LWN.net Logo

Firefox extension vulnerabilities

Firefox extension vulnerabilities

Posted Aug 27, 2009 13:14 UTC (Thu) by Trou.fr (subscriber, #26289)
Parent article: Firefox extension vulnerabilities

The problem is not that extensions should be reviewed extensively. The problem is that mozilla *really* should consider a security model with more granularity than "Internet" and "Trusted".

This and the fact that almost NO extension on AMO is signed ! As we know it is usually quite easy to compromise someone's email account and use it to recover the credentials to upload a new version of the extension on AMO, but with malicious code...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds