[dylug] Mozilla Warns of Firefox Security Holes
varun malik <[email protected]> Wed, 2 Mar 2005 21:06:49 +0000 (GMT)
| Newsgroups | gmane.user-groups.linux.dylug |
|---|---|
| Message-ID | <[email protected]> |
Hi All, How is everyone doing ? I was just checking out my Yahoo Groups Home Page and found that dygroups now has 61 members with the latest addition of Nitin. ( Welcome to the Group Nitin hope you have a nice time here. ) Now what i was wondering is have 61 members ... where is everyone ... Hardly 10-15 posts in 1month and half of them about jobs ... hmmm someone need to do something about it. Amit, an interesting topic you came up with ... Sad only 1 response. Anyways i think i rather go for free s/w cause at least then i can use it peacefully. Common open source is good, no doubt about it but tell me one thing ... if i give you the codes for Linux and charge you $100 will you still be that much interested in it. Or if i give you the codes that make gmail run and charge you for it ... fine you can open your own amit-mail but not everyone has the potential to do that. Free makes more sense ... it reaches the masses. And think about a clerk or a school teacher they need to use office suits, what good the code will be to them ??? At least using freeware they know they are not doing anything wrong and peacefully concentrate on their profession. And fine if the guy who made it should get something out of it but HOW MUCH. Building Microsoft Office, must have cost bill gates a million but at the end of the day he made zillions. I know many people will differ but these are my thoughts. Sometimes being computer engineers we forget that the rest of the world does not understand codes and needs what their brains can simply USE. Otherwise we'll loose our usefulness A more serious issue came to my knowledge and i would like to share it with all. This one is specially for all my firefox loving friends who particularly hated my post against it. ( i am laughing ... u bet i am ) Foundation releases an updated browser that includes fixes to many flaws. Joris Evers, IDG News Service Monday, February 28, 2005 Several security vulnerabilities in Firefox and the Mozilla Suite of Internet software put users of the open-source products at risk of hacker attacks, the Mozilla Foundation is warning. The organization released Firefox 1.0.1, which fixes 17 security flaws in the popular Web browser. The most serious flaws could allow an attacker to gain full control over a victim's PC, the Mozilla Foundation says in a statement. Firefox 1.0 was released in November and has since been downloaded more than 27 million times. Firefox 1.0.1 also includes several fixes to guard against spoofing of Web addresses and the security indicator on Web sites. These vulnerabilities could be exploited for phishing scams, which typically use spam e-mail messages to drive people towards fraudulent Web pages that look like legitimate e-commerce sites. One of the changes made in Firefox 1.0.1 is in the way the browser handles international domain names (IDNs). These names are now displayed differently to make it easier to spot spoofed Web sites. Because of the way Firefox displayed IDNs, it was possible to register domain names with international characters that resembled other common characters, thus tricking users into believing they were on a trusted Web site. For protection against possible exploitation of the security flaws, users should download and install the latest version of Firefox, the Mozilla Foundation says. The organization does not offer patches to fix the problems without having to install a new browser. Most of these flaws also affect the Mozilla Suite, which includes a Web browser, an e-mail client, Internet Relay Chat client, and Web page editor. However users of the suite are left vulnerable because no fixes are yet available. Mozilla 1.7.6, the update that fixes the issues, is due out in "a couple of weeks," according to a Mozilla Foundation spokesperson. False Sense of Security? The public warning of the security vulnerabilities is evidence that the Mozilla Foundation's products give a false sense of security, says Thor Larholm, a senior security researcher with PivX Solutions in Newport Beach, California. "The only reason Mozilla and Firefox have a good track record in security with a low number of security vulnerabilities is simply because they don't tell anyone about them," Larholm says via e-mail. "The Mozilla Foundation has fixed hundreds if not thousands of security vulnerabilities over the last few years without notifying the world and without providing security patches, instead they have simply just told their users to upgrade," he says. "We have to remember that all software has security vulnerabilities, the only difference is in how we anticipate them and inform the world about their existence." -----------END--------- Need I say anything more ??!!! Now if this was a case with Microsoft I am so sure it would have hit Star News by now. Well at least Microsoft does not hide its faults ( honesty is the best policy after all ) Well, i know you people are crazy for firefox ... i have only 1 thing to say ... Better Upgrade Soon !!! Cheers Varun PS : Waiting for comments, at least from vivek! Yahoo! India Matrimony: Find your life partneronline.