cf https://twitter.com/swiftonsecurity/status/62840155490772582...
cf https://twitter.com/swiftonsecurity/status/62840155490772582...
When you try to open a file with Firefox it will first try to map the file to a mimetype using the ExternalHelperAppService (https://developer.mozilla.org/en-US/docs/How_Mozilla_determi...). In case a mimetype is found, a file dialog is shown so you can open the file with the right application, in case it is not, the contents of the file will be displayed in the browser. In this case my OS provided the ExternalHelperAppService with a mimetype for one of my public keys with the .pub file extension: application/vnd.ms-publisher. Of course that's not the correct mimetype for the public key file, but that's basically what saved me by showing a file dialog because it found a mimetype. All other files had no file extension so no mimetype was found.
I also discovered that my private keys were all encrypted with a passphrase so even though they have been compromised it was not as bad as I initially believed.
An adblocker doesn't impact usability (in most cases, it improves it significantly, through lower page load times and less space occupied by non-content), but prevents the vast majority of malvertising. Blocking all Javascript blocks all of them, but makes the modern web nearly unusable.
But they cannot ask my conscience to open myself up to security issues because otherwise it impacts their income.
(note that I have read the rest of the thread and am aware that simply running an adblocker wouldn't have prevented this exploit)
(second note/disclaimer is that I do run µBlock, for the personal reason that I feel they also cannot ask my conscience to open my attention to energy-draining distractions because otherwise it impacts their income)