3 ms·
I tested the demo and it seems the associated javascript function to prompt someone to install a software is no longer present in Firefox (netscape.security.Pri
by feikname 8y ago
I tested the demo and it seems the associated javascript function to prompt someone to install a software is no longer present in Firefox (netscape.security.PrivilegeManager.enablePrivilege).
I question the utility of having this delay behaviour by default, worst that can happen is you accidentally start a download AFAIK, which you can just quickly delete/cancel afterwards.
And, there's browser.download.manager.alertOnEXEOpen too.
I much prefer Chrome's behaviour of starting the download and you instantly can see the filename and size in the bottom as soon as it starts and can then choose to either open it or show it in the file manager.
- mappu 8y ago> worst that can happen is you accidentally start a download There's a potential DLL hijacking attack: 1. Accidental download of kernel32.dll 2. Ignore, who cares, do something else 3. Download actually_wanted_installer.exe, which finds malicious kernel32.dll in current directory instead of SYSTEM32 There are a few DLLs whitelisted for protection for this, but drive-by downloads are a real attack vector. Also in the past, exploitable bugs in the thumbnailer if you browse to your Downloads directory (e.g. CVE-2017-11421 and others on Linux).
- marcosdumay 8y agoOpening documents is still dangerous, even if there is no option to ask for installations. Alert on exe is not nearly enough. Almost any file type is dangerous on Windows, and there is a long list for unixes. Making it possible for users to open a document without knowing what they are doing first is a huge vulnerability. That said, starting the download and immediately getting it out of the user's face, requiring interaction to open them is a very good solution. It leads to some problems on Windows, but then, what doesn't?