Re: Firefox Security Quarterly Newsletter - Q3 2017

Kevin Chadwick <[email protected]> Thu, 2 Nov 2017 14:26:03 +0000
Newsgroups gmane.comp.mozilla.security
Message-ID <[email protected]>
On Thu, 2 Nov 2017 03:25:38 -0700 (PDT)


> = Firefox Security Team Newsletter Q3 17 = 
> 
> Firefox Quantum is almost here, and contains several important
> security improvements.

The following message copied in and following thread might be of
interest to any interested in Firefox Security. The pledge model, makes
a lot of sense.

https://marc.info/?l=openbsd-misc&m=150652348327924&w=2
_____________________________________________________________________________



> Firefox has W^X compliance and so runs with the secure defaults.

it uses page aliasing, which is a shitty way of being compliant

> The latest Firefox (Not ESR as mtier provides) has recently had
> sandboxing for Windows and Linux added and legacy extensions will be
> phased out.
> 
> It is therefore likely possible to add pledge patches without
> depending on upstream and so Firefox could become the clear winner.

you really shouldn't be promising that to anyone.  it might not happen,
their design might not allow it.

pledge in giant programs is very rare.  chrome got LUCKY, and there is
no evidence that firefox will also.