3 ms·
I use Firefox. Are you saying I'm now less safe? If I'm more safe but some other people don't like the solution then I guess they can configure or fork Firefox
by superflyguy 8y ago
I use Firefox. Are you saying I'm now less safe? If I'm more safe but some other people don't like the solution then I guess they can configure or fork Firefox then we're all happy, right?
- pbhjpbhj 8y agoArguably, if Firefox is devoting resources to this then it's not got resources to spend on other issues. That could in theory make it less secure. HIBP and 1Password aren't making FF more secure, chances are they're increasing attack surface in both directions (ie making compromise of 1Password more likely too).
- ddalex 8y agoThis is FUD.
- pbhjpbhj 8y agoCan you explain what's incorrect in my post? (FWIW it's not a position I hold, I've not looked at the situation properly yet.)
- ddalex 8y agoSure, I'll take it point by point. > Arguably, if Firefox is devoting resources to this then it's not got resources to spend on other issues. This is a logical fallacy. It's like saying - if we wouldn't spend money on the space program, we could feed Africa with that money. The problem here is that this is not a zero-sum game: the people that worked on this (e.g. Troy Hunt) wouldn't had the skills or inclination to bring other enhancements to Firefox. Thus this is a net addition, and not to the detriment of other work > That could in theory make it less secure So adding a feature that helps people be more secure against a specific threat (using bad passwords that have been broken) makes the product less secure? This makes no sense, but it's just put in there to spread Fear (FF is less secure because of added security features) and Doubt ("could in theory" ... meaning we don't know, but lets put this out there) > HIBP and 1Password aren't making FF more secure, I tend to evaluate a security in context of a threat model. HIBP and 1Password have very good track records of mitigating attacks on user passwords (by notifying people about password breaches and thus decreasing the value of a password breach, and by making easy for the average user to manage complex passwords). As a result, the Firefox users have better tools to manage password-based authentication, increasing their security. > chances are they're increasing attack surface in both directions (ie making compromise of 1Password more likely too). The evaluation of the "attack surface" here refers to the horizontal scale (how many actors of the same type see the interface) whereas the concept of reducing the "attack surface" refers to the vertical scale (how many types of communication the actors see). Reducing the horizontal scale is known as "security by obscurity" and it's a very bad idea to use it. A larger horizontal scale has no impact on the security, see ciphered communication: an encrypted message doesn't get less secure if more eyes see it, its security only depends on how well the encryption works. Assuming that 1Password doesn't use "security by obscurity", increasing its footprint on the web will not decrease its security.
- auslander 8y ago'This is FUD.' - this is FUD.
- coldtea 8y ago>Arguably, if Firefox is devoting resources to this then it's not got resources to spend on other issues. That could in theory make it less secure. You stretched that argument to points that only Reed Richards could match...
- pbhjpbhj 8y agoThe GP posited a stance, the parent refuted the _possibility_ of it, I was stating it was possible. Indeed, is it not a quite reasonable and logical possibility? If the parent addressed the actuality of it, perhaps with some factual basis, ... (Like "when FF did X in past they still quashed Y bugs, introduced Z features" - I know number of bugs/whatever isn't the best metric, but something factual) ... I wonder what the controlling minds of Firefox are trying to achieve as a long-term goal; they seem to take an opposite stance to the "do one thing well" philosophy.
- auslander 8y agoTrue on both. On first point, obvious areas they should focus are strong sandboxing of tabs and cookie cleaning by default. On second point, why bother with some 3rd party? I trust mozilla, not its 'partners'
- dewey 8y agoHow do you know they are not? This sounds like the old "why are you not focusing on my pet peeve feature" entitlement.
- detaro 8y ago> 1Password aren't making FF more secure Did I miss any announcement about 1Password becoming part of FF, or Mozilla helping in any way with development of 1Password?