Ads by TechWords

See your link here
Receive the latest technology news and information.
Networking
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

New Firefox 3.0 alpha blocks malware, secures plug-in updates

Security features debut in latest preview, as Firefox 3.0 heads down the stretch

September 21, 2007 12:00 PM ET

Computerworld - Mozilla Corp. updated the preview of Firefox 3.0 to alpha 8 late yesterday, unveiling for the first time to users several security features it's talked up for months.

Among the security provisions debuting in the new alpha of "Gran Paradiso," the code name for Firefox 3.0, are built-in anti-malware warnings and protection against rogue extension updates, according to documentation Mozilla posted to its Web site.

The malware blocker, which was first mocked up in June, will block Web sites thought to contain malicious downloads. The feature, a companion to the phishing site alert system in the current Firefox 2.0, will use information provided by Google Inc. to flag potentially-dangerous sites, warn anyone trying to reach those URLs with Firefox and automatically block access to the site.

Mozilla also pointed to a URL that demonstrates the new malware blocker for alpha 8 users.

Also taking a bow is a check meant to prevent plug-ins' automatic updates from sending users to malicious sites where they might be infected by attack code or drive-by downloads.

Firefox relies on small plug-ins -- called "extensions" in the Mozilla vernacular -- for much of its power and flexibility. Several thousand extensions have been written, the vast bulk of them by outside developers, that do everything from boost browsing speed to block irritating Flash animations. Firefox regularly checks to see if the installed extensions are up to date, and if not, automatically pulls in the newest version and installs it.

"Firefox automatically checks for updates to add-ons using a URL specified in the add-on's install manifest," Mozilla spells out in a developer's document. "Currently there are no requirements placed on these URLs. In particular, [they are not] required to be https. This allows either the update manifest or the update package to be compromised, potentially resulting in the injection of malicious updates. A demonstration of one form of compromise is already public."

Most extensions are hosted on Mozilla's own servers -- at the servers feeding its Add-ons site -- but some are not; it's those off-site extensions that Mozilla wants to lock down.

To stymie attacks through a compromised extension update, Mozilla will require updates -- both the actual update package and the much smaller "manifest," or notification of an update -- to be delivered over an SSL-secured connection. Or the update must be digitally signed.

The change doesn't affect the initial installation of an extension, something Mozilla recognized. "[This] has no impact on the security of initial add-on installs," it told developers in the online guide.

This newest preview, which can be downloaded in versions for Windows, Mac OS X and Linux from the Mozilla site, still comes with a warning to end users. "Alpha 8 is intended for Web application developers and our testing community. Current users of Mozilla Firefox should not use Gran Paradiso Alpha 8," the browser's release notes.

Mozilla has not officially committed to a release date for the final version of Firefox 3.0.



Jump to comments

Firefox

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

What People Are Saying

White Papers & Webcasts

The 2009 Handbook of Application Delivery
Learn how to become better with application delivery.  

Aligning IT to Business: The Rising Importance of Application Delivery Networks
Application Delivery Networking (ADN) will play a vital role in helping enterprises incorporate strategic technologies to achieve business initiatives.

Unified Application Delivery
By providing a unified Application Delivery Networking platform, F5 BIG-IP offers the ability for organizations to adopt a single platform for all its...  

Preparing Your Business Services for the Future
Would you trust your network monitoring tools enough to know when something is truly halting a business service?

ROI of Application Delivery Controllers
How modern offload technologies in Application Delivery Controllers can drastically reduce expenses in traditional and virtualized architectures, with a fast ROI.  

BMC Application Performance and Analytics: Predictive Intelligence in Action
See the highlights of BMC's Application Performance and Analytics today!

Gartner: Magic Quadrant for Application Delivery Controllers, 2009
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing...  

IPAM: Slashing Network Costs
Slashing Network Costs by Consolidating and Automating Core Network Services

Gartner: Load Balancers are Dead
This research shifts the attention from basic load-balancing features to application delivery features to aid in the deployment and delivery of applications.