Mozilla: No 'kill switch' for Firesheep add-on
It won't -- or can't -- yank session hijacking add-on from Firefox
Computerworld - Mozilla today said it wouldn't -- or couldn't -- pull a "kill switch" to disable the Firesheep add-on that lets anyone steal log-on and account access information to Facebook, Twitter and other major Web services.
Firesheep adds a sidebar to Mozilla's Firefox browser that shows when anyone on an open network -- a coffee shop's Wi-Fi network, for instance -- visits any insecure site on a list that includes the microblogging service Twitter and the hugely-popular Facebook social networking site.
Mozilla has a "blocklist" mechanism that it can, and has in the past, applied as a last-resort defense against potentially-dangerous browser add-ons. The blocklist automatically cripples or uninstalls unwanted extensions that have been added to Firefox.
But Mozilla either can't or won't add Firesheep to the blocklist.
"[Firesheep] demonstrates a security weakness in a number of popular websites, but does not exploit any vulnerability in Firefox or other Web browsers," said Mike Beltzner, director of Firefox, in an e-mail reply to questions about Mozilla's possible moves.
Beltzner did not respond to questions about whether Mozilla is technically able to cripple Firesheep, or simply chooses not to.
As Beltzner pointed out, Firesheep is not an officially-approved Firefox add-on, but was "created and distributed by a third-party developer."
Most Firefox add-ons are obtained by users from the browser's Add-On center, which hosts Mozilla-vetted extensions.
In earlier instances when Mozilla has dealt the blocklist "kill switch" card, it's done so for add-ons that the company had previously approved, but later discovered were stealing information or distributing malware. In July, for example, it yanked a password-stealing extension that had been available from Firefox's gallery for more than a month before its malfeasance was detected.
The add-on, called "Mozilla Sniffer," contained code that intercepted login data submitted to any site, then sent that information to a remote server. Firesheep does some of the same, but it doesn't show what it finds to anyone but the tool's user.
In May 2008, Mozilla acknowledged that a worm had gone unnoticed in Firefox's Vietnamese language add-on for months, and last February it warned users that the Sothink Web Video Downloader 4.0 and all versions of Master Filer were infected with a Trojan horse.
As with Mozilla Sniffer, those add-ons had also been offered in the Firefox add-on center.
Firesheep has proved very popular. Since its Sunday debut, the add-on has been downloaded nearly 320,000 times, or an average of about 79,000 downloads per day. That puts it within striking distance of the Firefox's most popular add-on, Adblock Plus, which has averaged just over 80,000 downloads daily during its lifespan.
Using Firesheep may be a criminal offense under U.S. law, suggested Chet Wisniewski, a senior security adviser at antivirus vendor Sophos. "[Firesheep] isn't illegal, but using this tool is a crime in the U.S.," he said. "It would be considered wiretapping. You can play with it on your own network, use it for research, but not to invade the privacy of others."
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Inquiry Spotlight: Consumer-Facing Identity The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety.
- IDC Security Infographic From the Era Before security to this current era of empowerment this infographic from Blue coat provides a timeline navigates the rise of...
- Key Drivers: Why CIOs Believe Empowered Users Set the Agenda for Enterprise Security Several years ago, a transformation in IT began to take place; a transformation from an IT-centric view of technology to a business-centric view...
- Security Empowers Business Every magazine article, presentation or blog about the topic seems to start the same way: trying to scare the living daylights out of...
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts