Supporting Same-Site Cookies in Firefox 60 |
Firefox 60 will introduce support for the same-site cookie attribute, which allows developers to gain more control over cookies. Since browsers will include cookies with every request to a website, most sites rely on this mechanism to determine whether users & Continue reading
The post Supporting Same-Site Cookies in Firefox 60 appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2018/04/24/same-site-cookies-in-firefox-60/
Метки: Security |
Distrust of Symantec TLS Certificates |
A Certification Authority (CA) is an organization that browser vendors (like Mozilla) trust to issue certificates to websites. Last year, Mozilla published and discussed a set of issues with one of the oldest and largest CAs run by Symantec. The & Continue reading
The post Distrust of Symantec TLS Certificates appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2018/03/12/distrust-symantec-tls-certificates/
Метки: Security |
Analysis of the Alexa Top 1M Sites |
Prior to the release of the Mozilla Observatory in June of 2016, I ran a scan of the Alexa Top 1M websites. Despite being available for years, the usage rates of modern defensive security technologies was frustratingly low. A lack & Continue reading
The post Analysis of the Alexa Top 1M Sites appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2018/02/28/analysis-alexa-top-1m-sites-2/
Метки: Security |
Restricting AppCache to Secure Contexts |
The Application Cache (AppCache) interface provides a caching mechanism that allows websites to run offline. Using this API, developers can specify resources that the browser should cache and make available to users offline. Unfortunately, AppCache has limitations in revalidating its & Continue reading
The post Restricting AppCache to Secure Contexts appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2018/02/12/restricting-appcache-secure-contexts/
Метки: Security |
Preventing data leaks by stripping path information in HTTP Referrers |
To help prevent third party data leakage while browsing privately, Firefox Private Browsing Mode will remove path information from referrers sent to third parties starting in Firefox 59. Referrers can leak sensitive data When you click a link in your & Continue reading
The post Preventing data leaks by stripping path information in HTTP Referrers appeared first on Mozilla Security Blog.
Метки: Firefox Privacy |
January 2018 CA Communication |
Mozilla has sent a CA Communication to inform Certificate Authorities (CAs) who have root certificates included in Mozilla’s program about current events related to domain validation for SSL certificates and to remind them of a number of upcoming deadlines. This & Continue reading
The post January 2018 CA Communication appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2018/01/29/january-2018-ca-communication/
Метки: Security |
Secure Contexts Everywhere |
Since Let’s Encrypt launched, secure contexts have become much more mature. We have witnessed the successful restriction of existing, as well as new features to secure contexts. The W3C TAG is about to drastically raise the bar to ship features & Continue reading
The post Secure Contexts Everywhere appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2018/01/15/secure-contexts-everywhere/
Метки: Announcements Firefox Privacy Security https |
Mitigations landing for new class of timing attack |
Several recently-published research articles have demonstrated a new class of timing attacks (Meltdown and Spectre) that work on modern CPUs. Our internal experiments confirm that it is possible to use similar techniques from Web content to read private information between & Continue reading
The post Mitigations landing for new class of timing attack appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2018/01/03/mitigations-landing-new-class-timing-attack/
Метки: Security |
Blocking Top-Level Navigations to data URLs for Firefox 59 |
End users rely on the address bar of a web browser to identify what web page they are on. However, most end users are not aware of the concept of a data URL which can contain a legitimate address string & Continue reading
The post Blocking Top-Level Navigations to data URLs for Firefox 59 appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2017/11/27/blocking-top-level-navigations-data-urls-firefox-59/
Метки: Security |
November 2017 CA Communication |
Mozilla has sent a CA Communication to inform Certificate Authorities (CAs) who have root certificates included in Mozilla’s program about Mozilla’s expectations regarding version 2.5 of Mozilla’s Root Store Policy, annual CA updates, and actions the CAs need to take. & Continue reading
The post November 2017 CA Communication appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2017/11/16/november-2017-ca-communication/
Метки: Security |
Statement on DigiCert’s Proposed Purchase of Symantec’s CA |
Mozilla’s Root Store Program has taken the position that trust is not automatically transferable between organizations. This is specifically stated in section 8 of our Root Store Policy v2.5, which details how Mozilla handles transfers of root certificates between organizations. & Continue reading
The post Statement on DigiCert’s Proposed Purchase of Symantecs CA appeared first on Mozilla Security Blog.
https://blog.mozilla.org/security/2017/10/31/statement-digicerts-proposed-purchase-symantec/
Метки: Announcements CA Program |
Firefox AddressSanitizer builds have been moved |
https://blog.mozilla.org/security/2016/09/09/firefox-addresssanitizer-builds-have-been-moved/
Метки: Announcements Firefox |
Mitigating MIME Confusion Attacks in Firefox |
https://blog.mozilla.org/security/2016/08/26/mitigating-mime-confusion-attacks-in-firefox/
Метки: Security Mime confusion X-Content-Type-Options |
MWoS 2015: Let’s Encrypt Automation Tooling |
https://blog.mozilla.org/security/2016/08/08/mwos-2015-lets-encrypt-automation-tooling/
Метки: Security certificate authority https MWoS TLS |
Announcing the 2016 edition of Mozilla Winter of Security |
https://blog.mozilla.org/security/2016/08/01/announcing-mwos-2016/
Метки: Announcements Security |
Enhancing Download Protection in Firefox |
https://blog.mozilla.org/security/2016/08/01/enhancing-download-protection-in-firefox/
Метки: Security Safe Browsing |
March 2016 CA Communication |
https://blog.mozilla.org/security/2016/03/29/march-2016-ca-communication/
Метки: Security |
Payment Processors Still Using Weak Crypto |
https://blog.mozilla.org/security/2016/02/24/payment-processors-still-using-weak-crypto/
Метки: Security |
Mozilla Winter of Security-2015 MozDef: Virtual Reality Interface |
Метки: Security MozDef Winter of Security |
Man-in-the-Middle Interfering with Increased Security |
https://blog.mozilla.org/security/2016/01/06/man-in-the-middle-interfering-with-increased-security/
Метки: Security |