Re: UK Government's documentation on Firefox security

Ben Bucksch <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
Gervase Markham wrote on 02.11.2015 16:49:

> 7) No notification if browser updates fail

This is interesting. That means updates are vulnerable to a downgrade 
attack. This should be fixed for everybody.

> 4) Can't disable addon installation, and addons can be silently evil
>
> -- Can we add a pref to disable this?

That would be xpinstall.enabled = false , I think

> 5) Safe Browsing warnings are bypassable
>
> -- Can we add a pref to disable this?

Why should Google be the final authority on what gov users in the UK can 
see?

This could easily be implemented as extension. Same for some other 
points in the list.
BTW: A number of enterprises already use extensions to customize Firefox 
to their needs. Killing extensions would break all that.

> 6) Can't disable Basic/Digest Auth over HTTP
>
> -- UNCO bug about warning:
>       https://bugzilla.mozilla.org/show_bug.cgi?id=1185145
>     UNCO bug about turning off altogether:
>       https://bugzilla.mozilla.org/show_bug.cgi?id=966754

Ditto. There are legitimate uses for this.

> 8) No separation between Internet and Intranet pages
>
>
> -- My understanding is that making this distinction accurately is Hard.
>     Is that true? What does IE do?

MSIE configures this in Internet settings. The admin manually configures 
what constitutes "Intranet".

> 8c) old and vulnerable plugins needed in an Intranet can be invoked by
>      Internet content

Here, they are contradicting themselves. If they don't trust their own 
network enough to allow Basic Auth via HTTP even in the lowest security 
case, then they can't trust their Intranet to run vulnerable (!) plugins 
that would root all the client machines.

Apparently, they care about settings and theoretical features, but not 
about fixing known-vulnerable software. Typical "features over security" 
mindset. This request is a nice hint for government hackers in which 
area they let their guard down. Sorry for the rant, but I've seen too 
many government agencies see run Firefox 7 or so.

Ben
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.