Author Topic: Firefox Flaw  (Read 1322 times)

0 Members and 1 Guest are viewing this topic.

Offline Night Hammer

  • I Can't FRED
  • 29
  • You'll shoot your eye out...
http://news.yahoo.com/s/pcworld/120756


in case yall hadnt seen this...
Stop... Hammertime :hammer:

 

Offline Mongoose

  • Rikki-Tikki-Tavi
  • Global Moderator
  • 212
  • This brain for rent.
    • Steam
    • Something
At least it doesn't take them six months and fifty security patches to fix bugs. :p

 

Offline Clave

  • Myrmidon
    Get Firefox!
  • 23
    • Home of the Random Graphic
Lies!  Firefox is indestructable!
altgame - a site about something: http://www.altgame.net/
Mr Sparkle!  I disrespect dirt!  Join me or die!  Could you do any less?

 

Offline Ransom

  • M. Night Russel
  • 210
  • It will not wait.
    • Rate of Injury
Oh hell. Paul's going to be all over this one.

 
I'm not worried about this. The exploit requires to user to do something to activate it.

Which means that those of us who actually know a damned thing about the system arne't going to be caught so easily...

Under IE, there're too many loopholes that allow automatic activation of exploit code.
'And anyway, I agree - no sig images means more post, less pictures. It's annoying to sit through 40 different sigs telling about how cool, deadly, or assassin like a person is.' --Unknown Target

"You know what they say about the simplest solution."
"Bill Gates avoids it at every possible opportunity?"
-- Nuke and Colonol Drekker

 

Offline Taristin

  • Snipes
  • 213
  • BlueScalie
    • Skelkwank Shipyards
It'll be fixed shortly.
Freelance Modeler | Amateur Artist

 

Offline n00by

  • 24
Unlike those IE exploits...

 

Offline Annorax

  • 27
  • Wistful General
    • Steam
At least I'm safe... no Java VM installed. :)

 

Offline aldo_14

  • Gunnery Control
  • 213
That's the beauty of Firefox, really; even when holes do pop up, they get fixed and the client updated hella quick thanks to good old open-source.

 

Offline IceFire

  • GTVI Section 3
  • 212
    • http://www.3dap.com/hlp/hosted/ce
The benefit of Firefox is that it is invulernable.  The benefit is:
1) Separate layer from the OS (IE is integrated into the OS)
2) Bugs are found, fixed, and then released promptly
- IceFire
BlackWater Ops, Cold Element
"Burn the land, boil the sea, you can't take the sky from me..."

 

Offline ZylonBane

  • The Infamous
  • 29
Quote
Originally posted by Annorax
At least I'm safe... no Java VM installed. :)
And that has what to do with a JavaSCRIPT exploit? :rolleyes:
ZylonBane's opinions do not represent those of the management.

 

Offline Annorax

  • 27
  • Wistful General
    • Steam
Quote
Originally posted by ZylonBane
And that has what to do with a JavaSCRIPT exploit? :rolleyes:


I keep javascript turned off? No Java + No JS = immune to a vast majority of the crap out there

 

Offline ZylonBane

  • The Infamous
  • 29
Sigh.

Java and JavaScript are not the same thing. Not even close. So saying you're safe from these bugs because you don't have Java installed is just ignorant.
ZylonBane's opinions do not represent those of the management.

 

Offline aldo_14

  • Gunnery Control
  • 213
Quote
Originally posted by IceFire
The benefit of Firefox is that it is invulernable.  The benefit is:
1) Separate layer from the OS (IE is integrated into the OS)
2) Bugs are found, fixed, and then released promptly


(diversion alert!)

Strangely (or not) RE 1 I was just thinking that today with regards to Windows - they've really ****ed up that Os by trying to make it more than an Os and cater to the lowest common denominator.  If MS simply made a thin, efficient (god forbid) OS with minimal features, they not only wouldn't have half the security & interactivity problems they now have, they also wouldn't have to assume as much responsibility for the myriad security holes.  I've read recently about Ms considering denying pure socket access (or similar) to programs to try and polyfilla the holes they present - actually denying the programs operating on the computer access to a facility when IMO it's the OS' job to facilitate access.

At the moment they're seemingly doing neither; they have this bloated Os with non-Os related features, and rather than take the more obvious step (given the way windows has seemingly evolved, at least on the home PC) of fully integrating security/etc control as part of the Os, they're spinning it off onto yet another layer of applications.... to me the obvious and sensible way is either to incorporate all this into the OS itself as a proper security protection (acknowledging it'll **** up access to OS functions for a number of 3rd party programs in the meantime), or simply specifically neglect areas of security (viruses, for example) as being the responsiblity of the user.

At the moment they seem to do neither; not giving the user any responsibility, yet not actually committing to proper fixes but more sticky-tape over an amputed limb type solutions.  At least, that's my perspective.....

 

Offline aldo_14

  • Gunnery Control
  • 213
Quote
Originally posted by Annorax


I keep javascript turned off? No Java + No JS = immune to a vast majority of the crap out there


Javascript is just a name that was chosen to cash in on the popularity of Java at the time of development; offhand, Javascript was by Netscape (the actual Java language was by Sun; albiet it did spin out of a language for animated internet images, it's no relation), JScript was a competing MS equivalent, and ECMA262Script is what is colloquially known (now) as Javascript and was set by international standards (but not adhered to...).

The Java VM uses a sandboxing model specifically to try and prevent malicious access by remote code; principally by shoving it (code containing potentially dangerous methods of some description) into an access denied sandbox that stops it accessing files or operations upon your machine. Offhand there are 3 main ways it does this... I can only remember the one (bytecode verifier) at the mo.

anyways, Java has nothing to do with JavaScript, JScript, ECMA262, etc.

 

Offline Night Hammer

  • I Can't FRED
  • 29
  • You'll shoot your eye out...
you cant just goto tools/options/webfeatures and turn off javascript no biggy
Stop... Hammertime :hammer:

 

Offline ZylonBane

  • The Infamous
  • 29
Quote
Originally posted by aldo_14
the actual Java language was by Sun; albiet it did spin out of a language for animated internet images
Umm, no.

History of Java
ZylonBane's opinions do not represent those of the management.

 
Too bad there are quite a few sites out there that you need JS to navigate. >.<

 

Offline aldo_14

  • Gunnery Control
  • 213
Quote
Originally posted by ZylonBane
Umm, no.

History of Java


[q]
 The team returned to work up a Java technology-based clone of Mosaic they named "WebRunner" (after the movie Blade Runner), later to become officially known as the HotJavaTM browser. It was 1994. Daily, momentum behind the new vision grew. WebRunner was just a demo, but an impressive one: It brought to life, for the first time, animated, moving objects and dynamic executable content inside a Web browser. That had never been done.
[/q]

tis what i was thinking of.

 

Offline n00by

  • 24
1.0.4 is out! (w00t!)

Download
Changes

For those who don't want to read the changelog - it basically fixes the last two security flaws discovered.

Go, Firefox!