Security vulnerabilities fixed in Firefox 67.0.4 and Firefox ESR 60.7.2
mozilla.org
mozilla.org
Link to the first fix: https://hg.mozilla.org/releases/mozilla-release/rev/99a829d2...
Link to the second fix: https://hg.mozilla.org/releases/mozilla-release/rev/ea5154be...
[1]: https://www.mozilla.org/en-US/firefox/67.0.3/releasenotes/
[2]: https://www.mozilla.org/en-US/firefox/67.0.4/releasenotes/
Perhaps in particular for Firefox, which has had the sandbox for less time?
Would love to hear some expert opinions. I can't derive much from this since I don't personally see any trends.
Anyone who drives should spend 5 minutes a week watching dashcam videos.
Edit: Clarification, I was asking a question, not trolling.
Only few components of Firefox are written in Rust. Servo has no privileged Javascript per design choice, while it does have some components written in C/C++ (mostly taken from Firefox).
Reporter Coinbase Security
Impact high
Description Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer.
References Bug 1559858
Also, a bit less concerning to me, the Debian package of `firefox-esr` still hasn't been released, as I type this, hours later.
Of course this is a tricky problem, but should there be more coordination on such updates, in the spirit of responsible disclosure?
I've worked with people who work on release engineering. Many things can go wrong by accident and silently, so you take your time to avoid distributing a broken binary that you could not upgrade.
(I made one of the early tracker-blocking rulesets, and, for the last few years, as a side project, have been building a new practical dataset of specific sites' JS dependencies and third-party requests. I'm up to over 10,000 necessary whitelist rules, which I add to throughout each day, in my own normal use. That 10,000 doesn't include blanket whitelisting of many popular JS CDN URLs, for all domains, which I eventually had to do because of current tool support, and most sites needed them, and there's something privacy&security-friendly that could be done in the browser about those URLs in particular.)
Pwn2Own: One change in the 2016 event is that the Mozilla Firefox Web browser is no longer part of the contest. "We wanted to focus on the browsers that have made serious security improvements in the last year," Gorenc said.
The implication is that Firefox just wasn't as secure as other browsers.
My gut feeling is that Chrome is far more secure than Firefox, but I would like an expert opinion.
On that measure Chrome wins easily: https://zerodium.com/program.html
considering 67% of browsers in use are chrome and ~10% firefox it could be that they are paying based on difficulty and potential reach.
Or what are the black market prices for browser exploits? Although that would mostly depend on the value of an exploit per browser, not the cost of creating an exploit.
Firefox is capable of the same problems, but I rarely see malicious Firefox extensions in the wild, I assume they do a much better job policing their store.
Chrome may be better at fighting arcane sandbox escape exploits, but that's not what gets the regular user into trouble.
https://hn.algolia.com/?sort=byDate&dateRange=all&type=comme...
[0] https://www.mozilla.org/en-US/security/advisories/mfsa2019-1...
The more code inspected, the more zero days that are identified. Every large code base has security issues. What is scary are the ones that only the wrong people know about.