Security News

Mozilla blocks malicious add-ons installed by 455K Firefox users
2021-10-25 20:08

Mozilla blocked malicious Firefox add-ons installed by roughly 455,000 users after discovering in early June that they were abusing the proxy API to block Firefox updates. "Starting with Firefox 91.1, Firefox now includes changes to fall back to direct connections when Firefox makes an important request via a proxy configuration that fails."

Mozilla upgrades older Thunderbird clients to the latest version
2021-10-08 13:23

Mozilla is rolling out a forced upgrade for Thunderbird 78.x users, getting everyone aboard version 91, the latest stable release that came out in August. If you were sticking with version 78.x thus far, it's likely that you were doing so for reasons of stability and add-on compatibility.

Mozilla tests Microsoft Bing as the default Firefox search engine
2021-09-17 17:40

Mozilla is running a study to test users' responses to changing the default Firefox search engine to Microsoft Bing. Like all browsers, Mozilla Firefox automatically configures a browser to a default search engine for performing searches via the address bar.

Mozilla tests if 'Firefox/100.0' user agent breaks websites
2021-08-09 19:23

Mozilla has launched an experiment where they change the Firefox browser user agent to a three-digit "Firefox/100.0" version to see if it will break websites. The current user agent for Mozilla Firefox version 90 is listed below.

Mozilla Firefox to roll out DNS over HTTPS for Canadian users
2021-07-08 13:00

Mozilla has decided to roll out the DNS over HTTPS feature by default for Canadian Firefox users later this month. Firefox to enable DoH by default for Canadian users.

Mozilla Launches Privacy-Focused Browsing Data Sharing Platform
2021-06-28 21:11

Mozilla has a new privacy-focused data sharing platform that provides users with increased control of their data and also allows them to contribute to a better Internet. Built in collaboration with Princeton University researchers, the new Mozilla Rally allows users to select who they want to share their browsing data with, the browser maker says.

Mozilla Says Google's New Ad Tech—FLoC—Doesn't Protect User Privacy
2021-06-13 23:04

Essentially, FLoC allows marketers to guess users' interests without having to uniquely identify them, thereby eliminating the privacy implications associated with tailored advertising, which currently relies on techniques such as tracking cookies and device fingerprinting that expose users' browsing history across sites to advertisers or ad platforms. FLoC sidesteps the cookie with a new "Cohort" identifier wherein users are bucketed into clusters based on similar browsing behaviors.

Google, Microsoft, and Mozilla work together on better browser extensions
2021-06-06 14:30

Google, Microsoft, Apple, and Mozilla have launched the WebExtensions Community Group to collaborate on standardizing browser extensions to enhance both security and performance. "With multiple browsers adopting a broadly compatible model for extensions in the last few years, the WECG is excited to explore how browser vendors and other interested parties can work together to advance a common browser extension platform," the browser vendors said.

Mozilla: Update Firefox to avoid Netflix, Hulu streaming issues
2021-05-29 13:15

Mozilla advises Firefox users to update to the latest released version to avoid experiencing video streaming issues after Google updates the Widevine digital rights management on May 31. Once Google updates the Widevine private encryption keys and content decryption module on May 31, video streaming services using Google's DRM-protection technology will no longer work with older Firefox versions.

Icarus moment: Mozilla Thunderbird was saving OpenPGP keys in plaintext after encryption snafu
2021-05-24 17:15

Mozilla Thunderbird spent the last couple of months saving some users' OpenPGP keys in plain text - but that's now been patched, the author of both the bug and the patch fixing it has told The Register. The vulnerability, assessed as "Low" impact by Mozilla, existed in the free open source Thunderbird email client between version 78.8.1 and version 78.10.1 after a crestfallen maintainer realised carefully designed protections were in fact not protecting users' private OpenPGP keys.