Showing posts with label Mozilla Firefox. Show all posts
Showing posts with label Mozilla Firefox. Show all posts

Thursday, 15 March 2018

Mozilla Is Considering Blocking In-Page Pop-Ups In Firefox



Mozilla is collecting a dataset of in-page pop-ups in order to automatically block them in Firefox. In-page pop-ups are pop-ups that show pages at different times, such as when loading the website, scrolling, inactivity or opening a tab.

Experiments are now being done with a pop-up blocker to close these pop-ups automatically. For this Mozilla is working on a collection of such pop-ups. Internet users can report this via this page . The dataset is only needed to train the pop-up blocker. The plan is to be able to block them automatically without having a complete blocklist. Whether the feature also comes is still unclear. Firefox developer Ehsan Akhgari says on Twitter that Mozilla is exploring it as a possible Firefox feature.

Wednesday, 14 March 2018

Mozilla: Many Popular Websites With Symantec Certificates




There are still many popular websites with Symantec certificates that will soon no longer be trusted by Firefox and will cause an error message, as Mozilla has warned. It is about 1 percent of the Top 1 million most popular websites on the internet, which amounts to about 10,000 sites.

These websites use a tls certificate issued by Symantec to encrypt traffic to and from their visitors. Due to various incidents with tls certificates issued by Symantec, browser developers have decided to cancel the trust in Symantec certificates. This will take place in phases, with all Symantec certificates issued before 1 July 2016 no longer being trusted.

Google will implement this measure next month with the launch of Chrome 66. Mozilla will follow Firefox 9 on May 9. With the launch of Firefox 63 in October this year, trust in all Symantec certificates will be canceled regardless of issue date. Users who receive a certificate warning when visiting a website can ignore them and still reach the website, Mozilla explains, but security experts advise internet users never to ignore such warnings and not to visit the website in question.

Thursday, 5 May 2016

Anti-virus Again Caused Problems For Firefox Users



Mozilla has released an update to Firefox because anti-virus software again caused problems. Last week Firefox 46 , where several security issues were resolved. Shortly after the release of this version Firefox users complained that they did not have websites could charge more.

Users got to see only blank pages. Then Mozilla decided to discontinue the update to Firefox 46. An investigation was opened, from which it appeared that anti-virus software was the culprit. The problems resulted from the scanning of a certain directory. It is not the first time that Firefox crash and virus scanners. Early this year, Firefox proved to crash through the anti-virus software from G Data virus and made ​​sure that some users no SSL sites to visit. Updating to Firefox 46.0.1 will occur automatically on most systems.

Friday, 6 November 2015

Extra Secure Tor Browser For Linux Launched



The creators of Tor Browser, the software for browsing through the Tor network, have released a security-enhanced version of Linux. It is the first time that the Tor Project offers a "hardened" version of Tor Browser. This browser includes a customized version of Firefox and Tor software.

The extra secure Tor Browser is based on the Tor Browser Alpha series. These are test versions of the browser that appear in the final versions. In addition, extra protection is added which should offer protection against memory exploits. For this are both the Tor software, and Firefox version Address Sanitizer compiled. This should give users a safer Tor Browser, especially if JavaScript is partially or completely disabled. It also helps to find problems earlier and to remedy them in the alpha and stable versions.

The additional security does have several disadvantages. Thus, this version is slower, consumes more memory and is slightly larger than the normal version. In addition, the added security of Address Sanitizer not perfect. An attacker who successfully back halls which it is practiced can still via JavaScript certain types of attack vulnerabilities. To date, the high-security Tor Browser only for Linux available, but is being given to versions for Mac OS X and Windows.

Tor Browser lets Internet users hide their IP address and visit censored websites. Every day, over two million people from all over the world using the Tor network, such as activists, people in totalitarian regimes and Internet users who value their privacy. The software is also used by criminals. Two years ago, users of legacy Tor Browser still the target of an attack allegedly by the FBI conducted. The attack users of the real IP address could be traced. To avoid Tor Browser Users with outdated versions meanwhile continue surfing is an automatic updater added to the browser.

Thursday, 5 November 2015

Firefox 42 Display Changes Some SSL Certificates


In the latest version of Firefox, Mozilla has decided to offer some SSL certificates for different weather and the warning for HTTPS sites that have content via HTTP. In total, the four visual customization that users via the address should inform the HTTPS status.

The first concerns the so-called "domain-validated 'certificates. When domain-validated (DV) certificate, only the control checks on a particular domain. Firefox gave this SSL certificates previously via a gray lock icon in the address bar. Now this lock icon turned green. In addition, Firefox used for websites with mixed content two icons. In the case of mixed content display HTTPS websites also content over HTTP, which is a security risk. Firefox 42 now uses one icon that warns of mixed content. In addition, there are three different states for the display of mixed content.

Vulnerabilities

Yesterday reported all about the new Firefox version and reported that no vulnerabilities were fixed in the browser. At the time of writing, the Mozilla Security Advisories for Firefox are not updated and also made ​​no mention of the security fixes. Which are now published online. It appears that Firefox 42 in total 23 vulnerability fixes, including eight critical holes. Through this critical vulnerabilities an attacker can install malware on computers where only visiting a hacked or malicious website is enough. The latest version is basically updated automatically.

Wednesday, 4 November 2015

MacUpdate.com Provides Downloads Of Adware


A download site where Mac users can download software shows offered all kinds of apps like Skype, Firefox and 1Password to provide adware. The adware is in an installer. It is includes a "wrapper" that other apps in addition to the required software.

Users can be allowed to see the user agreement, but will ignore most users, says Thomas Reed of anti-malware company Malwarebytes. If it is for the "Quick" system chosen by the user in addition to the software you also get a browser extension and the browser settings are adjusted. According to Reed let many adware installers today see this behavior.

MacUpdate also the wrapper would install a program called MacBooster. Reed says that other download sites such as Download.com and Softonic exhibit this kind of behavior and Mac experts therefore advise you to avoid these types of websites. Mac users are therefore advised only apps from the Mac App Store, or the official website to download from the supplier, and to avoid external download sites.

Mozilla Launches Firefox With Built AdBlocker


Mozilla today released a new version of Firefox was launched which features a built AdBlocker, so as to better protect user privacy. According to Mozilla must Tracking Protection, as the new feature is called, give users more control and choice while browsing the Web.

Users can now determine which data third parties receive them. "The Private Browsing mode on Chrome, Safari, Microsoft Internet Explorer or Edge does not provide the protection that Firefox offers," said Mozilla's Nick Nguyen. Private Browsing with Tracking Protection will namely active ads, analytics trackers and buttons for sharing content on social media block.

Since some sites do not work properly if certain trackers are blocked, it is possible to simply Tracking Protection for a particular website off. There is also a new control center to the browser added that collects all security and privacy settings in one place. Firefox 42 also does not contain security updates. Updating via the browser, Mozilla.org.

Sunday, 1 November 2015

IBM: Businesses Need Flash Apps Replaced By HTML5


Companies that offer Flash applications are wise to that HTML5 to convert, since the call for an internet browser without plug-ins is getting stronger, says David Strom IBM. Strom pointing to newer versions of Chrome and Firefox that no longer support the old NPAPI plug-sustaining nature. The main reasons for this are security and performance issues.

Recently, Mozilla announced that it is supporting the Java browser plug-in will cease altogether. However, there is a plug-in that is still supported, and that's Adobe Flash Player. Increasingly parties, however, are calling for an alternative, so that Internet users do not need more plug-ins to view online content or use. So pleaded Facebook CSO Alex Stamos before the end of the Flash technology.

According to Strom, this is not a new trend, since the appearance of the first Apple iPad without Flash support organizations have attempted to create websites with HTML5, the intended successor of Flash. This year, however, HTML5 can make its breakthrough, according to security evangelist at IBM. He argues that the time has come for organizations and companies for their Flash based apps to HTML5 to convert.

Saturday, 24 October 2015

Firefox Will Warn Login Via HTTP


Mozilla Firefox 44 will warn users when they attempt to log in to a website that sends the password over HTTP. In this case, the open source browser will display a warning stating that the connection is not secure and the credentials can be stolen.

That Richard Barnes from Mozilla via Twitter announced. The measure is now in an early version of Firefox 44 for testing. In case a website login via HTTP sends the browser's address bar will show a red line through a lock. The warning also appears in login forms that are offered via HTTP, but send the completed data over HTTPS. According to Barnes, an attacker can steal in such a case via JavaScript password before the user clicks login. The final version of Firefox 44 is scheduled for January 26, 2016.

Friday, 23 October 2015

First British Newspaper Will Block Adblock Users


City AM is the first British newspaper who has decided to block users from a AdBlocker. According to the paper's journalists paid through advertising and now runs this risk by using adblockers, so ads no longer appear.

The blockade occurs when visitors want to read with a AdBlocker full articles. This not only concerns specific adblockers like AdBlock Plus, but also programs like Ghostery, Disconnect and Do Not Track Me that protect users from tracking on the web. In addition, the blockade is aimed only at Firefox users who use such software.

Opposite the Guardian explains director Martin Ashplant which uses about 8% of the 1.2 million visitors and that Firefox has installed 20% of this group adblockers. It is primarily a test, with other browsers and for example, tablets, and smartphones are excluded. "We want to see what the impact is and how many people choose to disable the adblockers" said Ashplant. Recently decided to Germany's Bild adblock users block.

Thursday, 22 October 2015

Google Gives More Details About Dangerous Blocked Sites


Every day protects via Google's Safe Browsing technology 1.1 billion people from dangerous Web sites, for example, want to install malware. Through Safe Browsing be users of both Google Chrome and Firefox and Safari warned of malware and phishing sites.

According to Google, the user is not always clear why a website is blocked. Therefore, the Internet giant has now added a special feature to the online Transparency Report which additional details can be retrieved. Through "Site Status" users can see exactly why a site is blocked by Google, such as website visitors to a malicious website which sends attempts to install malware or that forwarding dangerous websites visitors to the website visited.

Monday, 19 October 2015

Microsoft Promotes Edge In Windows 10 To Adjust Browser


Windows 10 users that in the future the default browser will be able to customize Microsoft's request to Edge and try not to move. Even when adjusting the default music and photo app praises Microsoft's own apps.

According to a new Preview Build of Windows 10. WinBeta discovered the changes in the test version of the operating system. This is still an adjustment in a Preview Build of Windows 10, but Microsoft often conducts these adjustments in the final version of the OS.

For the launch of Windows 10 had notably Mozilla criticized the policies of the software giant. When upgrading from Windows 7 or 8.1, the browser is set previously been replaced by Microsoft Edge, which is the default browser in Windows 10. Figures show that many users after the upgrade, change the default browser, making Chrome become by far the most popular browser for Windows 10 users.

Friday, 16 October 2015

South Korea Seems To Wrest IE And ActiveX


By a legal obligation from the end of the last century, most South Koreans still use Internet Explorer, but the country seems slowly to Microsoft's browser and ActiveX technology to emerge. This week launched the Korea Trade Network (KTN), part of the Korea International Trade Organization, new authentication services in addition to IE also work in other browsers.

The KTN late announcement specifically that the new services are free and ActiveX standard Microsoft Edge, Chrome and Firefox work. ActiveX is an extension dating from 1996 model, making it possible to add extensions to Internet Explorer.Decided because of all kinds of stability and security vulnerabilities in Microsoft ActiveX Edge no longer support.

In South Korea ActiveX still plays an important role. To encourage online shopping and Internet banking and fears about insecurity to take away the Internet, the South Korean government developed its own system to authenticate the identity of online buyers. To order online buyers had their name and Social Security number to apply for a digital certificate from the government. This certificate could show people as a kind of identity card to the retailer. The whole process was designed so that it occupied just a few clicks.

The technology for these online identity was based on Microsoft's ActiveX technology, which works only in Internet Explorer. When the system was introduced in 1999, the South Korean government stated that it was mandatory for online purchases above 210 euros. For smaller purchases by South Korean retailers, however, applies a similar certification system developed by webshops and credit card companies. However, the law does not apply to foreign retailers.

Many South Koreans also use IE. In recent years, received the browser, as ActiveX, having to make many security problems. Nevertheless, the browser according to StatCounter in South Korea still has a market share of 67.8%. The announcement of the KTN is also noteworthy. In August it was announced that the Korean financial authorities want the authentication certificates within two to three years phasing.

Friday, 25 September 2015

Mozilla: Industry Must Understand Adblock Users Better


In recent weeks on the internet between the supporters and opponents of adblockers a fierce debate erupted, but according to Mozilla, it is important that the industry understands why users use such resources on the web.

The answer here is not entirely clear, according to Mozilla's DENELLE Dixon Thayer. The reasons vary by user and device used. Desktop Users would be more focused on their privacy, and performance, while mobile users want to reduce power and data usage. "As an industry, we need to better understand the wishes of users," said Dixon Thayer. The wishes of users and commercial interests are not mutually exclusive. Rather they are both necessary for a healthy web, according to the Chief Legal Officer of Mozilla.

In addition, especially the collection of usage data plays an important role. According to Dixon-Thayer the collection of data is not inherently detrimental. It can also provide all kinds of benefits. However, it is important that users know this and keep control of the data collected. Otherwise, the confidence in the entire system can be lost, which is also at the expense of the proper parties.

Tracking Protection

Mozilla now wants to determine the cause of the problem which has arisen not only by research but also by developing features and products that provide a better balance and increase confidence in the web. In order to find this balance is also required to the input from users. Therefore, users are asked in the latest beta version of Firefox Private Browsing with Tracking Protection test. Through this feature, users have more control over the data collection.

"As an industry, we need to see which places the user in the product vision instead of the user as a goal to be achieved. It is the only way to respect user choices and the best, most trusted and valuable experience offer, "concludes Dixon Thayer.

Friday, 18 September 2015

Serious Vulnerability In Bugzilla Discovered And Patched


In the Bugzilla system leading software projects like Mozilla, Linux Kernel, Apache Project, Red Hat and Open Office for tracking bugs and vulnerabilities use has discovered a serious vulnerability patched. Using the vulnerability, an attacker could log on to the system and, for instance sensitive bugs and problems see that have not been patched.

It was recently announced it had received an attacker access to the Bugzilla system, Mozilla and so got hold of information on a Firefox vulnerability for which no security was available. This information, the attacker then used to Firefox users to attack. A common method within Bugzilla to provide user access is based on e-mail.

If a user has an email address of a particular organization has he will be considered as a trusted user. In the case of Mozilla involves users who for example an email address @ mozilla.com disposal. The now discovered vulnerability allows an attacker for any domain will create a Bugzilla account, even if they have no access to the e-mail account or domain.

The attacker can then use the created account to log in and depending on the rights given to users of a particular domain are set up access still can not fix bugs and other information. The vulnerability was reported on Monday, September 7th at Mozilla, which is responsible for the development of Bugzilla. On Thursday, September 10th, there appeared an update.

Take offline

Companies Bugzilla in combination with e-mail-based use rights and this update have not yet installed are advised to get the system right offline until the patch is deployed. Also, the logs and user-created lists should be reviewed to see if any users have been created via the vulnerability, so advises PerimeterX, the company that discovered the vulnerability.

Thursday, 17 September 2015

Mozilla Extends Deadline For Autographed Firefox Add-ons



Developers of add-ons for Firefox more time to meet the new demands of Mozilla. For harmful Firefox add-ons to address had demanded that all Mozilla Add-ons from Firefox would be 42 signed.Unsigned extensions will not work in Firefox.

All add-ons that are available on the Mozilla website, addons.mozilla.org (AMO), will be automatically signed and verified.Extensions which are offered through other channels must first be checked by AMO and signed. Add-ons that can not request a manual check by the automatic control haven. Mozilla late now that the deadline of Firefox 42 has shifted to Firefox 43. This version is scheduled for December 15th.

According to Lisa Brewster Mozilla had many developers indicated that they did not have sufficient time to meet the new requirements. Originally had the signings of add-ons for September 22 have been processed, if the beta version of Firefox 42 will appear. In addition to the extra time to get Mozilla developers will also make it clearer as an add-on for control is offered where exactly to meet.

Monday, 14 September 2015

Firefox Displays Ads When Opening New Tab


Mozilla has started displaying ads to Firefox users as they open a new tab in the browser, so the browser developer via a blog posting disclosed. The ads appear in the form of "Suggested tiles".These are ads that are based on the user's browsing habits. This would be taken into account with the users of privacy.

To make the ads relevant is a limited amount of data sent to Mozilla there. Since then it is analyzed and shared with the partners of Mozilla. According to the developer, the browser via Suggested Tiles possible to display relevant ads that users' privacy is respected and he or she is in control of the data.

The first partners who advertise via Suggested Tiles is now gone live, said Darren Herman, Vice President of Content Services at Mozilla. It involves Yahoo and several new titles including well-known Fortune Magazine and quartz, as well as "mission-oriented" partners such as Make-a-Wish Foundation and the Electronic Frontier Foundation. According to Herman, these parties are chosen because they add value to Firefox.

Mozilla is not paid for displaying the advertisements of those parties. Therefore, the advertisements are only labeled "Suggested" instead of "Sponsored". According to Herman should improve the tiles eventually advertise digitally, both increase by transparency in the industry and to ensure that users understand what is happening and how they control this themselves. So Firefox users via a single click of tiles showing off in a new tab.

Sunday, 6 September 2015

Firefox Users Attacked Using Information From Bugzilla


An attacker has certainly been a year of access to the bug system Mozilla and information about at least one unpatched vulnerability in Firefox used to attack users of the open source browser. That Mozilla via a blog posting yesterday disclosed.

Via Bugzilla registers Mozilla bugs and security vulnerabilities in various software projects, such as Firefox and the email client Thunderbird. Access is restricted to certain users. A user who had access to sensitive security information, the password for Bugzilla had also used on another website. This unnamed website was hacked, making the password into hands of the assailant came so access to the Bugzilla account users able to get.

As far as is known, the attacker had this way since September 2014 access to Bugzilla, but there is some evidence to suggest that the attacker since September 2013 on the account logging in. In this time, pushed the attacker information about 185 non-public bugs in Firefox. It is about 110 non-security related bugs, security issues and 53 minor 22 vulnerabilities as "high" or "critical" were labeled. Of these 53 vulnerabilities were patched 43 when she discovered the attacker. Mozilla allows the attacker the information on these 43 vulnerabilities probably can not use it to attack Firefox users.

Zero-Day Flaw

As regards the other 10 vulnerabilities, three of them were respectively 131, 157 and 335 days at the attacker known before appeared a patch. The other seven vulnerabilities were announced less than 36 days. "We think they used this information to attack Firefox users," said Richard Barnes of Mozilla. It is also about zero-day vulnerability patched Mozilla on August 6 and was used sensitive files to steal Firefox users. To the knowledge of Mozilla is not using information about the other nine vulnerabilities. On August 27 there appeared a new Firefox version in which all vulnerabilities were patched where the attacker had access.

Mozilla has decided because of the incident screwing the security of Bugzilla. All users who have access to sensitive security information have the password has been reset and the use of two-factor authentication obligatory. In addition, the number of users with special access restricted and what those users can do. This should make it more difficult for an attacker to gain access to an account and limit the amount of information that can be stolen at a successful attack.

Tuesday, 18 August 2015

Fuss About Speculative Connections Firefox


On the Internet fuss arose over a feature in Firefox for ensuring that websites load faster, but can also help to track users. Several years ago, Mozilla has developed an API (application programming interface) to "speculative connections" allows to load websites faster than expected is that the user will also open a link.

Only moving the mouse over a link ensures that a request is sent to the web server of the website. Recently, a user sketched out a scenario whereby can consider whether certain email addresses are in use. Suffice it to any e-mail address to send an e-mail with a link to a unique IPv6 address. Once the user receives the message and moves his mouse over the link or the mouse in the area with link state, Firefox will send the request and may be checked to see if the email address is still in use.

Users can take steps to disable the feature, so Mozilla late this article know. For this, users in the address bar about: config entries. Then there must be sought on network.http.speculative-parallel-limit and must be the value to 0.

Thursday, 13 August 2015

Tor Browser Enhances Privacy And YouTube Support


For Internet users who want to protect their anonymity and privacy on the web is a completely new version of Tor Browser appeared. It is the first version of Tor Browser 5.0 . Besides several vulnerabilities that are fixed This version contains several measures to protect user privacy.

For example, there are added protective measures to prevent identification on the basis of key strokes. The NoScript whitelist is reset. NoScript is a Firefox extension that prevents the execution of scripts on websites. NoScript uses a whitelist of domains where scripting is allowed. The reason for the reset is that NoScript previous updates certain areas were added to the whitelist. To avoid repetition NoScript will not be able to update the whitelist. Further supporting the playback of HTML5 video on YouTube improved.

Zero day

Tor Browser is based on Firefox. Recently, a zero-day flaw was used in the PDF reader Firefox to attack users. According to the Tor Project, the developer of Tor Browser, the problem was not present in version 4.5 of Tor Browser. Users of the trial version of Tor Browser 5.0 were vulnerable. However, the attack could not be carried out if the security slider Tor Browser stood tall. The browser has recently acquired a slider that allows users to specify the security level. Updating to the new versions of Tor Browser via the browser or Torproject.org . Globally, 2.5 million people use the Tor network.