A word of caution to fossians.. don't save your vital passwords (like
emails) in firefox's default saving mechanism.. it was an old exploit.. but
seems still a lot of holes remain... a lot of things are just because of the
structure of firefox itself (it's just a bunch of javascript codes running
javascript) so just try to keep your privacy safe...
*


"Although the Mozilla developers have fixed a known hole in the password
manager of Firefox & Co, a door remains open for exploitation. According to
an article on the heise site, hackers can still use JavaScript to steal
passwords <http://www.heise-security.co.uk/news/93018> from users of the
Mozilla, Firefox, and Safari browsers. However, the real problem might not
be Firefox' password manager. If users can set up their own pages containing
script code on a server, the JavaScript security model breaks. Heise
Security demonstrates the possible password theft in a demo. 'From the
users' perspective, this means that they should not entrust their passwords
to the password manager on web sites that allow other users to create their
own pages containing scripts. Otherwise somebody can easily create a page
that steals the password as soon as the page is opened ... Users could also
disable JavaScript or use add-ons such as NoScript to set up rules to
provide additional protection. In the age of Web 2.0 this would, however,
mean that many pages would cease to function. On the other hand it is
doubtful that by not using a password manager security levels would be
raised, since the resultant need to remember passwords often induces users
to choose simplistic passwords and use them on multiple sites.'"*

--~--~---------~--~----~------------~-------~--~----~
FOSS Nepal mailing list
[email protected]
http://groups.google.com/group/foss-nepal

Community website: http://www.fossnepal.org/
-~----------~----~----~----~------~----~------~--~---

Reply via email to