Slashdot Mirror


Sneaky Microsoft Add-On Put Firefox Users At Risk

CWmike writes to mention that the "Windows Presentation Foundation" plugin that Microsoft slipped into Firefox last February apparently left the popular browser open to attack. This was among the many things recently addressed in the massive Tuesday patch. "What was particularly galling to users was that once installed, the .NET add-on was virtually impossible to remove from Firefox. The usual 'Disable' and 'Uninstall' buttons in Firefox's add-on list were grayed out on all versions of Windows except Windows 7, leaving most users no alternative other than to root through the Windows registry, a potentially dangerous chore, since a misstep could cripple the PC. Several sites posted complicated directions on how to scrub the .NET add-on from Firefox, including Annoyances.org."

16 of 333 comments (clear)

  1. except Windows 7 by nurb432 · · Score: 4, Funny

    Best upgrade then ya lusers!.. Here is an online form to order your shiny new pc with Windows 7..

    --
    ---- Booth was a patriot ----
    1. Re:except Windows 7 by edwardsdl · · Score: 3, Funny

      I don't understand the question.

    2. Re:except Windows 7 by PopeRatzo · · Score: 2, Funny

      I don't understand the question.

      That's OK, neither did he.

      --
      You are welcome on my lawn.
    3. Re:except Windows 7 by Anonymous Coward · · Score: 1, Funny

      Since Ubuntu is the best Linux has to offer, the other distributions must be absolute shit.

  2. Re:Sabotage? by Captain+Spam · · Score: 2, Funny

    Not really, not when it's due to a plugin they themselves installed and have their name all over. I mean, you don't consider Flash vulnerabilities to be the fault of IE or Firefox, do you? If anything (and that's a big "if" in this case), it'll be a black eye for Microsoft.

    Nah, if you're going the paranoid route, it'd have been a better idea if they made this plugin under the guise of a shell company or something, then when the vulnerabilities hit the fan, have the shell complain about how "hard" it is to make a secure plugin for the "obviously inferior" Firefox, then have Microsoft suddenly pipe up about how much more secure the .NET plugin is under IE. Bonus points if the shell claims to be open-source with their reimplementation of .NET so Microsoft can attempt to discredit open-source software, too!

    But we're not THAT paranoid. Are we?

    --
    Demanding constant attention will only lead to attention.
  3. Re:"Cripple the PC" by Anonymous Coward · · Score: 2, Funny

    Exactly, and if anyone knows about crippled platforms, it's Apple.

  4. Re:remember the important part by jalefkowit · · Score: 4, Funny

    That's what SHE said!

    (sorry, couldn't resist)

  5. Re:Sabotage? by Ethanol-fueled · · Score: 2, Funny

    It's not broken if it still works, even if it is a gaping security hole.

  6. Re:Sabotage? by SleazyRidr · · Score: 2, Funny

    If your security is that bad, you should really consider switching to Linux.

  7. Re:Sabotage? by PopeRatzo · · Score: 2, Funny

    For instance most people see the CIA as a bunch of bad asses with cell phone watches that project holograms of your dossier into thin air while sending you messages via ESP.

    That's how those bastards did me, too!

    --
    You are welcome on my lawn.
  8. Re:Sabotage? by PopeRatzo · · Score: 4, Funny

    Who gave Glenn Beck a webcam?

    --
    You are welcome on my lawn.
  9. Re:Sabotage? by PopeRatzo · · Score: 4, Funny

    I'm the one who found and reported one of the vulnerabilities (CVE-2009-0090 [microsoft.com]) in this batch that affects Firefox, and I strongly doubt that it was in any way intentional...remember that IE is hit much worse

    You're spoiling everyone's fun, you know that?

    --
    You are welcome on my lawn.
  10. Re:Registry Danger! by PopeRatzo · · Score: 3, Funny

    turns out having a particular antivirus installed (mcaffee if I recall)

    There's your problem, right there.

    --
    You are welcome on my lawn.
  11. Re:Sabotage? by shutdown+-p+now · · Score: 3, Funny

    Ah, but you're missing the golden opportunity that I may be specifically sent here on /. to spread lies and FUD on the subject! ~

  12. Re:Sabotage? by JimboFBX · · Score: 4, Funny

    Nah, the instructions are missing a reference to an obscure library somewhere that the user was some how already supposed to have with no link as to where to download it.

  13. Re:Sabotage? by Hognoxious · · Score: 1, Funny

    I was designing an Algol-60 compiler targetting .NET

    You too? Small world or what?

    --
    Confucius say, "Find worm in apple - bad. Find half a worm - worse."