Showing posts with label Mozilla Thunderbird. Show all posts
Showing posts with label Mozilla Thunderbird. Show all posts

Thursday, 5 November 2015

Privacy Tails OS With Offline Mode For Sensitive Documents


There is a new version of the operating system focused on privacy Tails appeared, now an offline mode features. In this case, all network properties can be switched off. According to the developers, this is useful if it sensitive documents is underway.

Icedove further added, a modified version of the Mozilla Thunderbird email client. Icedove is at this stage a "technology preview", but according to the developers safe enough to be used in the context of Tails. In addition, in Tails 1.7 also numerous small bugs and fixes and the operating system would have to be something more compatible with hardware.

Tails is a complete operating system that can be used from a DVD or USB stick. Despite all the attention to the privacy Tails developers early this year showed that only 10 000 people daily in the privacy OS use.

Thursday, 6 August 2015

Developer: Mozilla Threaten Windows Users


Since the launch of Thunderbird 38 Mozilla e-mail client of the Lightning extension provided, but how the extension is implemented is a security risk for Windows users. The German software developer Stefan Kanthak even calls it a "security nightmare".

Lightning provides Thunderbird with an agenda. The extension is enabled by default, although users can turn off or Lightning.Mozilla install the extension in the profile of users and not in the Program Files directory. Mozilla thus violating the mandatory development guidelines for Windows, according Kanthak. It also introduces a security risk.

Applications in the Program Files directory can only be changed by users with appropriate privileges. That does not apply to files in the AppData directory. It is in this directory where the Thunderbird profile of users is stored and the Lightning extension is located. "This is a fundamental vulnerability in Mozilla's extensions and a security nightmare," writes Kanthak the Buggtraq mailing list .

According to the developer, users perform for safety reasons no code in their user profile. That does not apply to Lightning, which is being carried out from here. An attacker with access to the system can therefore replace the DLL files and JavaScript of the extension. Kanthak Mozilla advises to turn off local installation of extensions in Mozilla products and only global installations to allow extensions.