main
Report a problem

Mozilla Pushes Security in Firefox 3.0

Daniel Fleshbourne   on 09 August 2007 - 13:18 · 9 comments & 6534 views

Advertisement (Why?)
Mozilla Corp.'s next update to Firefox will sport several new safer surfing features, the company's chief of security said Wednesday, but users won't see the most important changes. On track and expected to make it into the final version of Firefox 3.0 when it ships later this year is a tool that would automatically block sites suspected of harboring malware. The Web browser will also offer support for the extended validation Secure Sockets Layer (EV SSL) certificates, said Window Snyder, Mozilla's chief security officer.

The malware blocker, which relies on site blacklists generated by Google Inc., has been publicly debated by Mozilla and Google developers, with mock-ups of the on-screen warnings debuting in early June. Then, Snyder refused to get specific about the feature, saying there was no guarantee the tool would be wrapped up in time to add to Firefox 3.0.

View: the full story
News source: PCWorld

Post a comment · Send to friend Comments · There are 9 additional comments
#1 jmc777 on 09 Aug 2007 - 13:47
"Window Snyder"

That's an awesome name!
(3 replies) #2 Xenomorph on 09 Aug 2007 - 13:53
Well, at first I thought "auto blocking bad sites" would be good, but when they said the list is provided by Google, I suddenly started worrying.

Why? Because I've seen sites blocked by Google not because of being bad, but because some company contacted Google and TOLD them to remove the site from their listings.

When searching for some things, you may get a message like this:

In response to a complaint we received under the US Digital Millennium Copyright Act, we have removed 1 result(s) from this page. If you wish, you may read the DMCA complaint that caused the removal(s) at ChillingEffects.org.

Or you may get this one:

Warning - the site you are about to visit may harm your computer!

Getting a message like that puzzled me, because it was a site I had been to many times, and never had any issues.

The sites may not be harmful to you or have anything to do with piracy. If a big company doesn't want a page to exist because it offers modifications to their product(s), they can send a letter to Google, claiming the site is violating the DMCA by having anything to do with their product.

In most cases, this won't be an issue, but I'd rather have some smaller independent company, who doesn't do what it does for a PROFIT, decide what pages are bad.
#2.1 vetmarkjensen on 09 Aug 2007 - 14:23
Quote - (Xenomorph said @ #2)
...
Or you may get this one:

Warning - the site you are about to visit may harm your computer!
...
Those types of warnings can come about when a site uses advertisers where they have had content provided by a malicious group intent on spreading a bit of malware by disguising it as a legitimate advert.

Therefore, a site that is normally "trusted" can be temporarily used as a malware vector.
#2.2 Sp3ctranova on 09 Aug 2007 - 17:52
This is exactly what I was thinking. Auto-blocking, blind censorship, isn't the way to go. Perhaps the browser should have just an additional security prompt, making it perfectly clear to the user that a certain website may have dangerous content on it.
But the problem can be that all these prompts get annoying. Whenever I reformat one of PCs I work with, the first thing I do is turn off some of the security prompts in IE7, such as phishing filter and that little message it gives you when you leave/enter a secure zone. I hate those little messages. I know they're designed to keep malware off of computers, but 99% of the time it's just another box to click through in order to get work done.
If Mozilla does put some kind of auto-block system into Firefox 3, it ought to be able to be turned off or at least customized.
#2.3 Shinji on 10 Aug 2007 - 06:33
Quote - (Sp3ctranova said @ #2.2)
But the problem can be that all these prompts get annoying. Whenever I reformat one of PCs I work with, the first thing I do is turn off some of the security prompts in IE7, such as phishing filter and that little message it gives you when you leave/enter a secure zone. I hate those little messages. I know they're designed to keep malware off of computers, but 99% of the time it's just another box to click through in order to get work done.


I don't like the pop-up messages, too. Because they interrupt me. I want to see the messages but not in a way that they make me stop what I am doing just to click OK.

Maybe the messages can be shown in a non-forcible manner so I can see them while the pages are nevertheless loading, like the pop-up block messages or the java script error log.
#3 IntelliMoo on 09 Aug 2007 - 18:01
And in that 1% time, you create a zombie... lol
#4 Xenomorph on 09 Aug 2007 - 19:01
Another reason this is weird - a big plus for using something like Firefox was because it never suffered all the security issues Internet Explorer had.

A page written in a certain way would prompt IE to install ActiveX controls (which many users may click to allow without even thinking about it), produce non stop popups, resize and move the window, or do a bunch other annoying things - when Firefox would just display it as a normal page.

So if there is a "bad" web site out there, I would be afraid to view it with IE. Firefox (or Opera) wouldn't have any issue with it, so why would Firefox try to block it?

#5 xMorpheousx416 on 09 Aug 2007 - 20:17
Since the founders/coders of Firefox read Neowin....


Let it be known, that too much "automation" is a BAD THING!! Intentions start off good,....the thought of a perfect computing environment in which there is little to know interaction between the safe guards and the user. Microsoft does this all the time, and it's the first thing users learn, is how to turn the damn "security" feature off.

So.... go for it!! Just give the option to have the site blocked to the user. Similar to AdBlock. Maybe a window of information the security feature could use to inform the user of malware content that could be activated because it's part of the site's page code. Then...the user has the option to block the site.
#6 +vlsi0n on 10 Aug 2007 - 05:41
Doesn't IE7 already have this? I like they way they've done it, they let YOU decide what YOU want to do with the warning. Anyway, looking forward to the fox3

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)