Live data from Hacker News

Firefox exploit found in the wild

blog.mozilla.org

121–130 of 277 posts

Re: Firefox exploit found in the wild

#121

Earlier quoted context omitted.

If large amounts of code written in memory unsafe languages is such a concern then Mozilla should immediately stop adding large numbers of highly complex new features implemented in unsafe code to Firefox every year, mostly to do things that have absolutely nothing to do with displaying web pages but are enabled by default for political reasons. Just like switching to PDF.js was a decision taken to try and reduce the…

> (a) If large amounts of code written in memory unsafe languages is such a concern then Mozilla should immediately stop adding large numbers of highly complex new features implemented in unsafe code to Firefox every year, > (b) ... mostly to do things that have absolutely nothing to do with displaying web pages but are enabled by default for political reasons. (a) Mozilla is working on adding/replacing parts of Fire…

>Mozilla is working on adding/replacing parts of Firefox with a language emphasizing security (among other things).

The safety of the implementation language is far from the only concern when considering the security impact of modern browser features. The recent WebRTC issues are well documented, as was the HSTS 'supercookies' issue. Even something seemingly fairly innocuous like css keyframe animation can be used to do remote timing attacks without js to leak browser state such as browsing history[1]. SVG filters in Firefox allowed information to be read from arbitrary pages through timing attacks, till they removed some of the optimisations[2]. Those kinds of things are not solvable with a safer language (in some cases that probably makes fixing timing attacks more difficult/impossible). I'm sure there are more of these kinds of things to be found. Some of them are realistically never going to be fixed now because they are baked into the standards and the browser vendors clearly care more about animating gizmos and not breaking existing sites than leaking users browser state.

[1] https://www.nds.rub.de/media/nds/veroeffentlichungen/2014/07...

[2] http://www.contextis.com/documents/2/Browser_Timing_Attacks.... and https://www.mozilla.org/en-US/security/advisories/mfsa2013-5... Read the bug to see how difficult it was for the devs to fix the issues without making the feature unusable - it took years

>I'd have added "You can install links if you want a simple browser letting you read static html documents", which you would have answered with "But I can't, every website require these features now", to which I'd have answered "a. Yeah, not everyone (that's an understatement) does progressive enhancement, but ultimately b. The times they are a-changing"

I'm not concerned about myself. I disable stuff like WebGL that I don't use, and I block most Javascript etc etc. My concern is for the average user who has absolutely no idea these features even exist, never mind knowing which ones they can turn off without breaking the sites they use. The general insecurity of the web affects me (and everybody else). When a site gets hacked because one of the admins was exploited by a browser vulnerability and my details get leaked that affects me.

Re: Firefox exploit found in the wild

#122

Once again, this demonstrates that blocking advertisements is a really good idea from an InfoSec perspective. Ad blocking not only abates a nuisance, it's an important security measure. cf https://twitter.com/swiftonsecurity/status/62840155490772582...

By that logic it's more like an argument for disabling JS entirely - there is nothing about this that's specific to ads, and the reporter has speculated that it was placed by an attacker and only disguised as an ad.

Not executing any JS is safer, sure, but that's beside the point. If you strive for absolute security, power off your computer and never touch it again. This is about what you can do to improve the situation without impairing usability.

An adblocker doesn't impact usability (in most cases, it improves it significantly, through lower page load times and less space occupied by non-content), but prevents the vast majority of malvertising. Blocking all Javascript blocks all of them, but makes the modern web nearly unusable.

Re: Firefox exploit found in the wild

#123
post #70

Earlier quoted context omitted.

I disagree that this is innovation. What innovation and what benefits do I reap by using pdf.js? It's slower and has less features than okular. It's stuck inside a firefox window, so I cannot add a window rule for it (barring adding one for firefox in general). The same holds on windows: why would I use pdf.js when there are faster, lighter pdf readers (e.g. sumatra) or the actual adobe acrobat reader and its eight b…

I have mupdf in firefox (iceweasel) using mozplugger. I could always set it up to not display pdfs, only downlad them, use mupdf through mozplugger or use the builtin pdf.js viewer. Having said that I'm not sure that mupdf is safer than pdf.js, but it's much faster.

I was debating the merit of having the pdf reader bundled and on by default, instead of having the pdf file downloaded like most other files. One can certainly change firefox's behaviour in the settings (unlike webgl).

Re: Firefox exploit found in the wild

#124
post #9

Why is anyone still using this browser anyway? Firefox is the new IE6.

Because it is the only browser that is not tied hand-and-foot to some major global commercial player, and because each and every browser ever launched had security issues. Even lynx is not immune: http://www.cvedetails.com/vulnerability-list/vendor_id-5836/...

> Because it is the only browser that is not tied hand-and-foot to some major global commercial player

Not close to true. There are hundreds of browsers out there. I used Surf[0] and Xombrero[1] for a number of years.

[0] http://surf.suckless.org

[1] https://opensource.conformal.com/wiki/xombrero

Re: Firefox exploit found in the wild

#125

Out of curiosity, how many users will be opening pdf using pdf.js? Is it widely used? I was never comfortable with pdf.js and changed the setting to use the default pdf viewer in all my machines.

For users that are opted in telemetry reporting, it can go up to 40M PDF views per browser version [1]

  [1] http://telemetry.mozilla.org/dist.html#!cumulative=0&end_date=2015-06-05&max_channel_version=beta%252F38&measure=PDF_VIEWER_USED&min_channel_version=nightly%252F38&product=Firefox&sanitize=1&start_date=2015-03-04&trim=1&use_submission_date=0

Re: Firefox exploit found in the wild

#127

Earlier quoted context omitted.

> (a) If large amounts of code written in memory unsafe languages is such a concern then Mozilla should immediately stop adding large numbers of highly complex new features implemented in unsafe code to Firefox every year, > (b) ... mostly to do things that have absolutely nothing to do with displaying web pages but are enabled by default for political reasons. (a) Mozilla is working on adding/replacing parts of Fire…

It doesn't help your position the fact that you are unable to express it without belittling anybody who disagrees with you using stuff like "stay stuck in 1992" ("If you don't like America you should go to Russia!"). Also, the links/lynx jokes have really gotten tired, plenty of people browse the web with ublock, no(t)script, webgl and webrtc disabled and so on. The pretense that anybody who tries to retain a modicum…

> It doesn't help your position the fact that you are unable to express it without belittling anybody who disagrees with you using stuff like "stay stuck in 1992" ("If you don't like America you should go to Russia!").

True, that was useless, could have just said "I and many users do want these features" . Thanks, and sorry anon.

> the links/lynx jokes have really gotten tired, plenty of people browse the web with ublock, no(t)script, webgl and webrtc disabled and so on. The pretense that anybody who tries to retain a modicum of control on what its browser does and does not it a luddist is frankly irritating.

That wasn't a links joke, I could have phrased it with your own words "You can install ublock, no(t)script, and disable webgl/webrtc if you want a simple browser letting you read static html documents" , and "But I can't, every website require these features now" would still be an answer.

My conclusion isn't that "anyone trying to retain a modicum of control on what its browser does and does not is a luddist" --and I do use some of these extensions too--, it's that the barebones web experience anon wants is broken now (and probably forever), due to:

a. Sadly, non-respect of progressive enhancement in cases where it's possible (documents).

b. The fact that _some_ parts of the web are increasingly not documents, but whole apps whose progressive-enhancement baseline (running without all the bells and whistles) would do nothing because they depend on these features.

> And the whole language debate is completely off point, we have plenty of safe(r) languages for writing stuff, the misguided idea is that the only way to do so is to use javascript and stick the resulting program inside the browser.

Yes. Development practices, testing, fuzzing, and safe(r) languages, like Rust.

Re: Firefox exploit found in the wild

#128

I'll just chuck this old blog post of mine out there: https://grepular.com/Protecting_a_Laptop_from_Simple_and_Sop... Specifically, the "Securing the Web browser" section. [edit] Also worth mentioning is the stuff about smartcards on that blog post. You can steal my ~/.ssh/ and my ~/.gnupg/, but because I'm using a smartcard, it wont do you any good.

That's a great post. Very thorough. However, a couple of observations concerning some security issues you might not be aware of:

First, X itself is very insecure, so by allowing your web browser to share the same X server as the rest of your apps, you are making the rest of your apps more vulnerable.

Second, the so-called "Trusted" Platform Module you're using for extra entropy may itself not be very trustable, despite the name. So you may want to rethink that.

Finally, according to the vendor of the GPG smartcard you're using, "the software on this card is not available as free software due to NDAs required for certain parts."

That there are NDAs on parts of the card or the software (it's not clear which) makes the card suspect, and I don't see where I can get the source of the code (free or not) that's running on the card. An ideal smart card would, like gpg itself, have completely open and transparent hardware and software. I'm not sure if any of those kinds of cards exist, however.

That said, I'm sure all the security measures you're taking in sum make you far better off than the typical computer user, but there's room for improvement.

Re: Firefox exploit found in the wild

#129
post #52

How many PDF.js security vulnerabilities have been found so far? A quick Google search found only four: https://www.mozilla.org/en-US/security/advisories/mfsa2013-9... (another local file disclosure) https://www.mozilla.org/en-US/security/advisories/mfsa2015-3... (needs to be "combined with a separate vulnerability" to be exploitable) https://www.mozilla.org/en-US/security/advisories/mfsa2015-6... (needs to be "combi…

>It still is looking better than the plugin it replaced.

Exploiting a bug in a memory unsafe language is much harder than writing some JavaScript. It is also much less reliable and platform specific.

The real question is why the hell is Firefox not sandboxed?

Re: Firefox exploit found in the wild

#130

Earlier quoted context omitted.

> except maybe Safari? I don't own a mac Safari uses the same library as Apple's Reader. So it's a proprietary native blob. Edit: While Chrome uses a native blob, I believe it's not proprietary. I think they use pdfium ( https://pdfium.googlesource.com/pdfium/ )

It is proprietary, but PDF is the foundation of OS X's graphics, so it's very well-tested.

Being well-tested from the perspective of regular use is not quite the same as being well-tested from the perspective of defending against a hostile actor.
Post reply on HN