4 ms·
Can someone explain why Mozilla is not signing gmpopenh264.dll and now eme-adobe.dll? These are executed from AppData (a folder with read/write permissions).
by nominated1 11y ago
Can someone explain why Mozilla is not signing gmpopenh264.dll and now eme-adobe.dll? These are executed from AppData (a folder with read/write permissions). Executing dll's from AppData is generally a bad idea but if I'm going to allow it I at least want a Publisher rule attached.
Google signs their CDM (WideVine) dll delivered with Chrome that executes from AppData, why isn't Mozilla?
- hsivonen 11y agoFirefox checks SHA-512 hashes at download time. If you have local malware that changes the GMP DLLs thereafter, the malware might as well change Firefox itself.
- duaneb 11y ago> If you have local malware that changes the GMP DLLs thereafter, the malware might as well change Firefox itself. Well hopefully firefox itself is signed. This is exactly what signing is designed to prevent.
- hsivonen 11y agoFor software that runs as non-admin, authenticode is very much about checking delivery-time integrity. If you have admin-level malware, it can replace signed software (that gets run without admin privs and doesn't have UAC at launch) with unsigned lookalikes.
- duaneb 11y ago> If you have admin-level malware ...you should reinstall your OS. Really, that shouldn't even be an "if" these days. Of course security doesn't matter if people can just execute random code on your machine. Anyway, code signing is not about delivery time integrity. It's easy to check whether a given binary is code signed at any given time—without it you wouldn't be able to revoke bad certificates. The only reason you shouldn't sign is if signing has some cost (like in the Mac OS X ecosystem) or you can't trust a single root certificate anyway (at which point you might as well move to OpenBSD anyway).
- briansmith 11y agoNot if the computer is configured to only run signed code, which is an option on Windows.
- conductor 11y agoIt can't change Firefox itself if it has no administrative privileges but it can change anything in the user's directories.
- hsivonen 11y agoYour scenario already has the malware running with the user's privileges. This means that the malware already has more privileges than sandboxed GMPs in your scenario.
- omeid2 11y agoWhile that is a valid point, it doesn't changes the fact that the more attack surface the more likely to break through. Sometimes you have few limited vulnerabilities that can add up to complete systems compromise.
- nominated1 11y agoI'm approaching it like this - I need to execute unsigned binaries from a location that does not have execute permissions. How can I manage this? The lack of a signature is at best an administrative burden and at worst an attack vector depending on how the Admin handles it ("let's just add a wildcard exeception"). Mozilla should recognize this and sign the dll's. I still haven't seen a reason for NOT signing them. We don't use WebRTC so ignoring gmpopenh264.dll was not a problem. However, now we're talking about "necessary" Adobe code. Need I say more? Chrome performs the same functions and adheres to common sense. This is one of those things that gets a package removed from offering. I like and use Firefox myself but I don't like the position Mozilla has put me in. Should I open a bug report or do you speak for Mozilla in an official capacity?
- yarrel 11y agoFirefox is now a malware installer? Awesome!
- anonbanker 11y agoYour post may seem snarky, but I upvoted you for truth. Many of us consider Adobe's DRM software to be nothing but malware.
- abroach 11y agoIt's easy to remove (see https://support.mozilla.org/en-US/kb/enable-drm); https://support.mozilla.org/en-US/kb/enable-drm); or, if you don't want it at all, you retain that option: http://download.cdn.mozilla.net/pub/firefox/releases/38.0/win32-EME-free/ http://download.cdn.mozilla.net/pub/firefox/releases/38.0/wi...