<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Measure What Matters &#8211; The SEC Essentials</title>
	<atom:link href="http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/</link>
	<description></description>
	<lastBuildDate>Thu, 19 Nov 2009 15:36:11 -0800</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Daniel Veditz</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105864</link>
		<dc:creator>Daniel Veditz</dc:creator>
		<pubDate>Tue, 09 Jun 2009 17:41:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105864</guid>
		<description>Paul: sorry you keep getting infected, but are you sure it&#039;s Firefox? We are aware of no &quot;in-the-wild&quot; exploits that affect recent versions of Firefox 3, and it&#039;s not just our small team looking, we are also contacted by internet security firms and researchers when they come across new attacks. What we do see is a lot of attacks on old plugins since their ubiquity makes them profitable multi-browser targets.

Please make sure your plugins are updated to the most recent version from their respective vendors and see if that helps. And don&#039;t forget to check external document viewers like Adobe Reader and Microsoft Word.

If you&#039;re still getting infected after that I would love to get a copy of your browser history if you&#039;re willing to share it. If so contact us at security@mozilla.org</description>
		<content:encoded><![CDATA[<p>Paul: sorry you keep getting infected, but are you sure it&#8217;s Firefox? We are aware of no &#8220;in-the-wild&#8221; exploits that affect recent versions of Firefox 3, and it&#8217;s not just our small team looking, we are also contacted by internet security firms and researchers when they come across new attacks. What we do see is a lot of attacks on old plugins since their ubiquity makes them profitable multi-browser targets.</p>
<p>Please make sure your plugins are updated to the most recent version from their respective vendors and see if that helps. And don&#8217;t forget to check external document viewers like Adobe Reader and Microsoft Word.</p>
<p>If you&#8217;re still getting infected after that I would love to get a copy of your browser history if you&#8217;re willing to share it. If so contact us at <a href="mailto:security@mozilla.org">security@mozilla.org</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Paul_Bags</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105861</link>
		<dc:creator>Paul_Bags</dc:creator>
		<pubDate>Tue, 09 Jun 2009 09:24:28 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105861</guid>
		<description>I&#039;ve been getting constant trojans for the last month or so while browsing with firefox. It is the only program running at the time, and the only possible source of these instances of malicious code running on my machine. It occurs after restoring from backup hard drive images, as well as complete, clean, reinstalls.

In my eyes both the quality and security of firefox has been declining for a long time, and I am seriously considering ditching it for something else. However I still prefer the firefox interface, I&#039;m comfortable with it, and I hold out hope for a return to the brilliance, stability, and security once inherent to firefox.</description>
		<content:encoded><![CDATA[<p>I&#8217;ve been getting constant trojans for the last month or so while browsing with firefox. It is the only program running at the time, and the only possible source of these instances of malicious code running on my machine. It occurs after restoring from backup hard drive images, as well as complete, clean, reinstalls.</p>
<p>In my eyes both the quality and security of firefox has been declining for a long time, and I am seriously considering ditching it for something else. However I still prefer the firefox interface, I&#8217;m comfortable with it, and I hold out hope for a return to the brilliance, stability, and security once inherent to firefox.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Mitchell</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105851</link>
		<dc:creator>Bill Mitchell</dc:creator>
		<pubDate>Mon, 01 Jun 2009 11:56:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105851</guid>
		<description>Can I remove IE from my system? I run latest Firefox/w, XP Pro SP3. Still get MS updates? Going blind so need Zoom Text, built for IE. I got it to work with Firefox! A vet hacking my way in the dark. Still have a need for speed. Thanks for your valued time.</description>
		<content:encoded><![CDATA[<p>Can I remove IE from my system? I run latest Firefox/w, XP Pro SP3. Still get MS updates? Going blind so need Zoom Text, built for IE. I got it to work with Firefox! A vet hacking my way in the dark. Still have a need for speed. Thanks for your valued time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fill</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105838</link>
		<dc:creator>Fill</dc:creator>
		<pubDate>Wed, 20 May 2009 06:47:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105838</guid>
		<description>I use NoScript and FlashBlock. 	I refused to AdBlock plus because this addon led to crash Firefox. May be he not working only with me =) But addon very cool.</description>
		<content:encoded><![CDATA[<p>I use NoScript and FlashBlock. 	I refused to AdBlock plus because this addon led to crash Firefox. May be he not working only with me =) But addon very cool.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Pseudonymous Coward</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105651</link>
		<dc:creator>Pseudonymous Coward</dc:creator>
		<pubDate>Sat, 02 May 2009 15:36:06 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105651</guid>
		<description>In the light of the recent NoScript/Adblock Plus controversy, I think Mozilla Security should focus its attention on the questionable security model of its add-ons mechanism. Suggestions:

1. A strong Javascript sandbox.
2. Why on earth do extensions have such raw power in Firefox? We need a strong add-ons sandbox too.</description>
		<content:encoded><![CDATA[<p>In the light of the recent NoScript/Adblock Plus controversy, I think Mozilla Security should focus its attention on the questionable security model of its add-ons mechanism. Suggestions:</p>
<p>1. A strong Javascript sandbox.<br />
2. Why on earth do extensions have such raw power in Firefox? We need a strong add-ons sandbox too.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105602</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Wed, 29 Apr 2009 12:47:53 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105602</guid>
		<description>If your security is so good, how come I can&#039;t stop google analytics, omniture and the other ad surveys from popping up on my computer when I am in Firefox?  I don&#039;t have this happen with Safari.</description>
		<content:encoded><![CDATA[<p>If your security is so good, how come I can&#8217;t stop google analytics, omniture and the other ad surveys from popping up on my computer when I am in Firefox?  I don&#8217;t have this happen with Safari.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tristan</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105592</link>
		<dc:creator>Tristan</dc:creator>
		<pubDate>Mon, 27 Apr 2009 02:33:38 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105592</guid>
		<description>Hey Johnathan, I&#039;ve whipped up a translation in French of this post. It&#039;s located here: http://standblog.org/blog/post/2009/04/27/Mesurer-ce-qui-est-important-%3A-S%C3%A9v%C3%A9rit%C3%A9%2C-Dur%C3%A9e-d-exposition-et-Compl%C3%A8te-divulgation

You&#039;ve written an excellent post that deserves more eyeballs!</description>
		<content:encoded><![CDATA[<p>Hey Johnathan, I&#8217;ve whipped up a translation in French of this post. It&#8217;s located here: <a href="http://standblog.org/blog/post/2009/04/27/Mesurer-ce-qui-est-important-%3A-S%C3%A9v%C3%A9rit%C3%A9%2C-Dur%C3%A9e-d-exposition-et-Compl%C3%A8te-divulgation" rel="nofollow">http://standblog.org/blog/post/2009/04/27/Mesurer-ce-qui-est-important-%3A-S%C3%A9v%C3%A9rit%C3%A9%2C-Dur%C3%A9e-d-exposition-et-Compl%C3%A8te-divulgation</a></p>
<p>You&#8217;ve written an excellent post that deserves more eyeballs!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: B.J. Herbison</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105591</link>
		<dc:creator>B.J. Herbison</dc:creator>
		<pubDate>Sat, 25 Apr 2009 20:31:22 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105591</guid>
		<description>I find Mozilla lacking in the disclosure area. In particular, take a look at http://www.mozilla.org/security/ -- the last two Firefox security patch releases aren&#039;t even mentioned.  The top of the page says &quot;we understand the importance of security&quot;, but the lack of updates says &quot;we don&#039;t think security is very important&quot;.

(I&#039;ve reported lags in updating that page many time over several years. It&#039;s hard to find contacts, or at least contacts that will respond to e-mail. The page needs someone to take ownership.)</description>
		<content:encoded><![CDATA[<p>I find Mozilla lacking in the disclosure area. In particular, take a look at <a href="http://www.mozilla.org/security/" rel="nofollow">http://www.mozilla.org/security/</a> &#8212; the last two Firefox security patch releases aren&#8217;t even mentioned.  The top of the page says &#8220;we understand the importance of security&#8221;, but the lack of updates says &#8220;we don&#8217;t think security is very important&#8221;.</p>
<p>(I&#8217;ve reported lags in updating that page many time over several years. It&#8217;s hard to find contacts, or at least contacts that will respond to e-mail. The page needs someone to take ownership.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: gandalf</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105571</link>
		<dc:creator>gandalf</dc:creator>
		<pubDate>Thu, 23 Apr 2009 00:49:59 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105571</guid>
		<description>Y - &quot;You attitude&quot; - bugs that are putting me at risk should be more important -&gt; bugs that are exploitable on SPARC machines or Amiga should be less exposed than those for Windows XP</description>
		<content:encoded><![CDATA[<p>Y &#8211; &#8220;You attitude&#8221; &#8211; bugs that are putting me at risk should be more important -&gt; bugs that are exploitable on SPARC machines or Amiga should be less exposed than those for Windows XP</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Josh</title>
		<link>http://blog.mozilla.com/security/2009/04/22/measure-what-matters-the-sec-essentials/comment-page-1/#comment-105570</link>
		<dc:creator>Josh</dc:creator>
		<pubDate>Wed, 22 Apr 2009 22:16:25 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=96#comment-105570</guid>
		<description>@Jesse

&quot;Y&quot;ear over Year improvement?</description>
		<content:encoded><![CDATA[<p>@Jesse</p>
<p>&#8220;Y&#8221;ear over Year improvement?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
