Showing posts with label Firefox Extensions. Show all posts
Showing posts with label Firefox Extensions. Show all posts

Thursday, 17 September 2015

Mozilla Extends Deadline For Autographed Firefox Add-ons



Developers of add-ons for Firefox more time to meet the new demands of Mozilla. For harmful Firefox add-ons to address had demanded that all Mozilla Add-ons from Firefox would be 42 signed.Unsigned extensions will not work in Firefox.

All add-ons that are available on the Mozilla website, addons.mozilla.org (AMO), will be automatically signed and verified.Extensions which are offered through other channels must first be checked by AMO and signed. Add-ons that can not request a manual check by the automatic control haven. Mozilla late now that the deadline of Firefox 42 has shifted to Firefox 43. This version is scheduled for December 15th.

According to Lisa Brewster Mozilla had many developers indicated that they did not have sufficient time to meet the new requirements. Originally had the signings of add-ons for September 22 have been processed, if the beta version of Firefox 42 will appear. In addition to the extra time to get Mozilla developers will also make it clearer as an add-on for control is offered where exactly to meet.

Thursday, 30 July 2015

Chrome Extension Prevents Profiling By Type Of Behavior



Websites, Internet users nowadays not only to follow based on their IP address or browser features, including the way one type provides companies with sufficient information to draw up a profile. Two researchers, Paul Moore and Per Thorsheim therefore have developed an extension for Google Chrome called " Keyboard Privacy "that prevents profiling by type of behavior.

Several banks were already using the technology. The technology according to the researchers, also interesting for totalitarian regimes, as well as advertisers. Even when using an Internet user or a Tor proxy, he would still be recognized by the use of his type of behavior. In order to counter this form of tracking and profiling Keyboard Privacy changes the rate at which typed characters arriving at the website.

Moore argues that the extension reduces security, but this is not a bad thing necessarily. "It's important to find a good balance between security and privacy. It is very difficult to raise one without the other measurable decrease," he notes.Internet users who like their type of behavior on websites "leak" or their bank will be forced to, according to Moore extension per website on or off. Soon there will appear a Firefox version of the extension.

Thursday, 2 July 2015

Researcher Circumvents NoScript Firefox Through Google Cloud


A researcher has managed to circumvent the popular Firefox extension NoScript by using the Google cloud. NoScript is an extension that can block JavaScript and other code on websites. It thus prevents malicious code on a compromised Web site can be started or ads, trackers and active content are automatically loaded.

The add-on protects both security and privacy. More than 2.2 million Firefox users have installed NoScript, making it one of the most popular extensions for Firefox. NoScript also allows users to set up a whitelist domains. Scripts in this domain will be run automatically. Some areas are already standard on the NoScript whitelist, such as Mozilla, YouTube, Google and Yahoo.

This concerns not only the fields, but also the sub-domains under the domain. Besides google.com also scripts on voorbeeld.google.com automatically accepted by NoScript. Recently discovered researcher Matthew Bryant that one of the areas that had expired stood on the NoScript whitelist and thus was available to everyone. Bryant registered the domain and placed here Javascript code, which automatically performed by NoScript. The developer of NoScript came with an update so that the domain from the default whitelist has been removed.

The publication of Bryant urged another researcher to look for a new opportunity, as well as subdomains of whitelisted domains attack vector for an attack can be used. Researcher Linus Sarud saw that the domain googleapis.com standard in the whitelist, meaning that script code storage.googleapis.com this is done by default. Through this domain, users can host files as they use the Google cloud storage. Another researcher named Mathias Karlsson worked out the idea and came up with code that NoScript was again defeated.

The problem has been fixed by the domain googleapis.com change to the whitelist in ajax.googleapis.com . However, subdomains are still automatically whitelist. Users of NoScript, however, can delete the default whitelist and only own domains to this place.

Wednesday, 11 February 2015

Mozilla Firefox Is Harmful Tackle Add-ons


Mozilla has announced a plan to which the browser developer harmful Firefox add-ons is targeting. One of the strengths of Firefox is the ability to support enhancements. Extensions through both Mozilla's own website addons.mozilla.org (AMO) and other channels can be spread. This gives developers a lot of flexibility and options, but also provides an opportunity rotten apples.

"We are responsible for our add-ons ecosystem and can not simply look at the side as our users affected by malicious add-ons," said Mozilla's Jorge Villalobos . This relates to extensions that injecting ads or execute scripts on social networking sites. Mozilla has follows guidelines, but keep the malicious extensions are not there and are usually spread outside the duct from Mozilla. Mozilla does have the ability to block these add-ons, but finding it is becoming impractical. Villalobos notes that Mozilla as only Google could offer add-ons through its own channel, but that is too easy an option.

Therefore, there is now announced another plan which henceforth only signed add-ons are accepted. All add-ons on AMO will be signed automatically. Extensions offered through other channels must first be checked and signed by AMO. Add-ons that can not request a manual check by the automatic control haven. Transition will occur whereby unsigned apps for a period of 12 weeks will give a warning. After that it will no longer be possible to install these extensions.

To give developers still some freedom will it be possible to install unsigned extensions in early test versions of Firefox.Ultimately, the measure must ensure that extensions that fully audited and signed are simpler and more user-friendly can be installed wherever they are offered. The plan now is to begin the transition phase in the second quarter of this year, which means that the extension warnings are likely to appear in Firefox 39.