Sneaky Microsoft plug-in puts Firefox users at risk


Recommended Posts

That's how it's supposed to be on paper. Reality, on the other hand, has shown us that Firefox simply keeps on springing leaks like no tomorrow.

Except that the thing is that you don't have to be (entirely) dishonest to paint a dishonest picture, especially when the masses of fanboys are willing to swallow whatever propaganda Mozilla tosses out at them.

Mozilla tries to sell Firefox as a more secure product than it really is, not by hiding security problems, but by shifting the attention elsewhere and telling people that's what they should be looking at. Multiple critical security vulnerabilities that keep popping up nonstop every few months? It's all cool, we'll just play whack-a-mole and fix them as fast as we can. Nothing to worry about, we're definitely the most securest browser ever!

And it's really sad when the fanboys buy this, hook, line, and sinker.

I don't know what's going wrong at Mozilla. But I think it may be worthwhile for them to take a step back and re-examine the fundamental way they do things, instead of continuing to leak security problems like crazy while stringing the gullible masses along with lame excuses like "we're open-source!" and "let's blame M$!".

Eice, let me ask you a question. What's with this persistence of your 'trolling type' to continue coming into these threads and talking complete cr*p? I'm not being rude, i'm just stating an obvious fact that you contribute absolute nothing in its purest sense to this discussion, except the opportunity to spread FUD, hate speech and irrationality....

Sure I understand you mention some valid points, but 'hey', which company doesn't play the whole 'i'm the best' game? Stop going off topic, why do you have to mention "what's going wrong at Mozilla" ?

Stop the senseless ranting and do yourself a favour and get out of the thread.

I for one wish you'd be warned or locked from this thread, this is coming a common occurance on Neowin; you simply can't read a thread without someone coming along and having to go completely go........off.....topic.....like.....this.

now back on topic -> I for one am not happy about this supposed 'solution' from MS and can't be bothered with people saying 'it can be uninstalled so what's the biggie'? Simply to put it, the argument behind such a comment is weak at best, I for one stand by the principle of privacy and consent from the user, so I don't take kindly to this MS 'crapware' if you ask me. Its Mozilla browser; really just either looks like foul play on MS's behalf or their complete idiotic mentality of thinking everybody wants their little 'solutions' to 3rd party software. I for one say 'No thanks'.

typical MS basher

There goes your credibility.

post-254628-1255862557_thumb.png

you can clearly uninstall , within two clicks

Your attachment didn't work. Show me how to remove the plugin in two clicks.

also to add to the point , we clearly "authorized" installation of .NET ....so

No, I didn't authorize it. It was a silent auto update and there was no mention of a plugin that would infect Firefox. Firefox is not MS software, MS has no right to interfere with third party software.

Face it, MS was wrong for infecting a third party software without any warning or authorization. I am surprised Mozilla hasn't done anything about it. But I also blame Mozilla for making it so easy for malware to be silently installed. If MS can do it, some other update could do it too.

There goes your credibility.

Your attachment didn't work. Show me how to remove the plugin in two clicks.

No, I didn't authorize it. It was a silent auto update and there was no mention of a plugin that would infect Firefox. Firefox is not MS software, MS has no right to interfere with third party software.

Face it, MS was wrong for infecting a third party software without any warning or authorization. I am surprised Mozilla hasn't done anything about it. But I also blame Mozilla for making it so easy for malware to be silently installed. If MS can do it, some other update could do it too.

See the thing is, it should be upto firefox to see hey theres this plugin and it's trying to install it into me, maybe i should prompt the user, rather than just full on accept the plugin.

Thing is if a browser can pickup a plugin like that and install it like that without any prompts what so ever, then errrrrr major flaw if you ask me.

So at the end of the day firefox is at fault for not detecting the plugin and prompting the user like it normally does when installing a plugin........

If anything it shows their plugin system needs a good look over.

Also you going on about "infected", seriously

Oh and in other news my company will not be deploying firefox ever again, so yer mozilla good one. The people above me have spoken.

This was discussed some time ago, and someone jumped infuriated on the suggestion that it could introduce a new extra attack vector.

Well, there you go.

Yeah, I totally remember that thread. You were right dude.

Didn't read the discussion much, but now the plugin has been blocked and unblocked, I think it was very irresponsible of Mozilla to issue a block so hastily. There are some people out there relying on the plugins functionality and some people have the technical know-how of protecting themselves against attack if needed. It should be users choice to use a plugin whether or not it has a potential security problem so as not to break their applications.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Samsung messages is still alive and well. They reversed that and decided to our more effort into it.
    • I think every American should have a course in a 'dry sense of humour' at school; and perhaps 'using sarcasm in jest' oh, and also 'the use or irony in humour'.
    • What they really need to do is automatically spell "loses" and "lose" correctly since nobody seems to know how to anymore. Then they blame spellcheck/autocomplete and don't realize autocomplete is just filling in the word for them automatically so it was misspelled in the first place.
    • If someone chooses to continue using SB and therefore goes through the manual intervention in the thread, afterwards the BSOD problem is gone. Whether they then re-enable the task doesn't matter, they're done, though on such machines it might pay to keep it disabled in case the next update (if there is a next) causes the same problem. OTOH, if someone disables SB in the BIOS, the problem is also gone. Incidentally, I noticed that this task exists even on machines that don't support SB. It's just installed across the board...and runs. Doing what on such machines is a little hazy.
    • qBittorrent 5.2.2 by Razvan Serea The qBittorrent project aims to provide a Free Software alternative to µtorrent. qBittorrent is an advanced and multi-platform BitTorrent client with a nice user interface as well as a Web UI for remote control and an integrated search engine. qBittorrent aims to meet the needs of most users while using as little CPU and memory as possible. qBittorrent is a truly Open Source project, and as such, anyone can and should contribute to it. qBittorrent features: Polished µTorrent-like User Interface Well-integrated and extensible Search Engine Simultaneous search in most famous BitTorrent search sites Per-category-specific search requests (e.g. Books, Music, Movies) All Bittorrent extensions DHT, Peer Exchange, Full encryption, Magnet/BitComet URIs, ... Remote control through a Web user interface Nearly identical to the regular UI, all in Ajax Advanced control over trackers, peers and torrents Torrents queueing and prioritizing Torrent content selection and prioritizing UPnP / NAT-PMP port forwarding support Available in ~25 languages (Unicode support) Torrent creation tool Advanced RSS support with download filters (inc. regex) Bandwidth scheduler IP Filtering (eMule and PeerGuardian compatible) IPv6 compliant Available on most platforms: Linux, Mac OS X, Windows, OS/2, FreeBSD qBittorrent 5.2.2 changelog: FEATURE: Use D-Bus to show file in file managers (Chocobo1) #24340 BUGFIX: Fix friendlyUnitCompact precision calculation (vafada) #24323 BUGFIX: Remove all top-level folders (glassez) #24333 BUGFIX: Use proper API for checking exit status (Chocobo1) #24349 BUGFIX: Delete stale lockfile when hostname mismatch (TurboTheTurtle, glassez) #24363 BUGFIX: Fix wrong removal procedure of watched folder paths (Chocobo1) #24413 BUGFIX: Don't reannounce before interface changes are applied (glassez) #24447 BUGFIX: Use Latin script for Bosnian locale name (Andy Ye) #24342 WEBUI: Fix performance of global checkbox toggling (tehcneko) #24316 WEBUI: Fix Safari transfer list header misalignment (Piccirello) #24377 WEBUI: Fix error when submitting magnet before metadata loads (Piccirello) #24378 WEBUI: Use correct row id when updating Rss Downloader feed selection (Chocobo1) #24402 WEBUI: Use SameSite=Lax for session cookie to fix cross-site login (Piccirello) #24422 WEBUI: Bring back properties panel expand/collapse button (vafada) #24430 WEBAPI: Only use X-Forwarded-Host header when reverse proxy support is enabled (Chocobo1) #24457 RSSS: Fix "RSS Smart Episode Filter" RegEx (nathanon-akk, glassez) #24398 RSS: Fix previously matched episode format (glassez) #24452 WINDOWS: Fix Python fallback search path (TurboTheTurtle) #24325 WINDOWS: NSIS: Allow to install x64 binary on ARM64 (Chocobo1) #24358 Download: qBittorrent 5.2.2 | 41.1 MB (Open Source) Download: qBittorrent 64-bit installer (qt6) | 43.6 MB Links: qBittorrent Home page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
  • Recent Achievements

    • One Month Later
      Twozo Technologies earned a badge
      One Month Later
    • Week One Done
      Twozo Technologies earned a badge
      Week One Done
    • One Year In
      Twozo Technologies earned a badge
      One Year In
    • Veteran
      branfont went up a rank
      Veteran
    • Reacting Well
      Almohandis earned a badge
      Reacting Well
  • Popular Contributors

    1. 1
      +primortal
      497
    2. 2
      +Edouard
      183
    3. 3
      PsYcHoKiLLa
      126
    4. 4
      Steven P.
      85
    5. 5
      neufuse
      71
  • Tell a friend

    Love Neowin? Tell a friend!