http://www.theregister.co.uk/2010/03/22 ... x_warning/
Germany warns surfers against Firefox
Achtung browser
By John Leyden
Posted in Malware, 22nd March 2010 14:13 GMT
Free whitepaper – Taking control of your data demons: Dealing with unstructured content
German's official cyber-security response team is advising surfers not to use Firefox pending the release of a patch to defend against a critical unpatched vulnerability.
BürgerCERT, a division of the German federal government's security in information technology (BSI) department, warned (http://www.buerger-cert.de/techwarnung_ ... %253d%253d) surfers to steer clear of the open source browser until Mozilla releases a fix, due on 30 March. The zero-day vulnerability in the latest full version 3.6 of Firefox was discovered by security researcher Evgeny Legerov last month and explained in much greater depth in our story at the time here (http://www.theregister.co.uk/2010/02/18 ... day_report). Legerov controversially offered to sell exploit code he developed.
Mozilla acknowledged (http://blog.mozilla.com/security/2010/0 ... ry-sa38608) the security vulnerability on Thursday and promised the the next version of 3.6.2, due at the end of the month, would plug the hole. In the meantime, Mozilla published a beta of Firefox 3.6.2 that addresses the flaw. However this release isn't ready for prime time just yet.
The German government, which previously urged surfers to stay off IE in January for similar unpatched security bug reasons, has now taken a stand against Firefox.
The consensus among security researchers is that mass browser migration in enterprises is unworkable. It's tricky enough to get some corporates (including even Google, if the evidence of Operation Aurora is to be believed) to upgrade from IE 6.
Consumers don't have to worry about access to legacy applications but swapping browsers willy-nilly in response to flaws doesn't make a great deal of sense even then because all browsers are subject to security flaps from time to time. The more important question is to what extent an unpatched browser hole is getting exploited by hackers, scammers and other riff-raff.
The Firefox vulnerability poses a possible mechanism to infect surfers using the open source browser if they can be tricked into visiting a maliciously constructed website. In the case of the Firefox vulnerability exploit code is available - though not in a "weaponised" form - and there's not much sign that attacks are taking place.
Versions of Firefox prior to 3.6 are not prone to this specific vulnerability but are subject to other bugs, so reverting back to earlier versions of the browser isn't the smartest idea. ®
Related stories
Mozilla swats Firefox zero-day bug a week early (23 March 2010)
http://www.theregister.co.uk/2010/03/23 ... o_day_fix/
Firefox zero-day fix set up for 30 March release (19 March 2010)
http://www.theregister.co.uk/2010/03/19 ... y_updates/
Anti-virus suites still can't block Google China attack (16 March 2010)
http://www.theregister.co.uk/2010/03/16 ... test_fail/
Microsoft spits out 'browser choice' update to appease EC antitrust probe (1 March 2010)
http://www.theregister.co.uk/2010/03/01 ... er_ballot/
Attack code for Firefox zero-day goes wild, says researcher (18 February 2010)
http://www.theregister.co.uk/2010/02/18 ... ay_report/
Firefox update takes down three critical flaws (18 February 2010)
http://www.theregister.co.uk/2010/02/18/firefox_update/
Contest offers $100,000 for smartphone, browser hacks (16 February 2010)
http://www.theregister.co.uk/2010/02/16/2010_pwn2own/
Mozilla admits Firefox add-on malware false alarm (11 February 2010)
http://www.theregister.co.uk/2010/02/11 ... lse_alarm/
Firefox 3.6 goes live and final (21 January 2010)
http://www.theregister.co.uk/2010/01/21 ... x_release/
MS spins IE security disaster into Windows 7 upgrade opportunity (19 January 2010)
http://www.theregister.co.uk/2010/01/19 ... nightmare/
IE6 exposed as Google China malware unpicked (19 January 2010)
http://www.theregister.co.uk/2010/01/19 ... _analysis/
Germany warns surfers against Firefox
- 5829
- Posts: 1726
- Joined: Sun Jan 22, 2006 11:09 pm
- Location: The Village
- Contact:
Germany warns surfers against Firefox
Nudes are played out.
Send me a video of you reading out loud so I know you are not dumb and your profile picture is actually you.
Free Rice - feed the world - play for free
National Domestic Violence Hotline - 1-800-799-7233
National Rape, Sexual Assault Hotline - 1-800-656-4673
Love Is Respect - 1-866-331-9474
~~~ accept everything - Believe Whatever - TRUST NOTHING ~~~~
There are more things in heaven and earth, Horatio, Than are dreamt of in your philosophy.
Never tell all you know...
Disclaimer: The opinions are my own. Nobody else wants them.
Send me a video of you reading out loud so I know you are not dumb and your profile picture is actually you.
Free Rice - feed the world - play for free
National Domestic Violence Hotline - 1-800-799-7233
National Rape, Sexual Assault Hotline - 1-800-656-4673
Love Is Respect - 1-866-331-9474
~~~ accept everything - Believe Whatever - TRUST NOTHING ~~~~
There are more things in heaven and earth, Horatio, Than are dreamt of in your philosophy.
Never tell all you know...
Disclaimer: The opinions are my own. Nobody else wants them.
BBcode: | |
Hide post links |
- AYHJA
- 392
- Posts: 37990
- Joined: Fri Sep 17, 2004 2:25 pm
- Location: Washington, D.C.
- Contact:
Re: Germany warns surfers against Firefox
I am just becoming more and more disinterested in these browser wars...I've tried them all here lately, and there is no longer a clear cut winner...Firefox has become so damn hard to use, I don't know what to do anymore...It's not crashing, but it kills my CPU...It's still the best browser I have, but if there were ever a browser to contest the power of FF extensions, I wouldn't hesitate to switch...
I tried Opera, and thought it was good, but I didn't see any advantages to using it instead of Firefox...
I tried Opera, and thought it was good, but I didn't see any advantages to using it instead of Firefox...
BBcode: | |
Hide post links |
- Dietrich
- Posts: 1176
- Joined: Tue Nov 03, 2009 5:36 am
- Location: about an hour north of Sam Clam's Disco, where I left my harp
Re: Germany warns surfers against Firefox
It may simply be because I use just three extensions (DownThemAll, Image Toolbar, and ImageHost Grabber) but my experience in the last two weeks has been just the opposite. Up until a couple months ago, I had been using Opera, and I found it definitely satisfactory. Then Über-san claimed he'd have to "block" me because I wasn't using Firefox ( :p ), so then I started up with it, and once I got familiar with certain extensions, I found FF to be the handiest browser I'd ever used. A couple weeks ago I tried the latest version of Chrome, and I dug it, especially it's minimal UI. But it gave me trouble with certain websites, especially Tumblr. Also, at certain times my comp would make that quiet crackling sound that tells you the CPU is hard at work, and when I looked at the Processes tab of Windows Task Manager, there would be six or seven "chrome.exe" processes going at once, even if I only had one or two Chrome tabs open. Several times this caused my computer to lock up, such that I had to switch it off manually and restart. Frustrated with this, I tried the latest version of Opera, and I dug it. But something about Opera made Tumblr quite user-unfriendly, so here am I back using FF again. :think: I haven't yet had any problems with FF, at least none worth speaking of.Über wrote:Firefox has become so damn hard to use, I don't know what to do anymore...It's not crashing, but it kills my CPU...It's still the best browser I have, but if there were ever a browser to contest the power of FF extensions, I wouldn't hesitate to switch...
I tried Opera, and thought it was good, but I didn't see any advantages to using it instead of Firefox...
BBcode: | |
Hide post links |