Mozilla To Force All Add-on Devs To Use 2FA To Prevent Supply-Chain Attacks
Peter Reutemann <[email protected]> Sat, 14 Dec 2019 08:47:54 +1300
| Newsgroups | gmane.org.user-groups.linux.waikato |
|---|---|
| Message-ID | <CAHoQ12LoqNXu8WVGd0+szD0xeqrPpSYQWCvk2T000J3P15w2hQ@mail.gmail.com> |
'Mozilla announced this week that all developers of Firefox add-ons must enable a two-factor authentication (2FA) solution for their account. From a report: "Starting in early 2020, extension developers will be required to have 2FA enabled on AMO [the Mozilla Add-Ons portal]," said Caitlin Neiman, Add-ons Community Manager at Mozilla. "This is intended to help prevent malicious actors from taking control of legitimate add-ons and their users," Neiman added. When this happens, hackers can use the developers' compromised accounts to ship tainted add-on updates to Firefox users. Since Firefox add-ons have a pretty privileged position inside the browser, an attacker can use a compromised add-on to steal passwords, authentication/session cookies, spy on a user's browsing habits, or redirect users to phishing pages or malware download sites. These types of incidents are usually referred to as supply-chain attacks.' -- source: https://it.slashdot.org/story/19/12/13/152239 Cheers, Peter -- Peter Reutemann Dept. of Computer Science University of Waikato, NZ +64 (7) 858-5174 http://www.cms.waikato.ac.nz/~fracpete/ http://www.data-mining.co.nz/ _______________________________________________ wlug mailing list -- [email protected] | To unsubscribe send an email to [email protected] Unsubscribe: https://list.waikato.ac.nz/postorius/lists/wlug.list.waikato.ac.nz