Slashdot Mirror


Spyware for Firefox Coming This Year?

EvilCowzGoMoo writes "One of the main reasons for the Firefox browser's successful seizure of market share from Microsoft's Internet Explorer is the desire to escape the inundation of PC-slowing spyware. However, spyware experts indicate that with its increased popularity, Firefox itself will become a target for spyware creators." From the article: "Basically, if you use Firefox today, you're not susceptible to any spyware, other than what you download when you're on Kazaa...The spyware writers target mostly Explorer users because that's the most fertile feeding ground for piranha-like (spyware) attacks. They'll watch as Firefox becomes mainstream, they'll see opportunity there and start targeting them."

3 of 630 comments (clear)

  1. Re:...and.... by arkanes · · Score: 5, Informative
    Current versions of firefox don't allow this, unlike the (annoyingly easy to mis-click) ActiveX install dialog in IE. There's a whitelist for sites permitted to install extensions, which (by default) is limited to the offical Mozilla update site. Sites not in the whitelist won't even get a dialog, instead a yellow bar at the top of the screen appears, with a button you can use to access the whitelist and add the site. A site on the whitelist gets the standard dialog, which has a time-delay OK button to help prevent mis-clicks. There's no absolute way to prevent people from installing malicious extensions, but (assuming there's no bugs in, say, the whitelist implementation) Firefoxes current model is about as good as you could get.

    Note that older versions of Firefox (and Mozilla) don't have the whitelist, and even older ones don't even have the dialog and are in fact vulnerable.

  2. Re:IE and Firefox have different problems by maskedbishounen · · Score: 5, Informative

    This is why Mozilla Update exists. A safe haven for users to find extentions that won't screw them over.

    Supposedly.

    If nothing else, at least it has a rating and feedback system, so you'll have a heads up from others.

    --
    "An infinite number of monkeys typing into GNU emacs would never make a good program."
  3. "Expert"? by Kupek · · Score: 5, Informative

    Their expert is the Vice President of Threat Research at Webroot. That much is from the article. The article doesn't take the next logical step, however, and point out that Webroot is in the business of developing and selling software to prevent, detect and eleminate spyware. So it's certainly in this guy's interest for people to think that spyware is still a problem.

    Their other expert is also from a company that makes similar software. So people who make anti-spyware software agree: you need anti-spyware software.

    I'll be more concerned when independent parties think spyware in Firefox is an issue.