Showing posts with label Firefox. Show all posts
Showing posts with label Firefox. Show all posts

Friday, 30 October 2015

Copy-Pasting Google URL May Leak Past Searches


Who shares with Google search queries run the risk of seeing others get past searches. It discovered Jeremy Rubin. The problem is to reproduce in a few simple steps. As a first example, there must in Chrome or Firefox in the search bar something to be sought.

Then must make the Google search page to be searched for something else. The URL in the address bar will now include both searches. Users who do not see and pass the URL of their search so others can share unintentionally sensitive searches, says Rubin. He warned Google, but the Internet giant announced that it will not solve the problem.

Thursday, 17 September 2015

Mozilla Extends Deadline For Autographed Firefox Add-ons



Developers of add-ons for Firefox more time to meet the new demands of Mozilla. For harmful Firefox add-ons to address had demanded that all Mozilla Add-ons from Firefox would be 42 signed.Unsigned extensions will not work in Firefox.

All add-ons that are available on the Mozilla website, addons.mozilla.org (AMO), will be automatically signed and verified.Extensions which are offered through other channels must first be checked by AMO and signed. Add-ons that can not request a manual check by the automatic control haven. Mozilla late now that the deadline of Firefox 42 has shifted to Firefox 43. This version is scheduled for December 15th.

According to Lisa Brewster Mozilla had many developers indicated that they did not have sufficient time to meet the new requirements. Originally had the signings of add-ons for September 22 have been processed, if the beta version of Firefox 42 will appear. In addition to the extra time to get Mozilla developers will also make it clearer as an add-on for control is offered where exactly to meet.

Tuesday, 8 September 2015

Security Experts Swear By 20-Year-Old Mail Client Mutt


Regular Internet users are advised to use the latest software, but in the case of e-mail clients swear some security experts at the 20-year-old Mutt. Mutt is a small text-based mail client for Unix systems.The latest stable release dated June 9, 2007, although there last week released a new preview version.

Mutt is characterized by its simplicity. The software does not support HTML or emails with JavaScript. It is also for this reason that security for Mutt choose. "Simplicity is security," says Marek Tuszynski of the Tactical Technology Collective in front of Vice Magazine. Tools that run from the command line are characterized by a simpler design, fewer lines of code and the absence of vulnerable code such as Java or Flash. Therefore these types of programs will generally contain fewer bugs and be more stable.

Security researcher Christopher Soghoian says that he does not want his email client also contains the rendering engine of a web browser or JavaScript can handle. "The smaller the attack surface, the better," he tells. Mutt consists of "only" 100,000 lines code. Much less than the 14 million lines of Firefox and the 17.4 million of Chromium, the open source browser, which is the basis for Google Chrome. Due to the spartan look and feel is to use command line tools like Mutt mostly limited to technical users, even if they offer more safety than the programs in which the masses participate.

Saturday, 18 July 2015

Google's Tougher Action Against Unwanted Software


Google Chrome users in the coming weeks will see more warnings from the browser get that warn against unwanted software. Programs that are undesirable in Internet hijack the browser and then inject all kinds of ads are a gigantic problem, as shown by previous research by Google and the University of California.

The researchers wanted to know how big the problem of "ad injectors" actually was. This is software that injects ads on websites or existing ads replace.Google had in the first few months of this year, more than 100,000 complaints received ad injectors. During the investigation it was found that 5.5% of all IP addresses that Google sites visits with one or more ad injectors infected. In total, the researchers discovered more than 85,000 applications that hijack the browser and inject ads.

Detection

The detection of Google has been improved to detect this type of unwanted software, making short-term Chrome users more warnings will be given. "The mandate remains unchanged," says Stephan Somogyi from the Google Safe Browsing team. "We focus only on protecting users from malware, phishing, unwanted software, and similar evil. You will see a warning SafeBrowsing not get another reason to see."

According Somogyi unwanted software is distributed through a variety of ways, including the above-mentioned ad injectors. In many cases, Google's Safe Browsing technology is the last layer of defense, commented Google employee. Besides Safari and Firefox, Chrome also make use of Google's Safe Browsing technology.

Wednesday, 8 July 2015

Zero-Day Vulnerability In Flash Player Active Attacked - Update


The vulnerability in Adobe Flash Player which the Italian developer of government spyware Hacking Team disposal is now actively used to infect internet users with malware. Recently, an attacker managed to break in Hacking Team in there and made some 400GB of data booty.

Among the files an exploit was discovered a vulnerability in Flash Player for which no security exists a so-called 'zero-day'.Anti-virus firm Malwarebytes and researcher JuK of the blog Malware Do not Need Coffee now now report that several exploit kits about the exploit to have discovered by Hacking Team Flash Player flaw.

Exploit kits are programs that cyber criminals can infect Internet users through unpatched vulnerabilities in popular software.Thereby running Internet using Adobe Flash Player now a high risk of becoming infected with malware. Visiting a hacked or malicious Web site or see getting an infected ad is sufficient to run an infection.

Emergency Patch

Adobe yesterday evening let know that there are expected today to emergency patch will appear. The notice is still no reports that the vulnerability is also actively attacked. Google Chrome users seem to be already protected against the vulnerability. Yesterday, Google published because a new version of Google Chrome. Details on changes Google is not announced, but discovered that the embedded Flash Player in the browser but was upgraded to a version that is not vulnerable according to Adobe.

Update 12:38

Adobe has released the emergency patch already released . This is version 18.0.0.203 for Windows and Mac users, while version 18.0.0.204 for the Linux version of Chrome is available. For the Linux version of Firefox, version 11.2.202.481 appeared. The update will be rolled out in most cases via the automatic update function, but can also be downloaded manually from Adobe.com .

Saturday, 4 July 2015

Spoofing Vulnerability In Google Chrome Can Distort Address


A spoofing vulnerability in Google Chrome makes it possible for a malicious website to spoof the address bar, the browser also shows a valid SSL certificate. The attack last Tuesday on the Full Disclosure mailing list revealed by researcher David Leo.

Then was the demonstration of Leo adapted by Mustafa Al-Bassam , the HTTPS version of Facebook was spoofed. The security company which operates Leo reported the problem to Google, but the Internet giant announced that it will not fix the vulnerability, because this is actually a denial of service, even if the browser crashes.

In addition, the impact of spoofing vulnerability is limited because users can not do anything in the spoofed pop-up or page. A direct phishing attack via this vulnerability is not possible, Al-Bassam noted. Readers of Hacker News report that the spoofing problem is partly also present in Firefox, the browser only because it crashes.

Thursday, 21 May 2015

Adblock Plus Launches Its Own Browser For Android


The makers Adblock Plus , the popular browser extension on the Internet, launched its own browser for Android that ad blocking is central. Through Adblock Plus can block Internet ads. According to the developers, the add-on downloaded over 300 million times. If we look at the statistics of active daily users would look about 20 million Firefox users and over 10 million users use Chrome extension.

In the past, Adblock Plus created an extension for Android users, but Google has removed from the Google Play Store, because the add-on products or services other influences. By not being available in app stores is very difficult to reach mobile users, thereby fail not of existence. Additionally Adblock Plus for Android could only block ads on HTTP. In recent months, developers have therefore been working on its own mobile browser that integrates ad blocking.

Today is the first beta version of the browser released. The browser is open source and based on Firefox. The reason is that the Adblock Plus developers Mozilla as a project and as a company really admire. "Firefox for Android is a great mobile browser," so they claim. Most users would not know it, but the browser supports numerous extensions, including Adblock Plus. "Unlike Firefox on the desktop, we are very limited when it comes to integrating Adblock Plus in the user interface of Firefox for Android."

By developing its own browser have to integrate the developers more freedom to adblocking as basic feature that is both understandable and easy to configure. The developers say that they have big plans for the future. So we look to combine the Adblock browser and desktop browser users in a meaningful way. So far the mobile browser now gets all the attention and Internet recalled that test. According to the website of the Adblock Browser comes soon a version for iOS.

Thursday, 2 April 2015

Google Says Trust Certificates In Chinese CNNIC CA


Due to a recent incident with wrongly issued SSL certificates for Google sites Google has confidence in the Chinese certificate authority (CA) CNNIC terminated, which Google products such as Chrome will no longer recognize the certificates of CNNIC. Something that will be implemented through a future update for Chrome. Since this is very big impact, particularly Chinese Chrome users will have Google has decided to permit temporarily issued SSL certificates under CNNIC even by placing them on a public whitelist.

The reason for the measure is the recent discovery of rogue SSL certificates for various Google domains that were created by the Egyptian company MCS Holding. The company had been given the opportunity of CNNIC, which is a root CA. As root CA is CNNIC trusted by all major browsers. CNNIC had spent an intermediate certificate for MCS Holding, which the company for arbitrary domains could create SSL certificates. Because the intermediate certificate of CNNIC came, they were created SSL certificates also trusted by browsers.

According MCS Holding made ​​a human error sure that the existence of the rogue Google certificate was discovered. Google, Microsoft and Mozilla therefore decided to block these certificates. In addition, the CNNIC was heavily charged that MCS Holding gave an intermedia certificate, which the Chinese company had violated all sorts of rules. After further investigation, Google has now decided to tell all the confidence in CNNIC.
Certificate Transparency

Google argues in a statement that it believes that no other unauthorized SSL certificates have been issued or that the rogue Google certificates are used outside the test environment of MCS Holding. Regarding the Chinese certificate authority that Google must "Certificate Transparency" before implementing any request about the renewed confidence of CNNIC is considered.

Certificate Transparency is a technology developed by Google and is intended to address several structural flaws in the SSL certificate system. Thereby to unjustifiably spent and rogue SSL certificates are detected earlier. Mozilla has also decided to Certificate Transparency support .
Update

CNNIC called Google's decision unacceptable and unwise. The Chinese CA Google also calls to take the interests and rights of users into consideration. CNNIC let customers know their rights and interests will not be compromised.

Wednesday, 1 April 2015

Five Percent Google Visitors Infected With Adware


More than five percent of all people who visit websites from Google is infected with adware and within this group has at least half two or more "ad injectors" installed. This involves software that injects or replace ads on websites. According to research from the University of California that will be published on May 1, but the most important details of which Google has already put online.

According to the Internet giant ad injectors are a big problem. It is about users of both Windows and Mac, with Internet Explorer, Firefox or Chrome works. The adware is often bundled with other programs or via advertisements. Google received since January this year more than 100,000 complaints of Chrome users on ads that were injected. This makes it the most common problem that users complain about.

The researchers discovered further 192 misleading Chrome extension where 14 million people were victims become.Furthermore, it appears that 34% of the Chrome extension that injects ads as malware is to classify. For Internet users from adware and other unwanted software to protect warns Google Chrome users since late February for websites where these programs are offered. Last week, Google made ​​this opportunity available for Mozilla, Apple and other parties.

Friday, 27 March 2015

Egyptian Company: Google Rogue Certificates Were Mistake


The Egyptian company that had generated rogue SSL certificates for different websites from Google calls it a mistake that Google eventually discovered the certificates and hit alarm . Indeed, it was not intended that the certificates were discovered. This week, Google warned Internet users to rogue Google certificates generated by the Egyptian MCS Holding. Through the certificates could allow an attacker to Man-in-the-middle and phishing attacks on Internet users to intercept passwords and the contents of encrypted traffic.

MCS Holding is an Egyptian security company that delivers business networking. However, it had become a so-called "intermediate" certificate authority (CA), which was linked to the Chinese certificate authority CNNIC. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. In particular, Mozilla had great criticism of CNNIC that MCS Holding had given permission to the intermediate CA to generate SSL certificates.

The Egyptian company said in a statement that it had signed an agreement with CNNIC to a two-week period intermediate CA to act. This would be necessary for the testing of a new roll from cloud service. The test took place in a secure lab where the private key of the CA certifcate, to generate SSL certificates, stored in a firewall.

However, the firewall was set to automatically generate certificates for websites that were visited on the Internet. During an unguarded moment at the weekend would be one of the IT engineers decided to use the internet with Google Chrome. Chrome offers certificate pinning, which websites can indicate what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist.

Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. After MCS Holding by CNNIC had informed the certificate was immediately removed from the firewall and warned all parties involved. According to the Egyptian company, it is a human error which inadvertently took place. "We have no evidence of abuse, and we therefore recommend that people will not change their password or other action," said a company spokesman.

Measures

Meanwhile, Google has revoked the intermediate certificate of MCS Holding and also a Microsoft update released under Windows Users. From the description of the software giant appears that certificates for domains *. google.com , *.google.com.eg , *. g.doubleclick.net , *. gstatic.com , www.google.com , www.gmail .com and *. googleapis.com were created. Firefox comes next week with an update to revoke the certificate.

On the mailing list of Mozilla developers after the incident a heated debate erupted or CNNIC is not guilty because it would have violated all sorts of rules. While some want CNNIC is removed from the root store of Firefox. Mozilla could do this then this can have very serious consequences, especially for Chinese Firefox users, thereby HTTPS sites with SSL certificates of CNNIC and suspended beneath intermediate CAs can not visit. The Chinese CA Mozilla has therefore asked not to remove it from the root store CNNIC.

Wednesday, 25 March 2015

Google Lets Firefox And Safari Block Unwanted Software


After previously Google Chrome users already for websites with unwanted software warns Google has now made ​​this opportunity available for Firefox and Safari. Google offers to other parties the Google Safe Browsing API. This interface make Firefox and Safari example use of information that Google has about phishing sites and malware sites.

Through the Safe Browsing API would globally 1.1 billion people are protected. Google has the information it through the interface to other parties by giving now expanded with a list of websites that offer unwanted software. This involves software that affects the Internet, for example, by adjusting the start or showing additional ads on websites. Or Firefox and Safari will warn their users also for unwanted software or automatically via the API happens is still unknown.

Tuesday, 24 March 2015

Google Sounds Alarm On Rogue Google certificate



Google warns Internet users to rogue Google certificate issued by a company from the United Arab Emirates and could be used to perform man-in-the-middle and phishing attacks on Internet users, so as passwords and the contents of encrypted traffic intercept. SSL certificates are used inter alia for encrypting traffic between websites and visitors and identifying websites.

The company that rogue SSL certificates issued is MCS Holdings , a so-called "intermediate" certificate authority (CA), which is linked to the Chinese CNNIC certificate authority. SSL certificates from an intermediate certificate authority originate have the full authority of the CA under which they fall. CNNIC is in all major "root certificate stores" so the Google unfairly issued certificates would be trusted by most browsers and operating systems.

Chrome on Windows, OS X and Linux, ChromeOS and Firefox 33 and newer would have refused the certificate because certificate-pinning. According to Google, there are probably also issued certificates for other websites that may not be recognized by certificate-pinning. Certificate-pinning sites may indicate by what their CA SSL certificate has been issued. The browser will then put these certificates on a whitelist. Is the website for an SSL certificate that is issued by a different CA, then turn the alarm browser. Browsers like Chrome and Firefox currently support only pinning for some great websites.

Proxy

Following the fraudulent certificates, which were discovered on 20 March, Google CNNIC approached and was told that MCS Holdings only if issued certificates for domains they had registered themselves. That turned the company does not have done. MCS Holdings provides proxy appliances and firewall solutions that enable organizations of workers through the encrypted traffic can intercept self signed certificates. Should normally be set to the office computers to trust the proxy, but in this case it was not required by the wrongly issued certificates.

Google sees similarities with previously unduly certificates issued in 2013 by the French CA ANSSI . The Internet giant also denounces that CNNIC the power to create SSL certificates awarded to a company that was not suitable here. Chrome users do not have to do to be protected from rogue certificates, while Firefox users will have to wait for the arrival of Firefox 37 in which the certificate has been revoked. This version on March 31 appear.

Friday, 20 March 2015

Zero-Day Vulnerabilities In Flash, Windows, IE11 And Firefox Shown


During the Pwn2Own contest in Vancouver researchers have multiple zero-day vulnerabilities in Adobe Flash Player, Adobe Reader, Windows, Internet Explorer and Firefox demonstrated. The Pwn2Ownd contest is an annual event organized during the CanSecWest conference where researchers and the safety of popular browsers, and browser plug-ins can be tested.

In total on the first day of the event three vulnerabilities in Adobe Reader, three vulnerabilities in Adobe Flash Player, three vulnerabilities in Windows, two vulnerabilities in Internet Explorer 11 and two leaks in Firefox displayed. Through the vulnerabilities could allow an attacker full control of the computer without user interaction is much here for required. This involves visiting a hacked or malicious Web site or open a malicious PDF file.

None of the demonstrated vulnerabilities A security update is available, so there is zero-day vulnerabilities. However, the Pwn2Own rules state that only details may be shared with the organization. Which will then inform the relevant suppliers. Only after a security update is available researchers may publish details of the vulnerabilities.

In total, the researchers for their leak 317,500 dollars , which researcher Nicolas Joly dragging $ 90,000 knew inside. The Keen Team, consisting of several researchers, however, managed to leak in Adobe Flash Player and Adobe Reader, as well as bugs to earn the rights to increase Windows, totaling $ 140,000. Later today , various researchers are trying to re-hack Firefox and IE but there are now planned attacks on Google Chrome and Apple Safari.

Monday, 16 March 2015

Google Asks Firefox Users To Customize Search


Google shows a new call to Firefox Users searching on Google.com, but have set a different default search engine in the browser. In late January , the Internet giant was already showing a message, but the message is still apparent. Following the decision of Mozilla not Google but Yahoo to create the default search engine for Firefox Users US.

Thereby Yahoo saw rising share of the US search engine market since cooperation with Mozilla, from 8.7% to 10.7%, although growth in February was already over, as reported research firm StatCounter . A growing number of American Firefox users decided last month Google again to set as default search engine. However, Google now shows the new call, as discovered Twitterers

Friday, 13 March 2015

Google Protects 1.1 Billion People With Safe Browsing


The Google Safe Browsing technology protects every day more than 1.1 billion people, as the Internet giant has let know. Safe Browsing through that 8 years ago was developed, users of Chrome, Firefox and Safari warned of malware and phishing sites.

In the case of Chrome also warned if the user downloads malware. A warning that soon also when visiting websites that unwanted software will appear offering. At this time let Safe Browsing see 5 million alerts per day, for all kinds of malicious websites and unwanted software. Through the technology would be discovered each month over 50,000 malware sites and more than 90,000 phishing sites.

Google puts the technology is also responsible for alerting webmasters when there are specific problems with their websites, for example if they have been hacked and malware. The figures from Google published ahead of the 26th anniversary of the Web. "As the Web matures, so does the Safe Browsing technology. We look forward to the web and its users to protect for many years," says Panayiotis Mavrommatis of the Google Safe Browsing team.

Wednesday, 11 March 2015

German Government Unveils End-To-End Encryption For Citizens


A service of the German government that is used for the exchange of confidential documents between citizens and government will soon support end-to-end encryption. As of April, users of the Mail- use end-to-end encryption. For this, they install a plug-in for Firefox or Google Chrome. The encryption used De-Mail based on PGP (Pretty Good Privacy).

The plug-in must make the encrypted exchange of documents easier, the German government so late in the announcement to know. "Germany wants to lead the way in the use of digital services," said Interior Minister Thomas de Maiziere."Encryption plays an important role." More and more government services to communicate using De-Mail. It is expected that this year 200 new public services are connected.

Encryption

De-Mail is already using encryption for transport, but will now post protect through end-to-end encryption, so that the content is only visible to the sender and recipient. To be of service to use, users with a username and password to log in, or for extra security with a token, such as the new digital ID card, smart card and SMS code. Logging is done by the special De-Mail page of the provider. Several German ISPs, such as Deutsche Telekom, GMX, Web.De and United Internet are as De-Mail provider accredited.

They are also pleased with the new security measure. "End-to-end encryption was previously something for experts. Therefore we would like to see everybody De-Mails can encrypt" said Timothy Höttges of Deutsche Telekom. Besides the introduction of encryption measure will also be simplified the registration process for De-Mail. So soon enough an online bank account to register for De-Mail. Meanwhile, two million Germans would have a De-Mail, in which hundreds of thousands of civilians have been identified for the service and act can make.

Monday, 2 March 2015

Mozilla Removes Superfish Certificate From Firefox

Mozilla Firefox

For Firefox users against Man-in-the-middle attacks to protect Mozilla has decided to remove the Superfish certificate from the browser, but only when users first have the controversial program their computers have been removed. Superfish installed on computers a root certificate that could intercept SSL traffic and then inject ads.

However, the adware found to contain a vulnerability whereby users could be attacked. Several parties, including Lenovo, came with removal tools to remove both Superfish Superfish if the installed certificate. Some of these tools do not remove remove the Superfish certificate from Firefox, allowing these users are still at risk of being attacked.

To ensure that these users are still safe Mozilla started rolling out a hotfix . This hotfix checks whether Superfish is removed and then remove the Superfish certificate from Firefox. If Superfish namely still on the computer and Mozilla would remove the certificate from Firefox, users would no longer be able to visit HTTPS sites. The browser developer advises users therefore to the removal instructions to follow Lenovo, which both the software and the certificate can be removed manually

Sunday, 1 March 2015

EFF: Install New Computer Ever Again

EFF

If you buy a new computer that must first install all over again, because the software that comes standard is not to be trusted. That secures the American civil rights movement EFF. Following are programs like Superfish and PrivDog who intercepted the SSL traffic of users to inject ads and thus users exposed themselves to all kinds of risks.

This week it was announced that next Superfish, standard on some Lenovo notebooks shipped, other programs intercepting SSL traffic. One of these programs was PrivDog . A vulnerability in certain versions of PrivDog caused the software each certificate which replaced the Internet came and intercepted by a self-signed certificate. Even though it was about certificates that were not valid in the first place.

The Decentralized SSL Observatory of the EFF, which gathers information from the HTTPS Everywhere plugin for Firefox, has collected more than 17,000 different certificates PrivDog users. "Each of these licenses may be an attack. Unfortunately there is no way to know this for sure" says Joseph Bonneau of the Electronic Frontier Foundation (EFF).

"So what have we learned from this Lenovo / Superfish / Komodia / PrivDog debacle? For users, we have learned that the software is pre-installed on your computer can not be trusted, which means that reinstalling a clean operating system standard now procedure must be if someone has bought a new computer, " said Bonneau. The main lesson, he says, for software companies, which must stop intercepting SSL traffic of their users.

Saturday, 28 February 2015

Mozilla Firefox Does Not Come With Its Own Phone Privacy


Mozilla will next week at the Mobile World Congress in Barcelona launch not own privacy phone. Rumors about the phone after an article appeared in the Wall Street Journal , but according to Mozilla, it is a misconception. The journalist of the American newspaper was briefed on various privacy options that are present in Firefox OS.

These were options that part of the " Future of Mobile Privacy Project "and last year were unveiled at the Mobile World Congress. These options a user has more control over his privacy and data. It is, among other things, location tracking."Many apps such as weather apps do not need to know my exact location," said Claus Ulmer, head of data privacy at Deutsche Telekom, to the Wall Street Journal. "It is sufficient if the location is accurate to 20 kilometers."

Mozilla is working on the project privacy and developing new privacy options with Deutsche Telekom. A spokesman for the software developer, the journalist of the American newspaper this cooperation misunderstood and will therefore no new device will be launched. "The Future of Mobile Privacy Project is a collaborative effort and continuous Deutsche Telekom and Mozilla that was introduced a year ago," said the spokesman opposite TechCrunch .

Sunday, 15 February 2015

Prize For Hacking Chrome During Pwn2Own


During a hacker contest next month in Vancouver held hackers and researchers can win the grand prize by hacking Google Chrome. Who a vulnerability in Google's browser on Windows 8.1 knows how to find can earn $ 75,000.

This is more than for leaks is offered in other browsers. The game in question is the annual Pwn2Own contest, which takes place during the CanSecWest conference. Every year, researchers and hackers at the event to test the security of browsers.After the prize for Google Chrome follows Internet Explore 11 where a reward of $ 65,000 to be offered. Apple Safari on Mac OS X Yosemite follows with $ 50,000 in the third. Finally provides a successful hack of Mozilla Firefox at $ 30,000.

Besides the four browsers will be tested also the security of Adobe Reader and Adobe Flash Player. A successful attack on both programs make $ 60,000 on. This year, the difficulty for participants is much higher than previous years because the exploits that should be developed with Microsoft's free security tool EMET works.

The Enhanced Mitigation Experience Toolkit (EMET) is precisely designed to neutralize the effect of exploits. As a result, researchers now take two hurdles. Researchers who through their exploits on a Windows computer code with SYSTEM privileges can perform get an extra $ 25,000 reward. In addition, Google will in the case of a Chrome hack pay an additional reward of $ 10,000. Pwn2Own will take place on 18th and 19th March.