6 ms·
Why were Coinbase employees allowed to use Mozilla Firefox?
by xtalh 7y ago
Why were Coinbase employees allowed to use Mozilla Firefox?
- aarpmcgee 7y agoWhy wouldn't they be allowed to use Firefox?
- therein 7y agoThey are not allowed actually. However maybe a few were anyway? As far as I can tell, this attack was fully unsuccessful anyway. They probably discovered phishing attempts with a link to a page deploying a curious payload. Regardless of my post above, keep in mind I do use Firefox primarily and see nothing wrong with it.
- xtalh 7y agoIt's worse than Chrome in every way. For example the privsep system is a joke. That's not to say that Chrome can't have an RCE but of course you don't have the same chances if the browser is much more secure. And if you work in an environment like Coinbase's you really should not take chances.
- ga-vu 7y agoProbably because 85% of the browser market it's Chromium-based, while the rest is not. Hence, a smaller attack surface.
- icebraining 7y agoThat's not what "attack surface" means. Firefox would have a smaller attack surface if it supported fewer file formats or protocols or such than Chrome.
- ga-vu 7y agoTrue. A smaller target base would have been the correct term.
- wlesieutre 7y agoAre we forgetting that Chrome had a zero-day literally three months ago? https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/analysis-of-a-chrome-zero-day-cve-2019-5786/ https://securingtomorrow.mcafee.com/other-blogs/mcafee-labs/... > Google is aware of reports that an exploit for CVE-2019-5786 exists in the wild.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- icebraining 7y agoWhile I'm a Firefox user, that's actually evidence to xtalh's point: that bug by itself is useless, because Chrome's sandbox meant that taking over the rendering process is not enough. They only managed to escape on Windows 7, thanks to another bug (in Windows itself - CVE-2019-0808).
- pcwalton 7y agoNote that Firefox has a sandbox too (in fact, it shares a good bit of code with that of Chrome), and therefore a sandbox escape is necessary to elevate privileges. (NB: I have no knowledge of the details of this specific bug.)
- laughinghan 7y agoLeaving aside whether it makes sense to call something "useless" that was actually used in the wild, the original article specifically mentions (twice) that the Firefox RCE 0-day was also sandboxed and also only managed to escape thanks to another 0-day. (And I'm actually a Chrome user, for now.)
- _wmd 7y agoYou almost make it sound like Chrome weren't written in C++, or that the typical Chrome install weren't hosted on a few 10s of millions of lines of C/C++
- xtalh 7y agoI make it sound like Chrome has privsev while Firefox has shit.
- AnaniasAnanas 7y agoA better question would be: why were Coinbase employees allowed to use any browser with javascript enabled and outside of a VM? Qubes OS has been a thing for quite a while.
- toyg 7y ago> why were Coinbase employees allowed to use any browser with javascript enabled I don't know, maybe because they need to get work done...? Even traditional banks allow JS.
- hackinthebochs 7y agoGoogle and Stackoverflow work just fine without javascript enabled. Trustworthy sites can be whitelisted if absolutely necessary.
- toyg 7y agoIt's this sort of attitude that makes sysadmins so incredibly popular among the masses. Hint: if your environment feels like a concentration camp, users will find ways to work outside of it most of the time - which will be even more disastrous.
- hackinthebochs 7y agoThat's a fair point when literally hundreds of millions of dollars aren't on the line. It's not hard to properly secure your system from all manner of internet threats. There's no excuse for crypto exchanges not to implement such measures.
- toyg 7y agoIf hundreds of millions of dollars are one JS exploit away, the defense model is flawed. That sort of movement should require approvals from multiple people and even dedicated terminals that are not used for everyday browsing. Security is a tradeoff; nuking browsers for everyone is just a bad tradeoff in 2019.
- jetzzz 7y ago> Why were Coinbase employees allowed to use Mozilla Firefox? Nowhere in article it is said that any Coinbase employee was using Firefox. It only says that attack targeted Firefox, not that Coinbase employees use Firefox.