Live data from Hacker News

Firefox exploit found in the wild

blog.mozilla.org

261–270 of 277 posts

Re: Firefox exploit found in the wild

#261
post #228

Earlier quoted context omitted.

Done.

Hi fukusa, I know a Russian website (not a news site, it is webdev oriented) that triggers some PDF error in Firefox 35 and does not do that with latest Firefox 39.0.3. I sent a bug report to owners 6 days ago (just because PDF errors on a webpage are strange) and they have not fixed it yet. Could you check this website? I can send you an URL the way you prefer.

I'm not a security expert. If you have a bug report you'd better report it to Mozilla here: https://bugzilla.mozilla.org/

Re: Firefox exploit found in the wild

#262
Updating software shouldn't give a sense of security, instead use sandbox/cipher technologies more generalized, for firefox you could use firejail[0] or sandfox[1].

Or even more general approaches like subuser[2] or QubeOs[3].

Personally I use FF 28.x + Noscript + Adblock plus + Firejail 0.9.28-1 and I feel quite confident I won't get hacked by random attacks.

[0] https://l3net.wordpress.com/2014/09/19/firejail-a-security-s...

[1] https://igurublog.wordpress.com/downloads/script-sandfox/

[2] http://subuser.org/

[3] https://www.qubes-os.org/

Re: Firefox exploit found in the wild

#263
post #250

Earlier quoted context omitted.

Not executing any JS is safer, sure, but that's beside the point. If you strive for absolute security, power off your computer and never touch it again. This is about what you can do to improve the situation without impairing usability. An adblocker doesn't impact usability (in most cases, it improves it significantly, through lower page load times and less space occupied by non-content), but prevents the vast majori…

Unfortunately, an adblocker impacts income of site owners. Otherwise, I would have used these programs since a long time, but now my conscience does not allow it.

I don't want to get into a discussion about ad-based business models and the moral discussion. For me, the trade off definitely favours security. I also just can't concentrate when the page is littered with flashing ads. Thus for me, alternative to adblockers is not seeing ads, it's not visiting the sites because I'm not willing to put up with that for content that very like isn't worth the ad bombardment.

Re: Firefox exploit found in the wild

#264
post #11

Earlier quoted context omitted.

"...the new IE" has been thrown about so much it is basically an empty statement I'm afraid https://www.google.com/webhp?q=%22chrome+is+the+new+IE%22 https://www.google.com/webhp?q=%22firefox+is+the+new+IE%22 https://www.google.com/webhp?q=%22safari+is+the+new+IE%22

If you had taken a moment to actually scan those search results, you would have realized that "Chrome is the new IE" is typically a reference to its ubiquity. Safari and Firefox is typically called the new IE because they are lagging behind the times. Which is why I said "IE6" in my original comment. The later versions of IE were very decent. They certainly didn't seem like the frozen accident of history - an issue F…

> Safari and Firefox is typically called the new IE because they are lagging behind the times.

That's a reasonable criticism of Safari, which is updated infrequently and is lagging on all sorts of web standards, but not for Firefox.

Re: Firefox exploit found in the wild

#265
post #52

How many PDF.js security vulnerabilities have been found so far? A quick Google search found only four: https://www.mozilla.org/en-US/security/advisories/mfsa2013-9... (another local file disclosure) https://www.mozilla.org/en-US/security/advisories/mfsa2015-3... (needs to be "combined with a separate vulnerability" to be exploitable) https://www.mozilla.org/en-US/security/advisories/mfsa2015-6... (needs to be "combi…

Tech lead of pdf.js here: All of the above exploits were issues with extension code in firefox, i.e. other extensions could have these issues too. If you were to use the web only version of pdf.js none of these exploits would apply.

Just to clarify... were the vulnerabilities in Firefox itself? Or were they in the extension?

Re: Firefox exploit found in the wild

#266
post #61
post #58

Earlier quoted context omitted.

> It still is looking better than the plugin it replaced. Not for long if this keeps up…

For comparison, NIST NVD lists 445 CVEs for Acrobat, or at least 17 per year since introduction. However CVEs haven't been maintained since the early 90s, so that number should be much higher. I think pdf.js does just fine.

>CVEs haven't been maintained since the early 90s

Can you clarify what you mean by this?

Re: Firefox exploit found in the wild

#267

Earlier quoted context omitted.

> I can't figure why would a browser double as a PDF reader, for instance, when a native app is invariably faster, more feature-rich, more customisable and more secure. A native app is less secure. They're all written in memory-unsafe languages, are not guaranteed to be up-to-date, and do not run sandboxed. Integrating a JS PDF viewer into the browser hurts performance, but it's more convenient (no separate app to op…

>> A native app is less secure. They're all written in memory-unsafe languages, are not guaranteed to be up-to-date, and do not run sandboxed. So how can we even trust the browser if native apps are always less secure according to you? The exploit ran despite the sandbox if I understood it right.

I don't understand the reasoning here at all. Are you arguing that because sandboxes sometimes have holes in them that they aren't worthwhile?

Re: Firefox exploit found in the wild

#268

Some more details would be helpful here. Specifically: 1. If PDF files aren't set to open using Firefox's built-in PDF viewer, was the relevant system still vulnerable? (That is, if under Options->Applications, PDFs were set to something other than "Preview in Firefox", would this attack still work?) 2. Which were the 8 popular FTP clients potentially affected? 3. Was this specific case all that could be done or was…

> 2. Which were the 8 popular FTP clients potentially affected?

Answered elsewhere in the thread (SmartFTP, Notepad++ NppFTP, FileZilla, FTP Explorer, FTPGetter, FTP Now, FTPInfo, Total Commander, Ipswitch WS_FTP, and VanDyke)

Re: Firefox exploit found in the wild

#269
post #208

Earlier quoted context omitted.

SumatraPDF is the only reasonable way to view a PDF safely. http://www.sumatrapdfreader.org/free-pdf-reader.html Not perfect but definitely not adobe or foxit and way safer than viewing in any browser.

What makes Sumatra safer than other FOSS PDF viewers like evince, okular, epdf, etc.?

It doesn't try to execute javascript and whatever else is in PDF these days.

Re: Firefox exploit found in the wild

#270

Earlier quoted context omitted.

> And what business does a browser have with a .pdf file anyway, where does that end? excel sheets? word documents? proprietary format 'x'? Web browsers should stick to web browsing or at least have a mode where they will stick to just web browsing. Displaying arbitrary media content is web browsing; the web is an interconnected network of servers providing hypermedia content that is self-describing as to content typ…

Sure, and if I install some plug-in to deal with a proprietary format that's my own doing and risk. But by default a browser should stick to a sensible subset otherwise we might as well author our web-pages in .pdf format instead of HTML. Anyway, I've already been called grumpy and being told to sell my laptop and go live in a cave so I'll give HN a miss for the next couple of days or so.

:-( but I like your comments!

(also let me take the moment to tell you that your recent "Nothing to hide" blog post is great, thanks for writing that)

Post reply on HN