Friday, November 25, 2011

Firefox Silent Updates are a Security Risk?

As a way to speed up the process of updating Firefox, Mozilla engineers are mulling over a silent update feature, which one security expert argues is a bad idea. Currently, when Firefox detects an available update, it lets you know and if you agree to install it, the browser launches its updater program. That program downloads the update, applies it to Firefox, and restarts the browser. While all that is happening, you're twiddling your thumbs watching a progress bar on your computer screen. To skirt the lag time in the current updating process, the Firefox team is considering a "silent" alternative. Instead of performing an update in the foreground, updates would be downloaded in the background and installed on a copy of the browser in a new directory. The first time that you launch Firefox after an update has been completed, your old version of Firefox is swapped out for the new version. "While many IT security systems will have to be reconfigured to allow background updates to Firefox--which is not a good thing in the first place--there is danger that hackers could subvert the update system to allow them back-door access to the users' computer." Silent updating may be more convenient to consumers, the security expert noted, but it will also invite hacker exploitation of the process.

Visit as on Omnifuzz or FastFind

No comments:

Post a Comment