Re: UK Government's documentation on Firefox security

Robert Strong <[email protected]>
Newsgroups gmane.comp.mozilla.security
Message-ID <CAOtrBA8c2btCuoUa0=pgUNGAKa2hG7zq+_F2WNHpvyH9NNKvTA@mail.gmail.com>
On Wed, Nov 18, 2015 at 2:28 PM, Ben Bucksch <[email protected]>
wrote:

> Gervase Markham wrote on 02.11.2015 16:49:
>
> 7) No notification if browser updates fail
>>
>
> This is interesting. That means updates are vulnerable to a downgrade
> attack. This should be fixed for everybody.
>
It would be interesting to know how they accomplished this. The one case I
can think of is when we wait up to 10 consecutive failures to contact the
update server before notifying the user.

Robert



>
> 4) Can't disable addon installation, and addons can be silently evil
>>
>> -- Can we add a pref to disable this?
>>
>
> That would be xpinstall.enabled = false , I think
>
> 5) Safe Browsing warnings are bypassable
>>
>> -- Can we add a pref to disable this?
>>
>
> Why should Google be the final authority on what gov users in the UK can
> see?
>
> This could easily be implemented as extension. Same for some other points
> in the list.
> BTW: A number of enterprises already use extensions to customize Firefox
> to their needs. Killing extensions would break all that.
>
> 6) Can't disable Basic/Digest Auth over HTTP
>>
>> -- UNCO bug about warning:
>>       https://bugzilla.mozilla.org/show_bug.cgi?id=1185145
>>     UNCO bug about turning off altogether:
>>       https://bugzilla.mozilla.org/show_bug.cgi?id=966754
>>
>
> Ditto. There are legitimate uses for this.
>
> 8) No separation between Internet and Intranet pages
>>
>>
>> -- My understanding is that making this distinction accurately is Hard.
>>     Is that true? What does IE do?
>>
>
> MSIE configures this in Internet settings. The admin manually configures
> what constitutes "Intranet".
>
> 8c) old and vulnerable plugins needed in an Intranet can be invoked by
>>      Internet content
>>
>
> Here, they are contradicting themselves. If they don't trust their own
> network enough to allow Basic Auth via HTTP even in the lowest security
> case, then they can't trust their Intranet to run vulnerable (!) plugins
> that would root all the client machines.
>
> Apparently, they care about settings and theoretical features, but not
> about fixing known-vulnerable software. Typical "features over security"
> mindset. This request is a nice hint for government hackers in which area
> they let their guard down. Sorry for the rant, but I've seen too many
> government agencies see run Firefox 7 or so.
>
> Ben
>
> _______________________________________________
> dev-security mailing list
> [email protected]
> https://lists.mozilla.org/listinfo/dev-security
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.