Showing posts with label Download Mozilla Firefox. Show all posts
Showing posts with label Download Mozilla Firefox. Show all posts

Thursday, 5 November 2015

Civil Rights Movement Praises AdBlocker In Firefox


The American civil rights movement EFF has very positively reacted to the latest version of Firefox, which typically has a built-AdBlocker features. Still, there is room for improvement, according to the organization. Yesterday released Firefox 42 includes Tracking Protection.

These Tracking Protection blocks trackers, analytics scripts, tracking pixels and also advertisements that follow users. For this, Firefox uses the blocking list of the Disconnect browser extension. This expansion also blocks all kinds webtrackers.According to Noah Swartz of the EFF Firefox does not take sides when it comes to online advertising, but has chosen to block ads that violate user privacy. Something the EFF agrees with.

The EFF is pleased that the browser now offers standard such an option. Earlier, namely Disconnect from the Android app store removed. Yet Swartz sees room for improvement. Tracking Protection is now enabled only when using the Private Browsing mode. If the option is enabled by default to the EFF for all users who have chosen within the browser for Do Not Track, whether via Private Browsing surfing or not. Swartz also hopes that other browser developers will follow the example of Mozilla.

Monday, 26 October 2015

Mozilla Firefox Extension Removes Spying After Miss



Mozilla has removed an extension for Firefox because those users spying and this is not detected during the inspection. It is about the add-on Download Manager S3. With nearly 120,000 users a reasonably popular add-on. Through the add-on downloads can be managed through a small status bar.

The developer of the Download Manager prompts users through a pop-up to support. In this case, additional ads will be displayed, according to the explanation of the add-on. A reader of Reddit discovered, however, that if the user agrees to this, the add-on sends back all kinds of information, such as the HTML of the page visited, customer ID and other data.The reader notes that data collection is not enabled by default, but the developer is trying to turn it in a misleading manner. An employee of Mozilla confirmed on Reddit the behavior of the add-on. He argues that Mozilla has made ​​a mistake.

All extensions for Firefox on addons.mozilla.org appear to be fact checked. A reviewer who checks the add-ons saw a "policy violation" in the latest update of the add-on was added overlooked. Then Mozilla decided all the add-ons on addons.mozilla.org check for this offense, which have resulted in another similar case. Both add-ons are now disabled, according to the Mozilla employee. The Download Manager S3 is indeed no longer on addons.mozilla.org to find, but Mozilla has not yet extend to the blocklist put. In this case, Firefox will unsafe or unstable add-ons that users turn off automatically.

Saturday, 10 October 2015

Firefox Stops Java Support, But Flash Continues To Support


Like Google and Microsoft will also stop supporting Mozilla based on NPAPI plug-ins, but for Adobe Flash Player is an exception. According to Mozilla are plug-ins that the old Netscape Plug-in API (NPAPI) use responsible for performance issues, crashes and security incidents.

End 2016 Mozilla also wants to stop the support for most NPAPI plugins in Firefox. A process that was initiated some years ago, by letting users activate these plug-ins manually. In addition, the new 64-bit Firefox for Windows platform will be launched entirely without support plug-ins, because it is no longer needed by the browser developer.

Because Adobe Flash Player on so many websites use Mozilla continues this plug-in, as an exception to the rule, do support. "Mozilla and Adobe will continue to work to make improvements to the Flash experience within Firefox, among others in terms of stability and performance, and security features," said Mozilla's Benjamin Smedberg.

Java

He advises websites that use plugins such as Silverlight and Oracle Java to switch to web technologies. These plug-ins will be late next year would no longer supported. In the event websites can not be without, for example Java advised to develop the required features as a Firefox extension. In order to end of Java within Firefox run smoothly cooperates with Oracle there. So advises Oracle now on websites instead of Java applets, plug-in free solution such as Java Web Start to use.

Friday, 9 October 2015

Mozilla Adopts Proposal For Blocking Online Content


The blocking of online content, and particularly ads and trackers already done a lot on the desktop, but with the arrival of iOS also ninth in the mobile ecosystem on the rise. The reason for Mozilla to present a proposal to block online content.

"Blocking content will not disappear, it is now a part of our online experience. But the landscape is not well understood, making it difficult to see how we can foster an open and healthy web," said Mozilla's DENELLE Dixon Thayer. According to her, let the increasing availability and use of content blockers show that users want their online experience.

"This is a good development. But the blocking some content can be harmful without it being immediately clear", says she.This concerns for example content blockers who will determine which content is or is not being displayed. This may ultimately harm innovation and competition. In the long term, users can also lose just as much control as they win, warns Dixon Thayer.

Mozilla therefore has three principles for content blocking proposed. Firstly, content blockers focus on the needs of users, rather than to block specific content, such as advertisements. In addition, content blockers should be transparent in front of users and give them control. The last principle Mozilla advocates openness. Blocking should provide a level playing field, regardless of the origin of the content. This last principle focuses on certain adblockers who continue to allow ads from certain parties.

Sunday, 4 October 2015

Android Version Firefox Receives Click-To-Play For Images



To save bandwidth and ensuring that websites load faster Mozilla has released an early test version of Firefox 44 for Android added click-to-play for images. Click-to-play is a mechanism that the browser is now used to activate browser plug-ins.

A user in this case will have to make an extra click before a Web browser plug-in can call. This should prevent users automatically via vulnerable browser plug-ins can be attacked because the user still needs to activate the plug-in. Click-to-play for images but works slightly different and mainly saving data traffic and faster loading websites as the reason. In case an image for a larger view links provides a single tap on the screen that the bigger picture is loaded.

A long tap on the image displays the context menu in which the user can then choose to display the image. The option currently applies to separate images. A user will be on a site with multiple images therefore have to tap several times before the images are displayed on the page, says Soren Hentzschel who discovered the feature. Click-to-play for images present in the Nightly version of Firefox 44 and must itself be activated by users.

Friday, 25 September 2015

Mozilla: Industry Must Understand Adblock Users Better


In recent weeks on the internet between the supporters and opponents of adblockers a fierce debate erupted, but according to Mozilla, it is important that the industry understands why users use such resources on the web.

The answer here is not entirely clear, according to Mozilla's DENELLE Dixon Thayer. The reasons vary by user and device used. Desktop Users would be more focused on their privacy, and performance, while mobile users want to reduce power and data usage. "As an industry, we need to better understand the wishes of users," said Dixon Thayer. The wishes of users and commercial interests are not mutually exclusive. Rather they are both necessary for a healthy web, according to the Chief Legal Officer of Mozilla.

In addition, especially the collection of usage data plays an important role. According to Dixon-Thayer the collection of data is not inherently detrimental. It can also provide all kinds of benefits. However, it is important that users know this and keep control of the data collected. Otherwise, the confidence in the entire system can be lost, which is also at the expense of the proper parties.

Tracking Protection

Mozilla now wants to determine the cause of the problem which has arisen not only by research but also by developing features and products that provide a better balance and increase confidence in the web. In order to find this balance is also required to the input from users. Therefore, users are asked in the latest beta version of Firefox Private Browsing with Tracking Protection test. Through this feature, users have more control over the data collection.

"As an industry, we need to see which places the user in the product vision instead of the user as a goal to be achieved. It is the only way to respect user choices and the best, most trusted and valuable experience offer, "concludes Dixon Thayer.

Wednesday, 23 September 2015

Mozilla Patches Numerous Leaks In Firefox 41


Mozilla has released a new version of Firefox where 27 vulnerabilities patched. Through six vulnerabilities an attacker without much interaction from a user his or her system in the worst case can take over completely. This would require visiting a hacked or malicious Web site or see getting an infected ad suffice.

In Firefox 41 are further resolved numerous other bugs and added new features. One of the new additions to the browser is perfect forward secrecy for WebRTC. WebRTC is an open source project developed by Google which provides browsers with Real-Time Communications (RTC). To the communications from users secure for applications and applications that WebRTC now use perfect forward secrecy required.

PFS at each session to generate a separate key and removed after the end of the session or sending a message. In the case attackers the encryption key compromise, they do not yet have access to the previously stored messages (sessions) of users, as these are generated using a separate derived key. WebRTC, according to critics, a privacy risk because the information users can leak. Updating to Firefox 41 via the automatic update feature of the browser, Mozilla.org.

Monday, 7 September 2015

Microsoft Discourages Firefox And Chrome At Bing Users


Microsoft uses its own Bing search engine to prevent Internet users use Google Chrome or Mozilla Firefox. Who through Bing for 'firefox' or 'chrome' is looking for gets a big black bar on the screen stating that Microsoft Windows 10 recommends the use of Microsoft Edge.

This was discovered by VentureBeat. The bar also contains a button that a page opens with the advantages of Microsoft Edge. The page is available only for US users only, the message isn’t showing up in other countries.The black bar appears also to be shown once and does not appear in the search for 'opera'. Microsoft said in a statement that the notification is intended to give people information quickly and easily. In the past also Yahoo and Google to bring people in a similar way to have to adjust their browser or search engine.

Saturday, 22 August 2015

Mozilla's Chrome Extensions Support In Firefox


Mozilla has announced major changes to the operation of add-ons in Firefox, including the possibility of later extensions for Google Chrome and Opera and possibly Microsoft Edge will work in the browser. In addition, measures are being taken against spyware, adware and other malicious add-ons.

According to Mozilla developers have much of a Firefox add-on also similar extensions for Chrome, Safari, Opera or developed. "We want the development of add-ons is more like web development, that same code using a set of standards across multiple browsers running," said Mozilla's Kev Needham. That is why Mozilla is working on a new API called Firefox WebExtensions.

Extensions for Chrome, Opera and possibly in the future, Microsoft Edge will therefore run in Firefox as Webex Tension.According to Needham, the API a number of advantages, such as supporting multiple processes and reducing the risk of malicious add-ons and malware. WebExtensions will like other Firefox add-ons work with Mozilla are signed and via addons.mozilla.org to find. A test version of WebExtensions is already available in the test version of Firefox 42.

Signings

To protect users from malicious add-ons from Firefox 42 will all extensions must be checked by Mozilla and signed. Unsigned extensions will not work in Firefox. From 41 unsigned Firefox extensions will be automatically disabled, but users still have the ability to turn back.

According to Needham, the strategy of Mozilla advantages and disadvantages. Developers who already support Chrome extension will benefit from it, because they now have only one code base support instead of two. For developers who develop only Firefox add-ons adjustment will be greater. "But we think that the end result for both users and developers of Firefox it will be worth it," said Needham.

Tuesday, 18 August 2015

Fuss About Speculative Connections Firefox


On the Internet fuss arose over a feature in Firefox for ensuring that websites load faster, but can also help to track users. Several years ago, Mozilla has developed an API (application programming interface) to "speculative connections" allows to load websites faster than expected is that the user will also open a link.

Only moving the mouse over a link ensures that a request is sent to the web server of the website. Recently, a user sketched out a scenario whereby can consider whether certain email addresses are in use. Suffice it to any e-mail address to send an e-mail with a link to a unique IPv6 address. Once the user receives the message and moves his mouse over the link or the mouse in the area with link state, Firefox will send the request and may be checked to see if the email address is still in use.

Users can take steps to disable the feature, so Mozilla late this article know. For this, users in the address bar about: config entries. Then there must be sought on network.http.speculative-parallel-limit and must be the value to 0.

Monday, 17 August 2015

Mozilla Improves Privacy Protection In Firefox


Mozilla has released new test version of Firefox that should better protect the privacy of users. All browsers now offer an option like "Private Browsing" or "Incognito Mode". These features are primarily aimed to make locally on the computer no trace.

For example, things like websites visited and cookies afterwards removed. According to Mozilla that users of Private Browsing, however, that they want more control over their privacy then provides the function at this time. Therefore, the Private Browsing function is modified so that certain parts of websites are blocked. It is in this case parts that follow users across multiple websites.

Some parties set Mozilla has incorporated a AdBlocker in Firefox this way. Martin Brinkmann of gHacks however, that the function does not block ads, but just famous tracking servers. Mozilla warns that some sites may not work anymore as the tracking components are blocked. However, users can at any time activate the block tracking components. For now, the feature is only available in the Developer Edition of Firefox 42 , which is available for Linux, Mac and Windows.

Thursday, 6 August 2015

Developer: Mozilla Threaten Windows Users


Since the launch of Thunderbird 38 Mozilla e-mail client of the Lightning extension provided, but how the extension is implemented is a security risk for Windows users. The German software developer Stefan Kanthak even calls it a "security nightmare".

Lightning provides Thunderbird with an agenda. The extension is enabled by default, although users can turn off or Lightning.Mozilla install the extension in the profile of users and not in the Program Files directory. Mozilla thus violating the mandatory development guidelines for Windows, according Kanthak. It also introduces a security risk.

Applications in the Program Files directory can only be changed by users with appropriate privileges. That does not apply to files in the AppData directory. It is in this directory where the Thunderbird profile of users is stored and the Lightning extension is located. "This is a fundamental vulnerability in Mozilla's extensions and a security nightmare," writes Kanthak the Buggtraq mailing list .

According to the developer, users perform for safety reasons no code in their user profile. That does not apply to Lightning, which is being carried out from here. An attacker with access to the system can therefore replace the DLL files and JavaScript of the extension. Kanthak Mozilla advises to turn off local installation of extensions in Mozilla products and only global installations to allow extensions.

Wednesday, 15 July 2015

Firefox Blocks All Versions Of Adobe Flash Player


Mozilla users to protect against attacks and malware has decided to block all versions of Adobe Flash Player inside Firefox. The popular browser plug-in contains two vulnerabilities that have still not been patched, and one of which is actively used by attackers to infect computers with malware. Reason for Mozilla to Flash Player on the blocklist place of Firefox.

Through the blocklist may block Mozilla plug-ins in Firefox, for example, contain malware or vulnerable. In this case, the blockade of Adobe Flash Player version 18.0.0.203. Instead of Flash Player completely block, users can turn on the plug-in itself still again. This can be arranged through the Add-ons for Firefox. Adobe has stated this week to come up with a patch for the two new vulnerabilities.

Sunday, 28 June 2015

Apple Blocks Unsafe Versions Of Flash Player


Because of a zero-day vulnerability in Adobe Flash Player which this week emergency patch released Apple has decided to block all versions of the emergency patch. The vulnerability was used in targeted attacks before the update was available from Adobe. Through the leak could allow an attacker complete control of the computer.

In order to achieve this, e-mails have been sent to links with different targets. The link in the message pointed to a website that then tried to install malware through the vulnerability in Flash Player. According to Adobe, the attacks against Firefox users on Windows XP and IE users on Windows 7 and older Windows versions. Nevertheless, Mac users were advised to install the emergency patch within 72 hours.

Mac users who have not yet done receive when visiting websites in Safari that Flash Player now invoke a pop-up . Which reports that Flash Player is outdated and needs to be updated. Something can be done via a button in the same message.The blockade applies to all Flash Player versions prior to version 18.0.0.194 and 13.0.0.296.

Wednesday, 10 June 2015

Mozilla Firefox Raises Reward For Bug Reports



Over the past five years, Mozilla has $ 1.6 million paid to hackers and researchers who discovered bugs and vulnerabilities in Firefox and reported, but according to the open source developer's time for change.When Mozilla five years ago with the program began, a maximum reward of $ 3,000 paid for critical vulnerabilities. That amount has now increased to $ 7,500.

In addition, Mozilla also uses variable remuneration, depending on the quality of the message, the severity of the leak and the simplicity with which the vulnerability to attack. For this category of special vulnerabilities or attack techniques, researchers can get more than $ 10,000. Furthermore Mozilla also vulnerabilities as "moderate" may be considered also qualify for a reward, something that previously was not the case.

These vulnerabilities deliver between 500 and 2,000 dollars on. Besides cash researchers will also be rewarded with eternal fame as a Mozilla Firefox Security Bug Bounty Hall of Fame was launched where all the researchers who find bugs listed.The reward program applies to Mozilla Firefox, Thunderbird, Firefox for Android and FirefoxOS.

Tuesday, 17 March 2015

Mozilla Launches Memory Scanner For Servers


Mozilla has released a tool that allows for real-time scan the memory of a great number of servers on any suspicious items. The open source developer manages thousands of servers for the development of products and offering services.

Developed to monitor the security of these servers was the Mozilla Investigator (MIG). MIG can the file system and network information on thousands of machines simultaneously monitors, which should provide more insight into the infrastructure.Until recently, however, it was not possible to isolate MIG to analyze the memory of running processes. Yet it would be for security investigation.

Masche

In recent months developed several students why a "memory forensics library" on Linux, Mac OS and Windows is running. Masche , as the tool is called, can scan the memory of running processes, without having impact on the system. It does not offer the same detail as advanced forensic software, but is focusing on " regexes "and" byte strings "in the processes of many systems.

This makes it possible to monitor the memory of such systems quickly and in real-time. The source code of Masche is completely open source and available on Github . Mozilla tool will integrate within MIG and deploy within their own infrastructure. This should ultimately improve scanning performance of the tool, which in turn Mozilla will share with the community.