Gaps in the appendices jeopardize the security of Firefox users
23 November 2009 | By Anton | Views: 252 | Comments 1 |
Security experts have found in many popular extensions for Firefox security issues. They warn that the use of plug-ins may reduce the level of the whole system.
One reason for the popularity of Firefox is the ability to expand browser functionality with add-ons. Some, like NoScript even raise the level of security while you surf. The problem is that there is no defined boundary between the browser and extensions. This means that the problem of security contained in the Appendix some may discredit the whole system. In addition, this promotes the fact that the developers of plug-ins often take their hobby occupation and safety are not as extensive as the competence of the browser developers.
Media reported that security experts discussed the problem at a conference in India, where among other things, demonstrated how to use a type of Zero Day exploits against many popular Firefox extensions. It appears that the critical vulnerabilities include, for example, two RSS feeds: Sage to version 1.4.3 and Yoono 1.1.4.2, as well as the addition of social networking Yoono 6.1.1.