Introducing Firefox Monitor, Helping People Take Control After a Data Breach
blog.mozilla.org
blog.mozilla.org
Right now Firefox Lockbox is not available everywhere and is not out on Android yet. That also would need to change fast for this to be adopted widely.
They're trying to get rid of it. Writing more of it as anything but a stopgap would be counter to their current goals.
They hid the decision to remove browser application extensibility behind 'web extensions' and refuse to acknowledge how they screwed over devs that relied upon it, and have a significant failure of the potentials of browser technology. There is a big difference between an extension in a browser, and extending the browser itself.
If there was a browser right now that could have its UI replaced in a standard way and updated just like the normal browser, most electron apps would not be required. It'd be far safer, performant, and would solve a lot of the big problems in the web app as a desktop app ecosystem. However, that's not their market. All browsers are in this for market.
This is not a new development either. Look at the JSApi for SpiderMonkey and they'll purposefully break compatibility on any and all versions. They don't understand what an API means. You can look at WebAssembly, too. There is no engine you can use to run independent wasm from mozilla, even though mozilla are the ones who pushed the spec which includes many claims outside of browser usage that Mozilla never persued.
At the end of the day Mozilla does not deliver on their ideas or technology unless it's firefox or something related. If you ever want to use 'web technology' in your own applications you will end up using Webkit. Which I think is super funny given that's Apple.
https://wiki.qt.io/QtWebEngine
I think CSS is pretty great, but I would like to see something like Sass/Jade/Mustache/etc rendered client side. If browsers would focus less on JavaScript, and more on improving markup languages under the core Unix Philosophies, then we wouldn't be where we are today. I hope eventually they will let containers or the API in Linux handle permissions/security, and improve that. Android has it's own issues with Java. With Vulkan, Linux is ready for a very efficient and ever-evolving scalable solution. Heck, a modern UI scripting framework for the terminal similar to kmscon would be incredible. No reason the terminal can't support markup and assets. My vision is something similar, but definitely more friendly than DolDoc:
[0] https://testpilot.firefox.com/experiments/firefox-lockbox/
Yes, I am aware that the breached data is already floating around on the internet, but it isn’t so convenient to consult it as on this website (or Have I Been Pwned?). These sites ought to require that a person prove they own that e-mail address before returning data concerning it.
https://www.troyhunt.com/have-i-been-pwned-opting-out-vtech-...
As for the second paragraph, it is trivial to grab a copy of all this data. The only ones that are hard to get are the ones you (or even anyone) haven't been told about yet.
As mentioned in another comment, you can opt-out of the HIBP database here: https://haveibeenpwned.com/OptOut
I also filed https://github.com/mozilla/blurts-server/issues/466 to consider making this visible in the Monitor UI.
I suppose it makes sense as a Mozilla project, but what does it have to do with the browser?
The browser is also the main way users interact with the web, so associating this web security project with Mozilla's browser's brand seems fine to me.
For another thing, the "Firefox" name is more widely-recognized than the "Mozilla" name.
Those are my thoughts as well. Mozilla is like Google, and Firefox is like Chrome. If Google had introduced such a service, it would have be called Google Monitor, not Chrome Monitor. Because it has nothing to do with a web browser.
Two additional steps I've read somewhere a few days ago is that the Firefox is going to flag breached sites somehow upon visit (don't know the specifics), and that Firefox Sync users will get alerts whenever they appear in HIBP.
While they are not primary leaker, Firefox Monitor providing the information this way is disheartening.
Most people in my network do not know about Have I Been Pwned (the source of the scan data), but they _do_ know about Firefox.
This brand recognition and resulting media impact will spread my bits of personal information wider and into my direct network of contacts.
I'd much prefer a qualification requirement. Make me click a link in an email you send when I ask for information about an email address instead of providing unfettered access to a list of (breached) services the email was used for over the past decade.
I expect better from Mozilla/FF.
With tools like this your grandma will find out where you’re registered to.
An easy fix would be to deliver the results to my email.
As mentioned in another comment, you can opt-out of the HIBP database here: https://haveibeenpwned.com/OptOut
I also filed https://github.com/mozilla/blurts-server/issues/466 to consider making this visible in the Monitor UI.
Slightly related, why the doesn’t Firefox offer to generate strong passwords like Safari does?
They don't support the gmail alias issue though (https://haveibeenpwned.uservoice.com/forums/275398-general/s...)
"This is major because Firefox has an install base of hundreds of millions of people which significantly expands the audience that can be reached once this feature rolls out to the mainstream. [...] I'm really happy to see Firefox integrating with HIBP in this fashion, not just to get it in front of as many people as possible, but because I have a great deal of respect for their contributions to the technology community. [...] They've also been instrumental in helping define the model which HIBP uses to feed them data without Mozilla disclosing the email addresses being searched for."
(Put another way, "What stops this database of breaches from becoming another entry in the database of breaches?")
I understand Troy assessment on the issue but would be great nonetheless.
Just trolling here, don't pay attention.
function isValidEmail(e) {
const b = /^(([^<>()[\]\\.,;:\s@"]+(\.[^<>()[\]\\.,;:\s@"]+)*)|(".+"))@((\[[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\])|(([a-zA-Z\-0-9]+\.)+[a-zA-Z]{2,}))$/;
return b.test((e + "").toLowerCase())
}
1. The valid email address n@ai (which used to be the real maintained email address of Ian Goldberg) doesn't pass this function. People can put DNS records on TLDs.2. You're calling toLowerCase() yet the regex is already case-agnostic.
If you're going to attempt email address validation, either go all out[1], or just use isValidEmail=(e)=>~e.indexOf("@")
Honestly, if you decide to use a email like n@ai you already know what to expect. Most services wont let you sign up, And even if they do most will likely incur errors in the application when you attempt to do things.
In reality, while it may be 'in spec' to use such a email, we can all hope that edge cases that allow it are changed and the legacy 'rules' that allowed it in the first place phased out completely.
So, in practice in the 'real world'- n@ai is not a valid email address and never will be. If I create a web application you can bet your bottom dollar I wont allow it and I will create less work for myself by doing so.
In fact, I bet many of them are so frustrated with the errors of nothing working that they dont even attempt to sign up for things with the email most times.
https://twitter.com/errbufferoverfl/status/10197667755614453...
And I don't mind at all. Many of the things you can technically do in an email address are needless complexity that shouldn't be encouraged.
This reminds me of that story of a Chinese man unable to get registered at the bank because the computer systems don't have a character required to write his name.
Sure, "it only affects a small amount of people", but it shouldn't be that hard to just flag strange but valid emails with "your email looks strange, check it again and tick this box if you're 100% sure you typed it right" instead of outright refusing to work. The check box doesn't even need to be interpreted server side, this can be done in one or two lines of javascript.