4 ms·
Paper this article is based on can be found here[1]. I'm not aware that the tools they used or the source for the tools they used was ever released although it
by ryuuchin 10y ago
Paper this article is based on can be found here[1].
I'm not aware that the tools they used or the source for the tools they used was ever released although it was reportedly given to the Mozilla reviewers[2]. Outside of the top 10 extensions they listed this makes it hard to draw conclusions other than the fact that Firefox's extension architecture leaves something to be desired although I'm not sure I would call it surprising. Firefox has a long history of not making a push towards a more secure platform. I'm not sure I would say they don't care but it's clearly not a priority for them (in general, not specifically this incident).
This is speculating but I would imagine they may have integrated this into their automated review process or at the very least done a more thorough scan and contacted extension authors since they were reportedly given the tools. Although a better question is could anything actually be done about this in the extension's code (it may be in the paper, I didn't read it all the way through)?
[1] https://www.internetsociety.org/sites/default/files/blogs-media/crossfire-analysis-firefox-extension-reuse-vulnerabilities.pdf https://www.internetsociety.org/sites/default/files/blogs-me...
[2] https://github.com/gorhill/uBlock/issues/1534 https://github.com/gorhill/uBlock/issues/1534
- JoachimSchipper 10y agoJavascript is notoriously hard to analyze, and it's not clear to me that Firefox should want to isolate extensions from each other - yes, it stops the most obvious form of this attack, but it also makes it impossible to integrate things other than by making one mega-extension.
- ryuuchin 10y ago> it's not clear to me that Firefox should want to isolate extensions from each other I think it's more interesting that the new(?) extension API (Jetpack) which was supposed to provide extension isolation is also apparently vulnerable to this. If you want to make isolating extensions from each other opt-in then ok but it should at least be able to do what it's designed to do.