firefox security
Chris Hofmann <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CA+zsDHDpXFugi7527ZyazEk7Q5dy9vW_+btg2BjNp-3cCDm1AA@mail.gmail.com> |
It also looks like 8b) no built-in XSS protection is https://bugzilla.mozilla.org/show_bug.cgi?id=528661 another possible case of some risk of a 'good security idea' that fails to deliver in implementation and administration. If this is better supported by CSP then we might have met the 'built in' checkbox, or if the requirement is broadened to include possible addons then we meet it via no-script and several other addons that are more aggressive in their blocking at the possible cost of some usability. -chofmann On Tue, Nov 3, 2015 at 9:14 AM, Chris Hofmann <[email protected]> wrote: > > on > 8) No separation between Internet and Intranet pages > > and > > 8c) old and vulnerable plugins needed in an Intranet can be invoked by > Internet content > > These both seem to be writing of requirements based on Microsoft's > security zone feature. > That feature is typical MS marketing from the 90's where you have a set of > capabilities > that can be used to reduce security, and they marketed and FUD'ed there > way to convince > folks this was a 'security feature.' > > The complexity of taking 22 features, and trying to implement and > administer each of those > across different behaviors in 4 differently defined 'security zones' has > led to more security > problems that it has solved. If there is evidence and research that the > security > zone feature in IE is widely, or effectively, used then we ought consider > it, but > I suspect its actually the reverse. In fact Firefox's first significant > bump in marketshare > in 2004 was due to a privilege elevation bug in the IE security zone > feature that led to > download of a remote plugin and execution of code without user > intervention or knowledge > that logged and forwarded keystrokes on banking sites back to the > attacker's server. > > As Gijs mentioned we have ways to block plugins, and we should encourage > enterprises > to particpate in the blocking scheme if they know of vulnerable plugins. > > -chofmann > > > On Tue, Nov 3, 2015 at 8:43 AM, Gervase Markham <[email protected]> wrote: > >> On 03/11/15 11:50, Gijs Kruitbosch wrote: >> > IOW, I am not convinced it makes sense to add this as a feature, beyond >> > the obvious NSPR and NSS logging which we already have. >> >> On this point (number 9), I agree. But I think some of the others are >> worth doing. >> >> Gerv >> >> _______________________________________________ >> dev-security mailing list >> [email protected] >> https://lists.mozilla.org/listinfo/dev-security >> > >