Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
1–10 of 82 posts
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#2Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#3The user can't leave the malicious domain, but they also can't interact with the page, because the dialog is in the way. And even if they could, are they really more likely to trust the site after it's made a bunch of random popups appear in a row?
Is it just malice? What does the malicious site gain?
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#4Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#5Pure curiosity, what's the advantage of this? What am I missing? The user can't leave the malicious domain, but they also can't interact with the page, because the dialog is in the way. And even if they could, are they really more likely to trust the site after it's made a bunch of random popups appear in a row? Is it just malice? What does the malicious site gain?
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#6Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#7Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.
Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#8One, among many, of the reasons I use Chromium is that I see reports taken absolutely seriously, especially any report with any potential security outcome. Even seemingly minor issues or feature requests I've filed with Chromium get thoughtful and prompt responses.
I wish Mozilla the best, but the quality of Firefox is low in a way that I notice every time I use it; I'd appreciate it if they go back to basics and actually try to address at least the known issues with the software.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#9Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.
Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.
A very good thing is that most websites use external javascript to implement the most annoying "features" like asking for consent, tracking, autoplay and diverse pop-up junk.
Also it includes the "cosmetic filtering" that allows me to block html elements by name, very useful for subscription requests.
Only when I browse in other people's computer, I'm reminded how screwed the web really is.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#10Pure curiosity, what's the advantage of this? What am I missing? The user can't leave the malicious domain, but they also can't interact with the page, because the dialog is in the way. And even if they could, are they really more likely to trust the site after it's made a bunch of random popups appear in a row? Is it just malice? What does the malicious site gain?
I assume the idea is that on the page visible behind the dialog are instructions to call some number, or open the download, or approve the extension the site wants to install.