Re: UK Government's documentation on Firefox security
Ben Bucksch <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <[email protected]> |
Gervase Markham wrote on 02.11.2015 16:49: > 7) No notification if browser updates fail This is interesting. That means updates are vulnerable to a downgrade attack. This should be fixed for everybody. > 4) Can't disable addon installation, and addons can be silently evil > > -- Can we add a pref to disable this? That would be xpinstall.enabled = false , I think > 5) Safe Browsing warnings are bypassable > > -- Can we add a pref to disable this? Why should Google be the final authority on what gov users in the UK can see? This could easily be implemented as extension. Same for some other points in the list. BTW: A number of enterprises already use extensions to customize Firefox to their needs. Killing extensions would break all that. > 6) Can't disable Basic/Digest Auth over HTTP > > -- UNCO bug about warning: > https://bugzilla.mozilla.org/show_bug.cgi?id=1185145 > UNCO bug about turning off altogether: > https://bugzilla.mozilla.org/show_bug.cgi?id=966754 Ditto. There are legitimate uses for this. > 8) No separation between Internet and Intranet pages > > > -- My understanding is that making this distinction accurately is Hard. > Is that true? What does IE do? MSIE configures this in Internet settings. The admin manually configures what constitutes "Intranet". > 8c) old and vulnerable plugins needed in an Intranet can be invoked by > Internet content Here, they are contradicting themselves. If they don't trust their own network enough to allow Basic Auth via HTTP even in the lowest security case, then they can't trust their Intranet to run vulnerable (!) plugins that would root all the client machines. Apparently, they care about settings and theoretical features, but not about fixing known-vulnerable software. Typical "features over security" mindset. This request is a nice hint for government hackers in which area they let their guard down. Sorry for the rant, but I've seen too many government agencies see run Firefox 7 or so. Ben