Sneaky Microsoft plug-in puts Firefox users at risk


Recommended Posts

It's not a secret Firefox installation. The plug-in is installed as part of the .NET Framework and Firefox picks it up automatically. If anything, we should complain to Mozilla for the browser not asking if the "found" plugin should be added. Their methodology could easily activate a hidden malware plugin the same way.

The installer could bypass any checking done by firefox anyway, there's really not much point in implementing such thing.

That's what I'm sayin'. I bet Mozilla wouldn't have liked it if Microsoft had uninstalled and blacklisted Firefox due to the crypto spoofing flaw.

You are forgetting one thing. Windows OS is not your even after you've paid for it. You just bought the right to use it, like a lease.It is Microsoft's which controls the OS completely and has the right to wipe the OS, stop it from running, install what ever Microsoft want.... and there is nothing you can do about it apart from formating and moving to free OS, like Linux.....

"This was obviously pushed through just to make some anti-microsoftie's pud hard.

This vulnerability is completely fixed, as much as anyone can know for now in the latest updates. see http://blogs.technet.com/srd/archive/2009/...2/ms09-054.aspx

Yes, there may still be a "potential vulnerability" but that is true for every single plugin/addin and firefox itself.

Thanks for disabling something that we were already protected from that we use in line of business applications. :rolleyes:

I guess our decision to move to firefox company wide was a mistake and we'll have to push out a script to set everyone back to IE as the default browser before Monday if this isn't recalled ASAP."

https://bugzilla.mozilla.org/show_bug.cgi?id=522777#c65

Edited by franzon
You are forgetting one thing. Windows OS is not your even after you've paid for it. You just bought the right to use it, like a lease.It is Microsoft's which controls the OS completely and has the right to wipe the OS, stop it from running, install what ever Microsoft want.... and there is nothing you can do about it apart from formating and moving to free OS, like Linux.....

None of this is accurate.

Yes, you are only licensing the software. However, you have the right to use your license as purchased, and they can't just 'stop it from running'.

"This was obviously pushed through just to make some anti-microsoftie's pud hard.

This vulnerability is completely fixed, as much as anyone can know for now in the latest updates. see http://blogs.technet.com/srd/archive/2009/...2/ms09-054.aspx

Yes, there may still be a "potential vulnerability" but that is true for every single plugin/addin and firefox itself.

Thanks for disabling something that we were already protected from that we use in line of business applications. :rolleyes:

I guess our decision to move to firefox company wide was a mistake and we'll have to push out a script to set everyone back to IE as the default browser before Monday if this isn't recalled ASAP."

https://bugzilla.mozilla.org/show_bug.cgi?id=522777#c65

They're really catching the crap for it now... :p

Yeah, that one guy on the internets is totally owning Mozilla!

Considering Microsoft agrees with the blacklist, I doubt any reasonable person has a problem with this.

I spoke on the phone with the responsible director at Microsoft on Friday, and

she agreed that the blocklist was the right approach. We can evaluate changes

to the blocklist in the future, and updates take effect quite quickly, but

right now both Microsoft and Mozilla are in agreement that this is the best way

to protect our mutual users.

https://bugzilla.mozilla.org/show_bug.cgi?id=522777#c56

Gotta love how the FF devs have gotten on their high horse about this, and gone off after Microsoft with their usual Inane banter.

Although I agree that Microsoft should make the installation Optional, it has also highlighted the need for Mozilla to have a rethink of the security within their browser, and other browser vendors as well, the fact that unsigned plugins can install themselves and be activated no questions asked is worrying

i know this may sound stupid , but is this anything to do with firefox throwing a random error box up at me an hour or so ago saying a couple of add-ons may cause conflicts ? i followed the link from the pop up and even tho it was the firefox google page it said invalid security certificate , but going to the same page from my normal firefox window worked without issue .

so was it this add on that was causing the memory leaks?

No. The Framework Asssistant doesn't do anything except add the MIME type for .NET ClickOnce applications to Firefox so Windows can open them. I'm assuming the WPF one allows WPF applications to run on Firefox in much the same way.

Stop whining, its actually a good thing Mozilla was able to block this application without any user intervention, especially those who do not read up on current security exploits.

As I said before, it's understandable there was a security issue, but I doubt Mozilla would have appreciated Microsoft uninstalling and blocking Firefox due to its security issues. You don't just remove another company's products from a user's computer without providing explicit information why and an opt-out.

What irritates me is that it didn't have an option to leave them anyway and it didn't have a link to the patch KB article so people could just make sure they were updated rather than banning two addons that could potentially cost corporate users tens of thousands of dollars in support Monday morning.

As I said before, it's understandable there was a security issue, but I doubt Mozilla would have appreciated Microsoft uninstalling and blocking Firefox due to its security issues. You don't just remove another company's products from a user's computer without providing explicit information why and an opt-out.

What irritates me is that it didn't have an option to leave them anyway and it didn't have a link to the patch KB article so people could just make sure they were updated rather than banning two addons that could potentially cost corporate users tens of thousands of dollars in support Monday morning.

+1

it really F***ing annoy me ,for one side action

if they try to pi$$ me off again , then Bye bye FireFox . Back to IE!

One side? They asked Microsoft and they themselves recommended blacklisting the plugin. I don't know where you guys keep pulling this crap.

cause Mozilla didn't ask for my consent to disable the plugin duh!

cause Mozilla didn't ask for my consent to disable the plugin duh!

ah, my bad. I thought you meant one sided in the sense that Mozilla disabled something that belongs to Microsoft behind their back.

"Soft blocks" (where in cases like this Firefox would pop up a warning dialog but wouldn't disable the extension/plugin) have actually been already checked in but the server side functionality hasn't been enabled yet so it couldn't be used in this case. Hopefully this incident gets them wrap up the server side support quickly.

Related bugs:

https://bugzilla.mozilla.org/show_bug.cgi?id=455906

https://bugzilla.mozilla.org/show_bug.cgi?id=462433

+1

if they try to pi$$ me off again , then Bye bye FireFox . Back to IE!

:laugh:

Oh yes, go to go back to a more unsecure browser just because mozilla blocks an extension. Boo Hoo.

on the same note, Microsoft ****es me off for automatically installing this extension. But I'm not going to boycott the .net framework or windows because of it.

cause Mozilla didn't ask for my consent to disable the plugin duh!

I don't remember Microsoft Asking for consent to install the plugin in the first place.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • UK to ban under-16s from social media following a six-week trial with teenagers by Paul Hill Credit: Pexels A few months ago, Neowin reported that the UK was trialing a social media ban with 300 teenagers for six weeks, that testing has come to an end, and Prime Minister Keir Starmer has announced that the country will ban under-16s from social media. Starmer said that this technology is making children unhappy and making it easier for bullies to harass and abuse them. He continued to talk about the addictive nature of social media, saying that it uses an infinite scroll designed to lock users in for hours. He said this interferes with children doing their homework, reading, playing with friends outside, and going to bed on time. Tackling the idea that nothing can be done about social media, Starmer said: The government’s action won’t stop at social media either, the PM said. It plans to take action on gaming services and livestreaming platforms. Right now, he said, strangers can contact any child unchecked. He said this wouldn’t happen in real life, and the government is going to stop it from happening online, too. The Labour government has overseen the introduction of the Online Safety Act, a big change to the internet which includes age verification on adult websites. This has led to a fair bit of backlash, but overall, the government is pushing ahead with these changes.
    • Still using Hexchat every day but i would not consider it Retro 😛
    • HONOR Robot Phone unveils first Cinematic Video at Shanghai International Film Festival by Steven Parker Global AI device ecosystem company HONOR announced on June 13 that its revolutionary HONOR Robot Phone made its professional imaging debut at the 28th Shanghai International Film Festival (SIFF), demonstrating the result of its mobile videography capabilities for the first time. As the official mobile photography and videography partner of the 28th Shanghai International Film Festival, HONOR empowers this premier cinematic event with cutting-edge mobile imaging technology. Marking the global debut of the first cinematic video it captured, Robot Phone breaks down the boundaries between mobile imaging and professional filmmaking, ushering in a new paradigm for the deep integration of technology and cinematic art. In the video published on HONOR’s official channel (above), Robot Phone was used byELLEMEN to capture cinematic video portraits for the SIFF jury members. With its exceptional stability and cinema-grade imaging capabilities, the device redefines the art of portrait filmmaking, faithfully reproducing the rich tonal gradations and nuanced color transitions associated with film photography. The result is a new level of visual sophistication, creating high-end cinematic imagery that seamlessly blends atmosphere with narrative tension. The video released for the Robot Phone showcases the powerful stabilization capabilities of its built-in gimbal system, delivering exceptionally smooth handheld camera movement while preserving full image quality. By minimizing reliance on electronic image stabilization, the device effectively avoids the image cropping and quality loss typically associated with digital stabilization methods. Representing an innovative leap in form factor, the HONOR Robot Phone features the industry's smallest titanium alloy gimbal, delivering ultra-precision, extreme flexibility, and superior stability. Driven by high-performance motors, the gimbal rises dynamically, breaking free from the physical limitations of traditional camera modules. Combined with advanced AI algorithms that enable intelligent object tracking and various movements with stable shots, the device significantly simplifies video creation and reshapes both the equipment choices and creative habits of modern users. Notably, the Robot Phone will be the first product that features the results of HONOR's strategic technological partnership with ARRI, the world-renowned designer and manufacturer of professional camera technology for cinematic storytelling. From Cannes to Shanghai, the HONOR Robot Phone continues to lead the mobile imaging industry into an entirely new stage of development. Moving forward, HONOR will leverage cutting-edge AI and mobile imaging technologies to unlock new creative possibilities and extend cinematic standards for visual expression from the world of high-end filmmaking to the next generation of content creators. Learn more about the HONOR Robot Phone here: https://www.honor.com/global/events/honor-robot-phone/
    • I'll wait for the root cause analysis. Looks like it's HP, Lenova, and certain configurations that are askew, hardly "all of windows." Time will tell.
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      510
    2. 2
      +Edouard
      200
    3. 3
      PsYcHoKiLLa
      137
    4. 4
      ATLien_0
      91
    5. 5
      Steven P.
      83
  • Tell a friend

    Love Neowin? Tell a friend!