Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 10-02-2006, 11:00 PM   #1
FrameShifter
Confirmed User
 
Join Date: Jan 2005
Posts: 1,120
Firefox Security Flaw "Impossible To Patch"

Hackers detail Firefox flaw, calling the browser a "complete mess"
Hacker conferences are so much fun. Case in point: San Diego's ToorCon conference on Saturday, when engineers Mischa Spiegelmock and Andrew Wbeelsoi (what names!) took the stage and called the increasingly popular Firefox Web browser a "complete mess." The duo detailed to the world a security flaw in Firefox, which afflicts the browser's handling of Javascript. As if that weren't painful enough, Spiegelmock and Wbeelsoi also said the glitch was probably "impossible to patch."

"Internet Explorer, everybody knows, is not very secure," said Spiegelmock. "But Firefox is also fairly insecure."

Naturally, Firefox officials were none too happy, reports CNET. The hard-working people from the Mozilla Foundation, which manages Firefox, had hoped for a bit more discretion. Publicizing a Firefox insecurity hurts the browser's image as the safe, spam-free alternative to Microsoft's Internet Explorer. "I think it is unfortunate because it puts users at risk, but that seems to be their goal," groused Window Snyder, head of security for Mozilla.

Digg readers are having none of the Firefox bashing. When one posted: "It makes you wonder why people always say FF is the best browser," one reader was quick to fire back: "Maybe because each Firefox flaw is worthy of a news post, while Internet Explorer has so many that no one bothers to write about them anymore."

http://money.cnn.com/blogs/browser/i...79456257268446
__________________
FrameShifter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-02-2006, 11:02 PM   #2
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
You'll find this due to the Netscape licensing for the Javascript engine. It's a hodgepodge of shit, and they were not allowed to make changes to it. AFAIK, they've been working on a complete code replacement.. at least, that's what the site has said for the past year or so..
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-02-2006, 11:02 PM   #3
madawgz
8.8.8.8
 
madawgz's Avatar
 
Industry Role:
Join Date: Mar 2006
Location: Noordermarkt
Posts: 30,509
whats the cliff notes?
__________________
TAEMDLRMSKRJIXMRLSMRJ.
madawgz is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-02-2006, 11:03 PM   #4
GrouchyAdmin
Now choke yourself!
 
GrouchyAdmin's Avatar
 
Industry Role:
Join Date: Apr 2006
Posts: 12,085
Quote:
Originally Posted by madawgz
whats the cliff notes?
lol open source lol
__________________
GrouchyAdmin is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-02-2006, 11:07 PM   #5
marzzo
Confirmed User
 
marzzo's Avatar
 
Industry Role:
Join Date: May 2002
Posts: 2,134
Eh, Toorcon kicks ass (ya know I love ya G ;) but they're Mac-biased.

Not that there's anything wrong with that, of course
__________________
4 5 zero - 2 2 - nine nine nine
marzzo is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 12:35 AM   #6
squishypimp
PostMaster General
 
Join Date: Aug 2006
Posts: 10,781
glad i use IE!
__________________
squishypimp is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 12:41 AM   #7
L-Pink
working on my tan
 
L-Pink's Avatar
 
Industry Role:
Join Date: Mar 2005
Location: Florida/Kentucky
Posts: 39,151
Quote:
Originally Posted by squishypimp
glad i use IE!
remember, open EVERY email
L-Pink is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 12:48 AM   #8
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by L-Pink
remember, open EVERY email
dont use i.e. for email , dont use firefox for browsing ... problem solved..
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 12:52 AM   #9
Superterrorizer
Confirmed User
 
Join Date: Sep 2003
Posts: 509
Impossible to patch doesn't mean impossible to fix. Quite easilly fixed/plugged in fact.
Two options off the top of my head:

1. Turn off javascript
2. Install the NoScript plugin and let only trusted sites execute js on your machine.
Superterrorizer is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 08:51 AM   #10
SmokeyTheBear
►SouthOfHeaven
 
SmokeyTheBear's Avatar
 
Join Date: Jun 2004
Location: PlanetEarth MyBoardRank: GerbilMaster My-Penis-Size: extralarge MyWeapon: Computer
Posts: 28,609
Quote:
Originally Posted by Superterrorizer
Impossible to patch doesn't mean impossible to fix. Quite easilly fixed/plugged in fact.
Two options off the top of my head:

1. Turn off javascript
2. Install the NoScript plugin and let only trusted sites execute js on your machine.
thats gonna make for some awfully boring browsing
__________________
hatisblack at yahoo.com
SmokeyTheBear is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 08:56 AM   #11
DamageX
Marketing & Strategy
 
DamageX's Avatar
 
Industry Role:
Join Date: Jun 2001
Location: Former nomad
Posts: 14,293
Quote:
Originally Posted by SmokeyTheBear
thats gonna make for some awfully boring browsing
Using the NoScript plugin here and haven't had a single problem, nor does it annoy me that it blocks shit. My work is much easier now, thanks to it.
__________________
Whitehat is for chumps

If you don't do it, somebody else will - true story!
DamageX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 08:58 AM   #12
Ebola
Confirmed User
 
Join Date: Aug 2004
Posts: 207
So FF's head of security's name is "Window"?
Ebola is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 09:02 AM   #13
Tuga
Confirmed User
 
Tuga's Avatar
 
Join Date: Nov 2002
Location: Portugal
Posts: 7,678
Safari rocks.
__________________

Go Fuck Yourself!
ICQ 101411627
Tuga is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 09:08 AM   #14
drjones
Confirmed User
 
Join Date: Oct 2005
Location: Charlotte, NC
Posts: 908
I remember back when Firefox (aka Pheonix) was released and had intended to be a "lightweight" bloat-free version of Mozilla. Supposed to be light and snappy, small and functional.

Even though it is incredibly useful (but only after adding the appropriate extensions), FF has long surpassed the bloated sluggishness of the original Mozilla. Seems like its strayed far from its original goals.
__________________
ICQ: 284903372
drjones is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 10:18 AM   #15
drjones
Confirmed User
 
Join Date: Oct 2005
Location: Charlotte, NC
Posts: 908
Turns out this whole thing was a hoax anyways.

http://digg.com/security/Claimed_Sec...ox_Just_A_Joke
__________________
ICQ: 284903372
drjones is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 10-03-2006, 10:31 AM   #16
RawAlex
So Fucking Banned
 
Join Date: Oct 2003
Location: In a house.
Posts: 9,465
At the end of the day, most viruses and security holes take advantage of IE because most of the surfers HAVE and USE IE. By using Firefox (or Opera) you are putting yourself in a much smaller group, a group much less likely to get targetted to start with.

That the so-called security hole is bullshit just makes me smile

Alex
RawAlex is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.