5 ms·
This is a security nightmare. You now have an application -- a web browser -- that can be turned into a server by any malicious person with even a modicum of sk
by Sanddancer 10y ago
This is a security nightmare. You now have an application -- a web browser -- that can be turned into a server by any malicious person with even a modicum of skill. It means that any other part of the payload no longer has to worry about setting up services, etc to covertly communicate back to the main site, that's all handled by the browser, which now has all the proxy settings and all of the keys to do so like any other traffic. This is just a terrible idea for very marginal benefit.
- ricardobeat 10y agoThe server is only visible in the local network, for the duration of the session, and subject to the browser sandbox. For any kind of malware, phoning home is hardly a problem, what advantage do you think this gives them?
- Sanddancer 10y agoDepends. Let's say, for example, you find a hole in a corporate webapp, say a wordpress application. You want to get usernames and passwords, but said app is firewalled off and you don't want to rouse suspicions. So, you send an email to Joe over in accounting, with a link to a game of some sort that asks to start a webserver. Now, FlyWeb makes its presence known via mdns, and the compromised server now has Joe's IP address. The server can now use Joe as the patsy/proxy, and your code can potentially stay on the server just a bit longer. Yes, it's a bit convoluted, but it's the first sort of attack that came to mind. An open web server, even if local, can cause a good number of problems, especially if it's running untrusted content.
- onion2k 10y agoFlyweb would be unnecessary in a situation where you have access to a web app server and a user's machine. You could just modify the code on the server to make Joe's machine post data to the outside when Joe visits the web app. FlyWeb does present a new attack surface, so it needs thought, but the blog post makes it abundantly clear that Mozilla know that.
- danjoc 10y agoAre you familiar with www.peer-server.com? Creating a server in the browser can be done by any browser with WebRTC. FlyWeb merely adds service discovery on a LAN. If you're worried about security, you should be running NoScript.
- Sanddancer 10y agoWebRTC is also a misfeature in my opinion. Service discovery makes the misfeature even worse by announcing it to the local world, making it easier for malicious software to use an unsuspecting user's browser as a proxy. Yes, noscript would help my personal box, but it wouldn't preclude Joe from Accounting from opening that "neat game" they got an email about.