Page 1 of 1

Germany warns surfers against Firefox

Posted: Fri Mar 26, 2010 1:19 am
by 5829
http://www.theregister.co.uk/2010/03/22 ... x_warning/


Germany warns surfers against Firefox

Achtung browser

By John Leyden

Posted in Malware, 22nd March 2010 14:13 GMT

Free whitepaper – Taking control of your data demons: Dealing with unstructured content

German's official cyber-security response team is advising surfers not to use Firefox pending the release of a patch to defend against a critical unpatched vulnerability.

BürgerCERT, a division of the German federal government's security in information technology (BSI) department, warned (http://www.buerger-cert.de/techwarnung_ ... %253d%253d) surfers to steer clear of the open source browser until Mozilla releases a fix, due on 30 March. The zero-day vulnerability in the latest full version 3.6 of Firefox was discovered by security researcher Evgeny Legerov last month and explained in much greater depth in our story at the time here (http://www.theregister.co.uk/2010/02/18 ... day_report). Legerov controversially offered to sell exploit code he developed.

Mozilla acknowledged (http://blog.mozilla.com/security/2010/0 ... ry-sa38608) the security vulnerability on Thursday and promised the the next version of 3.6.2, due at the end of the month, would plug the hole. In the meantime, Mozilla published a beta of Firefox 3.6.2 that addresses the flaw. However this release isn't ready for prime time just yet.

The German government, which previously urged surfers to stay off IE in January for similar unpatched security bug reasons, has now taken a stand against Firefox.

The consensus among security researchers is that mass browser migration in enterprises is unworkable. It's tricky enough to get some corporates (including even Google, if the evidence of Operation Aurora is to be believed) to upgrade from IE 6.

Consumers don't have to worry about access to legacy applications but swapping browsers willy-nilly in response to flaws doesn't make a great deal of sense even then because all browsers are subject to security flaps from time to time. The more important question is to what extent an unpatched browser hole is getting exploited by hackers, scammers and other riff-raff.

The Firefox vulnerability poses a possible mechanism to infect surfers using the open source browser if they can be tricked into visiting a maliciously constructed website. In the case of the Firefox vulnerability exploit code is available - though not in a "weaponised" form - and there's not much sign that attacks are taking place.

Versions of Firefox prior to 3.6 are not prone to this specific vulnerability but are subject to other bugs, so reverting back to earlier versions of the browser isn't the smartest idea. ®
Related stories
Mozilla swats Firefox zero-day bug a week early (23 March 2010)

http://www.theregister.co.uk/2010/03/23 ... o_day_fix/
Firefox zero-day fix set up for 30 March release (19 March 2010)

http://www.theregister.co.uk/2010/03/19 ... y_updates/
Anti-virus suites still can't block Google China attack (16 March 2010)

http://www.theregister.co.uk/2010/03/16 ... test_fail/
Microsoft spits out 'browser choice' update to appease EC antitrust probe (1 March 2010)

http://www.theregister.co.uk/2010/03/01 ... er_ballot/
Attack code for Firefox zero-day goes wild, says researcher (18 February 2010)

http://www.theregister.co.uk/2010/02/18 ... ay_report/
Firefox update takes down three critical flaws (18 February 2010)

http://www.theregister.co.uk/2010/02/18/firefox_update/
Contest offers $100,000 for smartphone, browser hacks (16 February 2010)

http://www.theregister.co.uk/2010/02/16/2010_pwn2own/
Mozilla admits Firefox add-on malware false alarm (11 February 2010)

http://www.theregister.co.uk/2010/02/11 ... lse_alarm/
Firefox 3.6 goes live and final (21 January 2010)

http://www.theregister.co.uk/2010/01/21 ... x_release/
MS spins IE security disaster into Windows 7 upgrade opportunity (19 January 2010)

http://www.theregister.co.uk/2010/01/19 ... nightmare/
IE6 exposed as Google China malware unpicked (19 January 2010)

http://www.theregister.co.uk/2010/01/19 ... _analysis/

Re: Germany warns surfers against Firefox

Posted: Fri Mar 26, 2010 4:51 am
by AYHJA
I am just becoming more and more disinterested in these browser wars...I've tried them all here lately, and there is no longer a clear cut winner...Firefox has become so damn hard to use, I don't know what to do anymore...It's not crashing, but it kills my CPU...It's still the best browser I have, but if there were ever a browser to contest the power of FF extensions, I wouldn't hesitate to switch...

I tried Opera, and thought it was good, but I didn't see any advantages to using it instead of Firefox...

Re: Germany warns surfers against Firefox

Posted: Fri Mar 26, 2010 5:55 am
by Dietrich
Über wrote:Firefox has become so damn hard to use, I don't know what to do anymore...It's not crashing, but it kills my CPU...It's still the best browser I have, but if there were ever a browser to contest the power of FF extensions, I wouldn't hesitate to switch...

I tried Opera, and thought it was good, but I didn't see any advantages to using it instead of Firefox...
It may simply be because I use just three extensions (DownThemAll, Image Toolbar, and ImageHost Grabber) but my experience in the last two weeks has been just the opposite. Up until a couple months ago, I had been using Opera, and I found it definitely satisfactory. Then Über-san claimed he'd have to "block" me because I wasn't using Firefox ( :p ), so then I started up with it, and once I got familiar with certain extensions, I found FF to be the handiest browser I'd ever used. A couple weeks ago I tried the latest version of Chrome, and I dug it, especially it's minimal UI. But it gave me trouble with certain websites, especially Tumblr. Also, at certain times my comp would make that quiet crackling sound that tells you the CPU is hard at work, and when I looked at the Processes tab of Windows Task Manager, there would be six or seven "chrome.exe" processes going at once, even if I only had one or two Chrome tabs open. Several times this caused my computer to lock up, such that I had to switch it off manually and restart. Frustrated with this, I tried the latest version of Opera, and I dug it. But something about Opera made Tumblr quite user-unfriendly, so here am I back using FF again. :think: I haven't yet had any problems with FF, at least none worth speaking of.