{"id":5801,"date":"2004-07-15T14:05:50","date_gmt":"2004-07-15T21:05:50","guid":{"rendered":"http:\/\/hill-kleerup.org\/blog\/wp\/2004\/07\/15\/why-firefox.html"},"modified":"2004-07-15T14:05:50","modified_gmt":"2004-07-15T21:05:50","slug":"why_firefox","status":"publish","type":"post","link":"https:\/\/hill-kleerup.org\/blog\/2004\/07\/15\/why_firefox.html","title":{"rendered":"Why Firefox?"},"content":{"rendered":"<p>When faced with suggestions from everyone from CERT to Slate to stop using IE, it certainly raises (or should raise) some questions in folks&#8217; minds about whether that&#8217;s good advice.  And the standard response (which I can say with some authority, as it was one of my responses) is:  <em>Why is Firefox\/Mozilla any different?  Any browser is going to have security holes here and there.<\/em><\/p>\n<p>True.  There are some <a href=\"http:\/\/stupidevilbastard.com\/index\/seb\/dave_asks_the_question_is_internet_explorer_really_so_bad\/\" target=\"_blank\">architectural issues<\/a> that come into play as well, but if every hacker with spare cycles on his\/her hands put their mind toward attacking Firefox, they would find bits to exploit.<\/p>\n<p>Society does a lot to keep fires from starting in cities.  Building codes, safety programs, sprinkler systems, stuff like that.  We&#8217;re better off for them, certainly, but accidents (and arsonists) still happen.  In which case, what&#8217;s also key to dealing  with fires is how you fight them when they come up.<\/p>\n<p>Last week, a vulnerability was discovered in Mozilla\/Firefox.  It&#8217;s actually present in IE, too, and there are reasons why it happened, but it resulted in a lot of crowing from IE boosters about how, <em>See, we told you that stuff is vulnerable, too.<\/em><\/p>\n<p>So what did the Firefox\/Mozilla folks do about it?  <a title=\"BlogSac :: Mozilla Vulnerability Timeline\" href=\"http:\/\/www.sacarny.com\/blog\/index.php?p=104\">This.<\/a><\/p>\n<p class=\"block\"><strong>July 7 &#8211; 13:46 GMT<\/strong> &#8211; Keith McCanless files a bug in the Bugzilla Database reporting a new vulnerability. It exploits the windows \u201cshell:\u201d handler and allows a malicious web page to execute a program on a client\u2019s computer (The program has to already be present on the computer). McCanless notes that the bug is \u201cBOTH a security concern and a DOS,\u201d since if the link points to a nonexistent file, it makes the Mozilla browser spawn off endless amounts of new windows. The bug is marked private since it is security-related; only developers with proper clearance can see it. [&#8230;]<br \/>\n<strong>July 7 &#8211; 18:16 GMT<\/strong> &#8211; Mozilla developer \u201ctimeless\u201d creates patch closing vulnerability. He posts the patch on the Bugzilla Database so that other developers can approve it. (source) <em>The bug had been known to the world for a matter of hours before a patch was created to fix it<\/em> [&#8230;]<br \/>\n<strong>July 8 &#8211; 03:23 GMT<\/strong> &#8211; A new branch is created, out of which developers will build new versions of Firefox and Thunderbird. The patch is checked into this branch. <em>In less than 11 hours after the vulnerability was reported to the public, all up-to-date Mozilla code was secure <\/em>[&#8230;]<br \/>\n<strong>July 8 &#8211; 16:13 GMT<\/strong> &#8211; Firefox XPI \u201cadd-on\u201d package placed on FTP site. Once again, this fixes the bug without making users download a whole new setup file.  <em>Before the vulnerability was known to the public for 24 hours, Mozilla had released updated versions of its poducts and patches for users running previous versions<\/em> [&#8230;]<br \/>\n<strong>July 8 &#8211; 21:57 GMT<\/strong> &#8211; Asa Dotzler checks in an official Mozilla.org notice of the vulnerability and the fix.  <em>In the course of less than a day and a half of public vulnerability, all Mozilla versions were updated, a security note was released, and new downloaders were secure by default.<\/em><\/p>\n<p>Now, nothing&#8217;s perfect, and in reality <a href=\"http:\/\/www.sacarny.com\/blog\/index.php?p=105\" target=\"_blank\">the issues surrounding this problem have been known and under discussion in the Mozilla<\/a> world for some time.  No actual exploit had been detailed, but nothing had yet been done.  <\/p>\n<p class=\"block\">The Mozilla developers did a great job handling this extremely critical security hole. After getting word of an exploitable hole, they pushed out a fix in less than 36 hours. Applause. The system worked.<br \/>\n\u2026but not perfectly. The critical bug got fixed in a jiffy, but it was actually the result of known weaknesses in the way Mozilla handles external protocol handlers. These weaknesses came up many times on Bugzilla, starting around 2 years ago. The developers quelled some concerns by implementing an insecure protocol blacklist, but this solution did not fix everything. What I propose here would not have plugged this security hole entirely, but it would have mitigated it to a great deal. I can\u2019t see how the Mozilla team could have prevented this problem entirely, but had they handled several known bugs, it could have been a minor issue.<\/p>\n<p>The disadvantage you have with an open source project like Mozilla is that, in order to convince the developers to do something about it (assuming you don&#8217;t do it yourself), you need to convince them that it&#8217;s <em>technically <\/em>important.  With Micro$oft, in order to convince it to do something, you have to show that it&#8217;s <em>financially <\/em>important (i.e., that they should mobilize the manpower necessary to make the change &#8212; which has more profound impact on M$ in this case because of the tight integration between IE and the OS.  Hoisted on their own petard, they are &#8230;<\/p>\n<p>Anyway, it was an impressive effort, and kudos to the folks at the Mozilla Foundation involved in this.<\/p>\n<hr width=\"75%\"\n\n\n<p>Definition of terms, as I understand it (and so that some of the above isn&#8217;t completely opaque):  <strong>Mozilla <\/strong>is an open source project spun off from Netscape, including a browser and an e-mail client, and a few different kitchen sinks, too.  It&#8217;s at version 1.7 at this point.<\/p>\n<p>A decision was made, after Mozilla went &#8220;live,&#8221; to break out the components into their own stand-alone products.  The browser has become <s>Phoenix<\/s> <s>Firebird<\/s> <strong>Firefox <\/strong>, and is at version 0.9.2 (not yet &#8220;officially&#8221; released).  The e-mail client has become <strong>Thunderbird <\/strong>(about which I know less, though I may soon know more).<\/p>\n<p>So you can use &#8220;Mozilla&#8221; to refer both to Mozilla and Firefox and\/or Thunderbird, or you can use the individual project names, or you can use lots of slashes between the names to be inclusive.  I think I managed all of the above above.<\/p>\n<p><small>(via <a href=\"http:\/\/www.boingboing.net\/2004\/07\/15\/mozilla_bugsquashing.html\" target=\"_blank\">BoingBoing<\/a>)<\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>When faced with suggestions from everyone from CERT to Slate to stop using IE, it certainly raises (or should raise) some questions in folks&#8217; minds about whether that&#8217;s good advice&#8230;.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_seopress_titles_title":"","_seopress_titles_desc":"","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[3],"tags":[],"class_list":["post-5801","post","type-post","status-publish","format-standard","hentry","category-blogging"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":6733,"url":"https:\/\/hill-kleerup.org\/blog\/2005\/01\/11\/firefox_tweaks.html","url_meta":{"origin":5801,"position":0},"title":"Firefox tweaks","author":"***Dave","date":"Tue 11-Jan-05 9:42am","format":false,"excerpt":"Two interesting Firefox bits: \"Secrets of Firefox 1.0\" shows how to look under the \"about:config\" hood and tweak stuff. Not for the faint of heart, but some good stuff they...","rel":"","context":"In &quot;My Computer&quot;","block_context":{"text":"My Computer","link":"https:\/\/hill-kleerup.org\/blog\/category\/my-computer"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":6244,"url":"https:\/\/hill-kleerup.org\/blog\/2004\/10\/04\/spell_check_in.html","url_meta":{"origin":5801,"position":1},"title":"Spell check in Firefox","author":"***Dave","date":"Mon 4-Oct-04 8:31am","format":false,"excerpt":"As noted before, Spellbound still rocks as a spell checker for Firefox. Except for its checking of HTML tags. And the fact that \"Firefox\" is not in its baseline English...","rel":"","context":"In &quot;My Computer&quot;","block_context":{"text":"My Computer","link":"https:\/\/hill-kleerup.org\/blog\/category\/my-computer"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":15253,"url":"https:\/\/hill-kleerup.org\/blog\/2009\/07\/20\/my-firefox-extensions.html","url_meta":{"origin":5801,"position":2},"title":"My Firefox Extensions","author":"***Dave","date":"Mon 20-Jul-09 8:17am","format":false,"excerpt":"I'm mapping out my course for migrating to my new PC. Yeesh. Lots of stuff, some of which will be kind of ugly to move. One of the first things will be installing Firefox. I'm currently on 3.5, and plan to use it instead of the IE7 (auto-updated to IE8)\u2026","rel":"","context":"In &quot;Blogging - Technical&quot;","block_context":{"text":"Blogging - Technical","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/blogging-technical"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":6631,"url":"https:\/\/hill-kleerup.org\/blog\/2004\/08\/11\/firefox_glitch.html","url_meta":{"origin":5801,"position":3},"title":"Firefox glitch?  Well, no, looks like PEBCAK","author":"***Dave","date":"Wed 11-Aug-04 8:37am","format":false,"excerpt":"(I need to add a new category -- maybe \"MyComputer\") This morning, Firefox wouldn't start up. Ran just fine last night. Everything closed down without a sweat. But this morning,...","rel":"","context":"In &quot;My Computer&quot;","block_context":{"text":"My Computer","link":"https:\/\/hill-kleerup.org\/blog\/category\/my-computer"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":14132,"url":"https:\/\/hill-kleerup.org\/blog\/2009\/03\/12\/amazon-one-click-firefox-tabs-hilarity.html","url_meta":{"origin":5801,"position":4},"title":"Amazon One-Click + Firefox Tabs = Hilarity!","author":"***Dave","date":"Thu 12-Mar-09 7:41am","format":false,"excerpt":"It appears that Amazon has changed something about its One-Click purchase exit pages. Because when they reload (e.g., if they were on an unclosed tab in Firefox when close and open it back up again), they repeat the purchase. That's ... unfortunate. Unless you plan on giving a particular book\u2026","rel":"","context":"In &quot;Hi-Tech&quot;","block_context":{"text":"Hi-Tech","link":"https:\/\/hill-kleerup.org\/blog\/category\/hi-tech"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]},{"id":25408,"url":"https:\/\/hill-kleerup.org\/blog\/2012\/01\/13\/an-interesting-perspective-on-chrome-and-firefox.html","url_meta":{"origin":5801,"position":5},"title":"An interesting perspective on Chrome and Firefox","author":"***Dave","date":"Fri 13-Jan-12 11:07pm","format":false,"excerpt":"If Google is competing in the browser market it Chrome, then why is it signing big-money agreements with Mozilla\/Firefox? Here's an interesting and (if you consider where Google actually gets its revenue from) believable answer. #ddtb Embedded Link Chrome Engineer: Firefox Is A Partner, Not A Competitor Google and Firefox\u2026","rel":"","context":"In &quot;~PlusPosts&quot;","block_context":{"text":"~PlusPosts","link":"https:\/\/hill-kleerup.org\/blog\/category\/blogging\/plusposts"},"img":{"alt_text":"","src":"","width":0,"height":0},"classes":[]}],"_links":{"self":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts\/5801","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/comments?post=5801"}],"version-history":[{"count":0,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/posts\/5801\/revisions"}],"wp:attachment":[{"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/media?parent=5801"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/categories?post=5801"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hill-kleerup.org\/blog\/wp-json\/wp\/v2\/tags?post=5801"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}