Re: UK Government's documentation on Firefox security

Chris Hofmann <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <CA+zsDHDpXFugi7527ZyazEk7Q5dy9vW_+btg2BjNp-3cCDm1AA@mail.gmail.com>
It also looks like

8b) no built-in XSS protection

is https://bugzilla.mozilla.org/show_bug.cgi?id=528661

another possible case of some risk of a 'good security idea' that fails to
deliver
in implementation and administration.

If this is better supported by CSP then we might have met the 'built in'
checkbox,
or if the requirement is broadened to include possible addons then we meet
it via
no-script and several other addons that are more aggressive in their
blocking
at the possible cost of some usability.

-chofmann

On Tue, Nov 3, 2015 at 9:14 AM, Chris Hofmann <[email protected]> wrote:

>
> on
> 8) No separation between Internet and Intranet pages
>
> and
>
> 8c) old and vulnerable plugins needed in an Intranet can be invoked by
>      Internet content
>
> These both seem to be writing of requirements based on Microsoft's
> security zone feature.
> That feature is typical MS marketing from the 90's where you have a set of
> capabilities
> that can be used to reduce security, and they marketed and FUD'ed there
> way to convince
> folks this was a 'security feature.'
>
> The complexity of taking 22 features, and trying to implement and
> administer each of those
> across different behaviors in 4 differently defined 'security zones' has
> led to more security
> problems that it has solved.  If there is evidence and research that the
> security
> zone feature in IE is widely, or effectively, used then we ought consider
> it, but
> I suspect its actually the reverse.    In fact Firefox's first significant
> bump in marketshare
> in 2004 was due to a privilege elevation bug in the IE security zone
> feature that led to
> download of a remote plugin and  execution of code without user
> intervention or knowledge
> that logged and forwarded keystrokes on banking sites back to the
> attacker's server.
>
> As Gijs mentioned we have ways to block plugins, and we should encourage
> enterprises
> to  particpate in the blocking scheme if they know of vulnerable plugins.
>
> -chofmann
>
>
> On Tue, Nov 3, 2015 at 8:43 AM, Gervase Markham <[email protected]> wrote:
>
>> On 03/11/15 11:50, Gijs Kruitbosch wrote:
>> > IOW, I am not convinced it makes sense to add this as a feature, beyond
>> > the obvious NSPR and NSS logging which we already have.
>>
>> On this point (number 9), I agree. But I think some of the others are
>> worth doing.
>>
>> Gerv
>>
>> _______________________________________________
>> dev-security mailing list
>> [email protected]
>> https://lists.mozilla.org/listinfo/dev-security
>>
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.