<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Update on the AMO Security Issue</title>
	<atom:link href="http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/</link>
	<description></description>
	<lastBuildDate>Fri, 10 Feb 2012 22:23:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Ram</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-69244</link>
		<dc:creator>Ram</dc:creator>
		<pubDate>Sun, 04 Apr 2010 08:15:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-69244</guid>
		<description>I do agree that an anti virus need to be up-to-date and shield your computer, so if the file contain a virus it know it will tell you, or stop the virus.

To &#039;let people read the source code&#039; is not the best way, after all not all the user know how to read code...

a file signature is a good method it can work but not all the time.

I just think users need to be alerted that virus live among us, and to double check any thing that is downloading form the web...

Ram.</description>
		<content:encoded><![CDATA[<p>I do agree that an anti virus need to be up-to-date and shield your computer, so if the file contain a virus it know it will tell you, or stop the virus.</p>
<p>To &#8216;let people read the source code&#8217; is not the best way, after all not all the user know how to read code&#8230;</p>
<p>a file signature is a good method it can work but not all the time.</p>
<p>I just think users need to be alerted that virus live among us, and to double check any thing that is downloading form the web&#8230;</p>
<p>Ram.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Té</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-48586</link>
		<dc:creator>Té</dc:creator>
		<pubDate>Sun, 14 Feb 2010 19:41:37 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-48586</guid>
		<description>@tricks

He&#039;s probably talking about the drama with Ad-block Plus.
http://www.schillmania.com/content/entries/2009/adblock-vs-noscript/


@Doelf

I haven&#039;t checked, so I&#039;m not sure about exact numbers, but I do remember that Sothink Video Downloader where pointed to as the major infector with Master Filer only contributing a minor amount of downloads.

Now that Sothink Video Downloader has been shown to have been a false positive the only infector is Master Filer, which only made out a minor part of the downloads.

That is, at first it were Sothink Video Downloader downloads (~5000) + Master Filer downloads (~700) = total downloads (~6000) and now, after more thorough checks, it&#039;s Master Filer downloads (~700) = total downloads (~700).

Also, it&#039;s important to remember that Mozilla isn&#039;t the only one hosting add-ons.</description>
		<content:encoded><![CDATA[<p>@tricks</p>
<p>He&#8217;s probably talking about the drama with Ad-block Plus.<br />
<a href="http://www.schillmania.com/content/entries/2009/adblock-vs-noscript/" rel="nofollow">http://www.schillmania.com/content/entries/2009/adblock-vs-noscript/</a></p>
<p>@Doelf</p>
<p>I haven&#8217;t checked, so I&#8217;m not sure about exact numbers, but I do remember that Sothink Video Downloader where pointed to as the major infector with Master Filer only contributing a minor amount of downloads.</p>
<p>Now that Sothink Video Downloader has been shown to have been a false positive the only infector is Master Filer, which only made out a minor part of the downloads.</p>
<p>That is, at first it were Sothink Video Downloader downloads (~5000) + Master Filer downloads (~700) = total downloads (~6000) and now, after more thorough checks, it&#8217;s Master Filer downloads (~700) = total downloads (~700).</p>
<p>Also, it&#8217;s important to remember that Mozilla isn&#8217;t the only one hosting add-ons.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bee</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-48548</link>
		<dc:creator>Bee</dc:creator>
		<pubDate>Sun, 14 Feb 2010 17:23:33 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-48548</guid>
		<description>Hi tricks!!!!!!!

I don&#039;t want to write it again!!!!!!!!!!!It&#039;s so boring!!!!!!! but I wrote something about NoScript&#039;s history one week ago, here http://forums.lanik.us/viewtopic.php?f=86&amp;t=5809 you could read it there!!!!!!!!!! follow the links!!!!!!!

bye!!!!!!!!!!!!!!!!!!!
~bee!!!!!!!!!!
http://honeybeenet.altervista.org/beefree/</description>
		<content:encoded><![CDATA[<p>Hi tricks!!!!!!!</p>
<p>I don&#8217;t want to write it again!!!!!!!!!!!It&#8217;s so boring!!!!!!! but I wrote something about NoScript&#8217;s history one week ago, here <a href="http://forums.lanik.us/viewtopic.php?f=86&#038;t=5809" rel="nofollow">http://forums.lanik.us/viewtopic.php?f=86&#038;t=5809</a> you could read it there!!!!!!!!!! follow the links!!!!!!!</p>
<p>bye!!!!!!!!!!!!!!!!!!!<br />
~bee!!!!!!!!!!<br />
<a href="http://honeybeenet.altervista.org/beefree/" rel="nofollow">http://honeybeenet.altervista.org/beefree/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: tricks</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-47788</link>
		<dc:creator>tricks</dc:creator>
		<pubDate>Fri, 12 Feb 2010 21:10:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-47788</guid>
		<description>What is this about NO SCRIPTS history? I thought NO SCRIPTS was a good security program. I run it now, is there a reason I should remove it?</description>
		<content:encoded><![CDATA[<p>What is this about NO SCRIPTS history? I thought NO SCRIPTS was a good security program. I run it now, is there a reason I should remove it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Doelf</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-47659</link>
		<dc:creator>Doelf</dc:creator>
		<pubDate>Fri, 12 Feb 2010 14:34:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-47659</guid>
		<description>Last time you said Master Filer was downloaded 600 times, now the number is reduced from 6,000 to 700 times. So: How many?</description>
		<content:encoded><![CDATA[<p>Last time you said Master Filer was downloaded 600 times, now the number is reduced from 6,000 to 700 times. So: How many?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: annoyed</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-47421</link>
		<dc:creator>annoyed</dc:creator>
		<pubDate>Thu, 11 Feb 2010 23:59:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-47421</guid>
		<description>&lt;i&gt;t the very least, those non-Mozilla-approved plugins should be with displayed a STERN warning – “Mozilla has not tested this plugin for vulnerabilities – Use at your own RISK”.&lt;/i&gt;
You mean with something like the big fat &quot;Install add-ons only from authors you trust&quot; warning dialog that already appears when installing *any* add-on and also says &quot;Malicious software can damage your computer or violate your privacy&quot;? How much more hand-holding do you need?</description>
		<content:encoded><![CDATA[<p><i>t the very least, those non-Mozilla-approved plugins should be with displayed a STERN warning – “Mozilla has not tested this plugin for vulnerabilities – Use at your own RISK”.</i><br />
You mean with something like the big fat &#8220;Install add-ons only from authors you trust&#8221; warning dialog that already appears when installing *any* add-on and also says &#8220;Malicious software can damage your computer or violate your privacy&#8221;? How much more hand-holding do you need?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David Gerard</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-47369</link>
		<dc:creator>David Gerard</dc:creator>
		<pubDate>Thu, 11 Feb 2010 20:23:48 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-47369</guid>
		<description>&lt;i&gt;&quot;Would be nice if add-ons with files that aren’t open-source were marked in some way.&quot;&lt;/i&gt;

+1

Big red warnings for:

* binaries
* closed source</description>
		<content:encoded><![CDATA[<p><i>&#8220;Would be nice if add-ons with files that aren’t open-source were marked in some way.&#8221;</i></p>
<p>+1</p>
<p>Big red warnings for:</p>
<p>* binaries<br />
* closed source</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Té</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-46977</link>
		<dc:creator>Té</dc:creator>
		<pubDate>Wed, 10 Feb 2010 19:47:43 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-46977</guid>
		<description>Would be nice if add-ons with files that aren&#039;t open-source were marked in some way.

@anon
They are tested. But the anti-virus used just didn&#039;t know about that trojan. Any usable anti-virus and anti-malware program work using blacklists. But they use three programs now instead of just one, if I remember correctly, which is what caught this particular bug.
You&#039;re an ignorant fool if you think you&#039;re 100% safe just because a program tells you so.

There&#039;s also no reason to not allow non-approved to be listed on the &quot;untested&quot; page. The same users who installed this extension might as well have downloaded some random &quot;increase your internet speed by 150%&quot; application from some other place.

The correct way to create a secure environment are through education and not censorship.</description>
		<content:encoded><![CDATA[<p>Would be nice if add-ons with files that aren&#8217;t open-source were marked in some way.</p>
<p>@anon<br />
They are tested. But the anti-virus used just didn&#8217;t know about that trojan. Any usable anti-virus and anti-malware program work using blacklists. But they use three programs now instead of just one, if I remember correctly, which is what caught this particular bug.<br />
You&#8217;re an ignorant fool if you think you&#8217;re 100% safe just because a program tells you so.</p>
<p>There&#8217;s also no reason to not allow non-approved to be listed on the &#8220;untested&#8221; page. The same users who installed this extension might as well have downloaded some random &#8220;increase your internet speed by 150%&#8221; application from some other place.</p>
<p>The correct way to create a secure environment are through education and not censorship.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Veditz</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-46975</link>
		<dc:creator>Daniel Veditz</dc:creator>
		<pubDate>Wed, 10 Feb 2010 19:37:01 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-46975</guid>
		<description>This incident says nothing about reviewed addons on AMO (other than don&#039;t put all your anti-virus eggs in one basket). Average users should not be installing untrusted, unreviewed, &quot;experimental&quot; addons and this incident does point out that the site is not at all clear that the intended audience for unreviewed addons (hard-core testers and experimenters) is very very different than the general Add-ons user.</description>
		<content:encoded><![CDATA[<p>This incident says nothing about reviewed addons on AMO (other than don&#8217;t put all your anti-virus eggs in one basket). Average users should not be installing untrusted, unreviewed, &#8220;experimental&#8221; addons and this incident does point out that the site is not at all clear that the intended audience for unreviewed addons (hard-core testers and experimenters) is very very different than the general Add-ons user.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matti</title>
		<link>http://blog.mozilla.com/addons/2010/02/09/update-on-the-amo-security-issue/comment-page-1/#comment-46963</link>
		<dc:creator>Matti</dc:creator>
		<pubDate>Wed, 10 Feb 2010 18:48:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/addons/?p=1309#comment-46963</guid>
		<description>@Bee: Your &quot;!&quot; key is broken, you should get a new keyboard.

2 things :
This 2 experimental addons and you need an AMO Account if you want to download such addons

&gt;Download only extensions that YOU trust
That is true, always install Software (not only Addons) that you thrust.
There is no difference between &quot;normal&quot; applications, plugins and addons.</description>
		<content:encoded><![CDATA[<p>@Bee: Your &#8220;!&#8221; key is broken, you should get a new keyboard.</p>
<p>2 things :<br />
This 2 experimental addons and you need an AMO Account if you want to download such addons</p>
<p>&gt;Download only extensions that YOU trust<br />
That is true, always install Software (not only Addons) that you thrust.<br />
There is no difference between &#8220;normal&#8221; applications, plugins and addons.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

