Fraudulent tech-support sites cause Firefox to freeze, displaying scary message
arstechnica.com
arstechnica.com
Just copy Chrome and confine all modal dialog boxes such as HTTP basic auth and Javascript alert() to the individual browser tab. No individual tab should every be allowed to pop a modal that prevents interaction with any other tab, any other browser window.
This problem immediately goes away and you don't need to play rate limit wackamole games or do stupid things like have a dialog box that asks if you want to see another modal dialog box.
As someone who interacts with HTTP basic auth frequently Firefox's behavior here is maddening. Fix the bad UI.
Edit: Oh, and here is a 13 year old bug about the real issue: https://bugzilla.mozilla.org/show_bug.cgi?id=377496
So, `alert()` was fixed about 10 years ago in Firefox.
I'm not sure why the "Authentication Required" dialog wasn't, but I'm willing to bet it's something that was blocked indirectly by the old extension infrastructure (the so-called XUL extensions): until Firefox ~57, huge chunks of the architecture of Firefox were impossible to touch without breaking XUL extensions at a fundamental level, and this included making many things non-blocking.
If I'm right, it's the kind of thing that can now be fixed.
If extensions were the problem an interface to actually let the extensions work would have been created. As it is you still can't implement a password manager natively.
In-browser treatment of HTTP auth is just shockingly bad. But Firefox seems to be somewhere you get rewarded for introducing new features rather than fixing bugs.
My biggest annoyance is that since the login modal blocks the rest of the UI, I can't use my password manager!
(At least, I can't use Bitwarden, but I can't imagine how any other browser-plugin-based password manager would get around this.)
At the time I thought that was cool, and was sad when it went away with the new plugin architecture, but looking back it does indicate quite how bad the situation was with that old plugin format.
>But Firefox seems to be somewhere you get rewarded for introducing new features rather than fixing bugs.
Something else they are copying from Google!
"JavaScript exploits continue to plague all browsers" was something I wrote in 2002. Will it ever get better?
> "JavaScript exploits continue to plague all browsers" was something I wrote in 2002. Will it ever get better?
No. 10 years ago was common knowledge that you should avoid flash and javascript pages. Now flash is being slowly killed and javascript is the "saint" (if you say something bad about it you get excommunicated)
Luckily the affected tab was in a separate window, and here comes the tip if you're on Windows:
You can click `Alt+Space` to have an OS-provided menu, in which there's an option to close the window.
I primarily use Firefox, but am deeply disappointed in how such issues are handled (or rather, not handled). How many users on the planet would even know what a "Task Manager" is on Windows or how to "Force Close" an application on macOS? If/when the users learn from their more technically knowledgeable friends/family that this is a Firefox issue, most of them would just decide to switch to that popular browser that's been advertised on the most popular search engine and many other sites by the same company. That doesn't help Firefox much or people (like me) who evangelize Firefox to others.
Wouldn't it be easier to disconnect from the internet before reopening Firefox?
Seriously though I think it's a testament of how common the internet connection has become. Someone probably didn't even thought of it.
Who takes care of a crime if the perpetrator is in a different country or online?
They seem to have solved this issue in cases of copyright infringement of big companies (such as WB/Disney) and child pornography.
aren't reporters supposed to wait for a patch?
Full disclosure will get this fixed rather quickly now.
I wouldn’t hold your breath.
No. I'm sorry, but the application of the tiniest bit of common sense can do wonders. I send a URL to Cloudflare or Amazon. They see that this is, in fact, the same scam as they've seen hundreds or thousands of times before. Instead of "protecting" the free speech of the uploader, they instead recognize that this isn't free speech - it's an attempt to scam and defraud. Fraud is not protected free speech. They take it down without delay, they block the uploader, and everyone benefits.
Same with phishing sites - it doesn't take a genius to look at a "Bank of America" site and see that it's not, in fact, the real BoA, just like it doesn't take a genius to know that a "Flash Update" site isn't.
They make money. Therefore, they have the resources to do this. Don't make it out like they're just poor companies that are stuck between a rock and a hard place, because that's just plainly disingenuous.
No, I am not kidding you. You pay tax for your law enforcement to do this. They can easily automate legit legal take down requests. Why can't your cops enforce your laws? Why do random companies have to come up with inconsistent rules,process and response? It's nice to have someone to blame but if hollywood can go after DMCA law enforcement can also go after cybercrime -- it's their job!
Oh, and I did not make them out to be poor companies. My concern is that I don't want these companies anywhere near being responsible for take downs of user generated content what is harmful needs to be defined by lawmakers and enforced by law enforcement not by facebook and cloudflare. You're asking a store owner to inspect patrons for criminal behavior and kick them out when you should be calling 911 to get them arrested. The business owner can and should kick them out but the responsibility of enforcig that law is with cops.
Yes, reporting malicious activity to police is the right thing to do.
> Same with phishing sites - it doesn't take a genius to look at a "Bank of America" site and see that it's not, in fact, the real BoA, just like it doesn't take a genius to know that a "Flash Update" site isn't.
What you think to be a non-genius is nonetheless genius to someone who doesn't understand how web sites work and what to look for.
So you're saying they should outsource all scam and spam mitigation work to the police, and just let it run (and cause damage) until some police agency tells them to shut it down?