Mozilla To Force All Add-on Devs To Use 2FA To Prevent Supply-Chain Attacks

Peter Reutemann <[email protected]> Sat, 14 Dec 2019 08:47:54 +1300
Newsgroups gmane.org.user-groups.linux.waikato
Message-ID <CAHoQ12LoqNXu8WVGd0+szD0xeqrPpSYQWCvk2T000J3P15w2hQ@mail.gmail.com>
'Mozilla announced this week that all developers of Firefox add-ons
must enable a two-factor authentication (2FA) solution for their
account. From a report:

"Starting in early 2020, extension developers will be required to have
2FA enabled on AMO [the Mozilla Add-Ons portal]," said Caitlin Neiman,
Add-ons Community Manager at Mozilla. "This is intended to help
prevent malicious actors from taking control of legitimate add-ons and
their users," Neiman added. When this happens, hackers can use the
developers' compromised accounts to ship tainted add-on updates to
Firefox users. Since Firefox add-ons have a pretty privileged position
inside the browser, an attacker can use a compromised add-on to steal
passwords, authentication/session cookies, spy on a user's browsing
habits, or redirect users to phishing pages or malware download sites.
These types of incidents are usually referred to as supply-chain
attacks.'

-- source: https://it.slashdot.org/story/19/12/13/152239

Cheers, Peter
-- 
Peter Reutemann
Dept. of Computer Science
University of Waikato, NZ
+64 (7) 858-5174
http://www.cms.waikato.ac.nz/~fracpete/
http://www.data-mining.co.nz/
_______________________________________________
wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected]
Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz