Help - Search - Members - Calendar
Full Version: How secure is Firefox ?
B.I.S.S. Forums > Internet Security Forum > Internet Security Discussion
lassar25
I have done some Googling and it seems FireFox has had a few security problems.

From what I have read; it is way more safe the internet explorer.

Would FireFox plus NoScript be almost immune to malicious web sites ?
Aaron.Walkhouse
Yes, that's a pretty safe combination.

You can greatly enhance your security with the BISS Hosts File Manager
and the Adblock Plus Firefox plugin.
Chroma
NoScript is an excellent idea and something I've been using successfully for at least 8 months. I must warn you though that many legit websites use scripts as a matter of course and NoScript blocks scripts (which it's supposed to do!!) but it can be a real pain in the backside particularly when you forget you're using it and get totally frustrated that a website does not responding to what you want it to do!!
winston
QUOTE (Chroma @ Mar 27 2009, 06:30 AM) *
NoScript is an excellent idea and something I've been using successfully for at least 8 months. I must warn you though that many legit websites use scripts as a matter of course and NoScript blocks scripts (which it's supposed to do!!) but it can be a real pain in the backside particularly when you forget you're using it and get totally frustrated that a website does not responding to what you want it to do!!


and that's why you can whitelist "trusted" sites ..
Tech Geek
I am not sure that IE is more secure than FF ? Because I have lots of bad experiences with IE. How about Chrome's security ?
schmandel
QUOTE (Chroma @ Mar 27 2009, 05:30 AM) *
NoScript is an excellent idea and something I've been using successfully for at least 8 months. I must warn you though that many legit websites use scripts as a matter of course and NoScript blocks scripts (which it's supposed to do!!) but it can be a real pain in the backside particularly when you forget you're using it and get totally frustrated that a website does not responding to what you want it to do!!


I would say NoScript is a necessity, PITA or not. Another add-on that is effective against major trackers and easier to use than NoScript is Ghostery. BetterPrivacy will help to keep your Flash cookie cache clean.
vopmikey
QUOTE
I have done some Googling and it seems FireFox has had a few security problems.


It's seems to me that the Mozilla folk tend to deny POCs untill the related exploits are actually found in the wild.

Ref;
http://web.nvd.nist.gov/view/vuln/search-r...s?query=firefox

http://web.nvd.nist.gov/view/vuln/search-r...s?query=mozilla

http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=firefox

http://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=mozilla

QUOTE
From what I have read; it is way more safe the internet explorer.


Think again. Ref; http://www.spywareinfoforum.com/index.php?...post__p__753312
The Netweasel
In my opinion, choosing a browser is sort of like shopping for a new automobile. Each model has pros and cons, and a safety rating, and in the end your choice comes down to personal preference. Safety equipment is important, but I think most people just assume that there are researchers somewhere who look after that sort of thing, and choose based on style and desired features. Word of mouth plays a part, of course, but that is unreliable and only worth so much.

As with an automobile, when considering browser security, the only safety device that really, really matters is the person sitting in the driver's seat. Vehicle designers try to plan for every imaginable hazardous situation their product might face, and do their best to make it idiot-proof, but they must ultimately fail in their pursuit of perfection because they cannot predict the future. The highway, be it constructed of asphalt or electrons, is full of strangers who are apt to do anything, and you can only plan for just so much. New safety features nearly always have their origins in accident analysis.

I use Firefox because it has features I like, and add-ons that enhance my security and help me in my work, such as Ghostery, Better Privacy, and WorldIP. Security enhancements notwithstanding, I can't abide Internet Explorer because like so many Microsoft products, it has become insufferable nagware. When I download a file, the only browser dialog I want to see is, "Where do you want to put it?"

"That's fine for you," you might say, "you work in Internet security every day and wrangle Trojans as a hobby. What about the poor schlub who hasn't a clue?"

Well, for him there's Internet Explorer, which is probably what he's using, and someone he can hire to fix his computer when it gets infected.

I have a relative who is just such an Internet and computer neophyte, who uses IE. I made sure his computer had the latest version of that browser, installed all the updates for Windows and Internet Explorer, installed good antivirus, adjusted various settings to minimize risk, and still his machine got infected several times - through IE! He doesn't visit dodgy web sites or engage in risky browsing behavior ... the infections arrived via malicious Flash-based ad banners on well-known and legitimate commercial sites.

That rash of fake-antivirus infections from Flash ads seems to have subsided now. Perhaps that is due to browser security updates, but I frankly don't know. I don't think anyone's browser was immune during the height of that malware campaign, and I suspect it was "accident analysis" that got us beyond the vulnerability.

So while I firmly believe that analyzing browsers for security flaws is vital work, I hesitate to assign blame to any particular browser when clever hackers find and exploit a vulnerability. Those miscreants are good at what they do, and work assiduously to break into people's computers. My personal feeling is that pointing a finger at Internet Explorer, or Firefox, or Opera, or Chrome, or whoever, and shouting, "You didn't prevent it!" is sort of like blaming Ford Motor Company for the drunk driver who unexpectedly came around the curve on the wrong side of the road. Unforeseen hazards.

Just my two-cents worth.
drinks.gif
vopmikey
Exactly. Use what suits you but learn how to protect it. smile.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.