New Firefox 3.0 alpha blocks malware, secures plug-in updates
Security features debut in latest preview, as Firefox 3.0 heads down the stretch
Цитата:
Among the security provisions debuting in the new alpha of "Gran Paradiso," the code name for Firefox 3.0, are built-in anti-malware warnings and protection against rogue extension updates, according to documentation Mozilla posted to its Web site.
"Firefox automatically checks for updates to add-ons using a URL specified in the add-on's install manifest," Mozilla spells out in a developer's document. "Currently there are no requirements placed on these URLs. In particular, [they are not] required to be https. This allows either the update manifest or the update package to be compromised, potentially resulting in the injection of malicious updates. A demonstration of one form of compromise is already public.
|
More Info:
Код:
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9038258&intsrc=hm_list
|