Re: UK Government's documentation on Firefox security
Robert Strong <[email protected]>
| Newsgroups | gmane.comp.mozilla.security |
|---|---|
| Message-ID | <CAOtrBA8c2btCuoUa0=pgUNGAKa2hG7zq+_F2WNHpvyH9NNKvTA@mail.gmail.com> |
On Wed, Nov 18, 2015 at 2:28 PM, Ben Bucksch <[email protected]> wrote: > Gervase Markham wrote on 02.11.2015 16:49: > > 7) No notification if browser updates fail >> > > This is interesting. That means updates are vulnerable to a downgrade > attack. This should be fixed for everybody. > It would be interesting to know how they accomplished this. The one case I can think of is when we wait up to 10 consecutive failures to contact the update server before notifying the user. Robert > > 4) Can't disable addon installation, and addons can be silently evil >> >> -- Can we add a pref to disable this? >> > > That would be xpinstall.enabled = false , I think > > 5) Safe Browsing warnings are bypassable >> >> -- Can we add a pref to disable this? >> > > Why should Google be the final authority on what gov users in the UK can > see? > > This could easily be implemented as extension. Same for some other points > in the list. > BTW: A number of enterprises already use extensions to customize Firefox > to their needs. Killing extensions would break all that. > > 6) Can't disable Basic/Digest Auth over HTTP >> >> -- UNCO bug about warning: >> https://bugzilla.mozilla.org/show_bug.cgi?id=1185145 >> UNCO bug about turning off altogether: >> https://bugzilla.mozilla.org/show_bug.cgi?id=966754 >> > > Ditto. There are legitimate uses for this. > > 8) No separation between Internet and Intranet pages >> >> >> -- My understanding is that making this distinction accurately is Hard. >> Is that true? What does IE do? >> > > MSIE configures this in Internet settings. The admin manually configures > what constitutes "Intranet". > > 8c) old and vulnerable plugins needed in an Intranet can be invoked by >> Internet content >> > > Here, they are contradicting themselves. If they don't trust their own > network enough to allow Basic Auth via HTTP even in the lowest security > case, then they can't trust their Intranet to run vulnerable (!) plugins > that would root all the client machines. > > Apparently, they care about settings and theoretical features, but not > about fixing known-vulnerable software. Typical "features over security" > mindset. This request is a nice hint for government hackers in which area > they let their guard down. Sorry for the rant, but I've seen too many > government agencies see run Firefox 7 or so. > > Ben > > _______________________________________________ > dev-security mailing list > [email protected] > https://lists.mozilla.org/listinfo/dev-security >