"We have notified the relevant law enforcement authorities about this incident, and may take additional steps based on the results of any further investigations," Barnes said.
They already knew...
Tinfoil hat time...
Hackers have known about unpublicized and unpatched critical security holes in the Firefox web browser for a year or more – all by invading Mozilla's systems. The Mozilla Foundation admitted on Friday that a privileged account on Firefox's Bugzilla bug-tracking software has been compromised since at least September 2014. Said …
1. High value target hacked.
2. May have lasted years.
I'll skip the obligatory XKCD. The Mozilla Foundation suffers from the illusion that some combination of security procedures is going to prevent just this event into the future. The attacker need only succeed once, the defender always. So, good luck with that.
This is a combination of:
1. Storing extremely high-value information on a server
2. ...which is directly accessible to anyone on the Internet
3. ...protected by nothing more than username and password
In this context, "high-value" includes "allowing an attacker to take over Internet banking accounts and directly steal money from victims"
Storing extremely high-value information on a server
I have to downvote your there, AC. How is anyone supposed to get any work done these days if they can't collaborate and share crucial development info over the net? Especially something like open source tools where (presumably) developers are spread around the world?
Could you suggest a way for them to share info that will be 100% secure? Of course not. We're all human and susceptible to making mistakes every now and then that can let the bad guys breach almost any "secure" system.
On a side note, has anyone been able to extract a full username/password out of the frame padding by using a sniffer? The most I ever extracted was 4 characters*, but then I wasn't really trying.
* I knew what the password was, it was mine.
Want to know how to hit a high value building.
Raid the insurance company for the vulnerability report. *
Want to hit some high value software.
Hit their bug tracking .
You've got to ask how many other projects have been infiltrated this way.
*AFAIK first mentioned in the novel "The Consultant" in the late 70's, also "Absolute Power."
It's a common mistake that can often be overlooked when people have the mind-set for fixing one type of problem (they miss the obvious weak-spot).
For example, I am currently working on building a security platform for a customer which involves collecting and analyzing data from all parts of the network in order to make it more secure.
This platform then becomes the #1 target for any infiltrator because it contains all the information you would ever need to hack into the more sensitive parts of the environment, especially the bits that haven't been sorted out yet*
Therefore as much effort has gone into securing the platform as it has developing the tools to map the network - but not everyone does this - it isn't cheap.
*due to the scale of the mountain
Welp, I'm a believer in full disclosure anyway. And this provides another good reason for this -- if blackhats will get ahold of the exploits anyway*, then the other users may as well get a fair chance to see just what they are currently vulnerable (and possibly be able to mitigate it instead of just being left in the dark.)
*Even if you pretend they can get perfect security, there's nothing stopping a bug report from getting to the vendor AND to the blackhat community.
we've said it before, and I'll say it again......why don't they just concentrate on fixing the browser and making it secure, rather than introducing unwanted crap features and facelifts, and messing around with a mobile phone OS that nobody wants and noone is going to use?
the world needs a secure browser thats independent of the major companies (aka scam merchants). It doesn't need a new phone OS that isn't going to be used by anyone....
Yup. Despite lots of clever people pointing this out to him at the time, Eich managed to get that completely the wrong way round - and practically single handedly fucked the internet in the process. Considers himself an "evangelist" and bent Mozilla over for Google in exchange for funding his worthless braindead whimsy. The twat. "Privacy/security isn't exciting - no-one cares." Eich! The worst thing that ever happened to the web.
It doesn't need a new phone OS that isn't going to be used by anyone....
Somehow reminds me of that famous quote from some fella who worked at IBM.. Something about 6 computers IIRC..
There was a time when no one would've considered Windows to be useful. And who would ever have wanted what Android offers now just 10 years ago?
I haven't seen FF's phone OS and may never see it. But want better security? Maybe a separate OS "independent of the major companies" is worth someone looking at. Certainly, with the spying and data pinching done by MS and Google, I would welcome anyone who doesn't go down their path.
the problem is that any new phone OS, however clean, is going to get "modified" by the phone manufacturers to provide back doors, thus rendering any security initiative pointless.
It doesn't matter how good the base software is, the phone companies will compromise it, making it totally pointless
particularly when fixing a known bug takes over 300 days!
"I hope it gets you over your misinformation regarding http2"
Actually it just repeats the points that are debunked everywhere else. What you call "misinformation" is actually a reply to the arguments brought forward in articles like this one.
I mean if I pick a part from that article at near random, "The HTTP 1.1 request sizes have actually gotten so large over time so they sometimes even end up larger than the initial TCP window"
Yes that's correct, but the problem here is that this is because of abuse. People put more and more junk into those headers because they are trying to implement things like state into a stateless protocol. If you want a session use Websockets instead of cramming huge cookies into your HTTP headers.
Then there's stuff like Multiplexing connections... which may sound like a good idea until you realize that that means that you somehow have to prioritize the individual requests at the server. Browsers can do that rather well, as they know how to display the contents so they can prefer downloading the pictures you should actually see at the moment. This is _much_ harder on the server side of things.
And even in the most favourable tests, HTTP2 is just a bit faster, given that it requires lots of code even for the most minimal implementation, it's simply not worth it. And using libraries won't cut it as we have seen with TLS.
Christian is right - nearly a year to fix a security related bug *is* too long. Even if the privileged Bugzilla account had been secure, a bug can be discovered by more than one person.
If they can't fix it within a sensible timescale they should assume it is being exploited and at least warn the user community. We can argue what sensible is, but it is much less than a year.
I appreciate that letting someone else find the bugs and then peeking at their results is a slightly simpler way of finding them, or at least the ones that they have found, but since the Firefox source is available to anyone anyway and almost certainly contains many more bugs that haven't made it into the private part of their Bugzilla database yet, this doesn't strike me as a biggie.
Also, wouldn't it be easier to contribute features to the product and "accidently" leave subtle flaws in. Of course, most wouldn't make it into production and those that did might only remain open for a few months before someone else spots them, but I imagine that a deliberate bug could be made harder to find than a truly accidental one.
I suspect that it is quicker to find the bugs with a fuzzer than by looking through the source, and you don't really need the source code for that. You can spend an hour meticulously going through just one smallish function and the chances are fifty thousand to one that you will find anything exploitable. Easier to set up a farm running fuzzers and then let that do all the work.
I still feel a bit safer using FF and like its features better. At least Mozilla came clean with what happened. Just because there aren't glaring headlines about IE, Chrome, Safari, etc. re. the same thing, it's extremely likely that it's just not been discovered yet or has been swept under the rug.
The other day I passed Mozilla HQ on the Muni line and thought, "How cool ..... they're right here". AND YET(!!!) with all of the security tech 'right here', you let your priv accts get pwn'd
WHAT IS WRONG WITH The Valley and The Bay? It's obvious that fucktard mgmt gets in the way, but Goddamn it. We're the ones that know what is going on. Why aren't the admin accounts under strict control.
You have enterprise pwd mgmt orgs (that most other orgs have invested) like Cyberark and Thycotic and others, and they sit, sucking up power - DOING NOTHING!!!!!! Like they're Skunkworks or something.
We have Thycotic (not sure how they get as much play as they do (as compared to Cyberark)), and people act surprised when I mention that we can rotate RADIUS password to comply with our pwd policy - like it is new news. 90% of CISOs, 80% of CIOs and almost 100% of Dirs of Infosec should be FIRED!!!!!
Not all bugs with an indicated security dimension are exploitable - that having been said, you don't work on writing an exploit, you close the hole.
There's a problem however if by doing so, lots of people's favourite web site doesn't work with your browser. Not because the site uses the hole (you hope) but because the site doesn't work for whatever reason when you change the code to disable (thing) outright.
So, this can take a long time to resolve.
I'm writing hypothetically.
Biting the hand that feeds IT © 1998–2019