<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: A Glimpse Into the Future of Browser Security</title>
	<atom:link href="http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/</link>
	<description></description>
	<lastBuildDate>Fri, 11 Nov 2011 11:23:21 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Tom T.</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-108163</link>
		<dc:creator>Tom T.</dc:creator>
		<pubDate>Wed, 21 Oct 2009 00:56:46 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-108163</guid>
		<description>@ home computer:
&quot;and the possibility to choose our own search engine and not the ones that have been pre-choosen by Mozilla (i.e. Scroogle &quot;

Or you can just do what I did: Delete all search engines from FX and bookmark Scroogle. Two clicks to search. End of problem.  If you can&#039;t manage the two clicks, there was code somewhere about how to add Scroogle or anything else to your search engine list. Search the MZ instructions. 

[off-topic political commentary deleted --dveditz]</description>
		<content:encoded><![CDATA[<p>@ home computer:<br />
&#8220;and the possibility to choose our own search engine and not the ones that have been pre-choosen by Mozilla (i.e. Scroogle &#8221;</p>
<p>Or you can just do what I did: Delete all search engines from FX and bookmark Scroogle. Two clicks to search. End of problem.  If you can&#8217;t manage the two clicks, there was code somewhere about how to add Scroogle or anything else to your search engine list. Search the MZ instructions. </p>
<p>[off-topic political commentary deleted --dveditz]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Geld Lenen</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-108152</link>
		<dc:creator>Geld Lenen</dc:creator>
		<pubDate>Tue, 20 Oct 2009 11:52:45 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-108152</guid>
		<description>As rvdh states, the web has become a landscape for profit making folks. I read an article that a distributor of scare-ware earned 3 times the amount that Obama makes :o</description>
		<content:encoded><![CDATA[<p>As rvdh states, the web has become a landscape for profit making folks. I read an article that a distributor of scare-ware earned 3 times the amount that Obama makes <img src='http://blog.mozilla.com/security/wp-includes/images/smilies/icon_surprised.gif' alt=':o' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-108029</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Thu, 15 Oct 2009 09:56:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-108029</guid>
		<description>This sounds like a recipe for yet more governance bloat on the web.. if you want a secure environment for your users then secure your applications properly so that these kind of mechanisms are not necessary.

Browsers are already bloated, this is just adding to the problem and creating a patched solution for the underlying problem: web developers don&#039;t use adequate tooling to prevent serving their users threatening content.

This is not a sensible solution.</description>
		<content:encoded><![CDATA[<p>This sounds like a recipe for yet more governance bloat on the web.. if you want a secure environment for your users then secure your applications properly so that these kind of mechanisms are not necessary.</p>
<p>Browsers are already bloated, this is just adding to the problem and creating a patched solution for the underlying problem: web developers don&#8217;t use adequate tooling to prevent serving their users threatening content.</p>
<p>This is not a sensible solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rvdh</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-108022</link>
		<dc:creator>rvdh</dc:creator>
		<pubDate>Thu, 15 Oct 2009 00:51:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-108022</guid>
		<description>@home computer

As much as I prefer Opera as my main browser, I think you are somewhat disappointed by Firefox, for reasons I might understand. However, that isn&#039;t a valid argument against the folks who are trying to implement a security policy -we (or almost) all- we&#039;re waiting for. Content restriction is a serious and -by far- underrated issue that had to be addressed at some point. The day of the &quot;happy open web&quot; is over, it has become a landscape of marketeers and mostly profit making folks who aren&#039;t interested in your well-being. The news hat Mozilla is taking the torch of content restriction is a good sign, and we should encourage that instead of radiating our personal opinions of Mozilla -or- Firefox. I know very well that hundreds of developers spent countless hours on Firefox, giving their free time to make a change on the web. Albeit, some choices of Mozilla will affect &amp; influence security of the browser (like plugin support), one must not forget that you do have the ability to modify/adjust Firefox to your needs, the choice is given to you, whereas many other browser vendors limit this very freedom.</description>
		<content:encoded><![CDATA[<p>@home computer</p>
<p>As much as I prefer Opera as my main browser, I think you are somewhat disappointed by Firefox, for reasons I might understand. However, that isn&#8217;t a valid argument against the folks who are trying to implement a security policy -we (or almost) all- we&#8217;re waiting for. Content restriction is a serious and -by far- underrated issue that had to be addressed at some point. The day of the &#8220;happy open web&#8221; is over, it has become a landscape of marketeers and mostly profit making folks who aren&#8217;t interested in your well-being. The news hat Mozilla is taking the torch of content restriction is a good sign, and we should encourage that instead of radiating our personal opinions of Mozilla -or- Firefox. I know very well that hundreds of developers spent countless hours on Firefox, giving their free time to make a change on the web. Albeit, some choices of Mozilla will affect &amp; influence security of the browser (like plugin support), one must not forget that you do have the ability to modify/adjust Firefox to your needs, the choice is given to you, whereas many other browser vendors limit this very freedom.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Veditz</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-107955</link>
		<dc:creator>Daniel Veditz</dc:creator>
		<pubDate>Fri, 02 Oct 2009 20:08:00 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-107955</guid>
		<description>You&#039;re right: if the server itself is compromised all bets are off. XSS attacks, however, inject content into a web application without actually compromising the underlying server configuration. CSP does nothing to help a site secure its network or machines, but it does provide a back-stop to catch programming bugs in the web application layer.</description>
		<content:encoded><![CDATA[<p>You&#8217;re right: if the server itself is compromised all bets are off. XSS attacks, however, inject content into a web application without actually compromising the underlying server configuration. CSP does nothing to help a site secure its network or machines, but it does provide a back-stop to catch programming bugs in the web application layer.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Johnathan Nightingale</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-107954</link>
		<dc:creator>Johnathan Nightingale</dc:creator>
		<pubDate>Fri, 02 Oct 2009 20:00:10 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-107954</guid>
		<description>@Andrew - typically the way sites are exploited in an XSS attack is that some facet of the site allows users to add content to the page (a comment box on a blog, a review box on a shopping site, &amp;c) and the attacker includes malicious content in their submission. CSP is delivered as a header, and points to a standalone policy file - neither of which are part of the web page itself, so an attacker is unlikely to be able to change them unless that attacker has full control of the server itself, in which case no client-based defense will be sufficient.</description>
		<content:encoded><![CDATA[<p>@Andrew &#8211; typically the way sites are exploited in an XSS attack is that some facet of the site allows users to add content to the page (a comment box on a blog, a review box on a shopping site, &amp;c) and the attacker includes malicious content in their submission. CSP is delivered as a header, and points to a standalone policy file &#8211; neither of which are part of the web page itself, so an attacker is unlikely to be able to change them unless that attacker has full control of the server itself, in which case no client-based defense will be sufficient.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andrew</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-107953</link>
		<dc:creator>Andrew</dc:creator>
		<pubDate>Fri, 02 Oct 2009 19:26:18 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-107953</guid>
		<description>Hi.

If a site has been compromised won&#039;t the attacker just add their dodgy domain to the list of domains that are okay?  So you could go to Google but also download the dodgy iFrame at the same time cause the modified CSP would say it is okay?  I am trying to understand how the new protection would actually make me safer on the web.</description>
		<content:encoded><![CDATA[<p>Hi.</p>
<p>If a site has been compromised won&#8217;t the attacker just add their dodgy domain to the list of domains that are okay?  So you could go to Google but also download the dodgy iFrame at the same time cause the modified CSP would say it is okay?  I am trying to understand how the new protection would actually make me safer on the web.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel Veditz</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-107952</link>
		<dc:creator>Daniel Veditz</dc:creator>
		<pubDate>Fri, 02 Oct 2009 15:54:54 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-107952</guid>
		<description>@home computer:

We never said XSS protection was &quot;enough&quot;, but we can&#039;t talk about everything all the time. In this post we&#039;re talking about Content Security Policy. CSP has a different focus from the features you mention, which are about how a web surfer can customize their experience. CSP is focused on letting site authors declare the expected content of each page so the browser can help prevent unintended content from being injected.

Apart from CSP, plain vanilla Firefox can block cookies and images per site, and on a global basis you can disable JavaScript and Flash (and/or other plugins). You can also disable the Referer header but that requires twiddling an &quot;about:config&quot; settings. The average web surfer does not use those features, but yeah, if you&#039;re in the power-user minority that needs more than that then you have to install an add-on to get the full per-site flexibility Opera has &#039;out of the box&#039;.

I don&#039;t understand your complaint about the search engine choice. Like Opera we default to a Google search. Like Opera there&#039;s a drop-down that lets you switch engines with a handful of preinstalled choices (a lot of the same choices, like Yahoo, Wikipedia, Amazon, eBay, Answers.com). Like Opera you can add more. We even provide a link to our addons site where we have hundreds of choices. And you can right-click on any search form in any page, anywhere to create a keyword search you can later access from the URL bar at any time

But really, if you prefer Opera that&#039;s fine by us. A Firefox monopoly would be a failure of our mission to bring choice and innovation to the internet.</description>
		<content:encoded><![CDATA[<p>@home computer:</p>
<p>We never said XSS protection was &#8220;enough&#8221;, but we can&#8217;t talk about everything all the time. In this post we&#8217;re talking about Content Security Policy. CSP has a different focus from the features you mention, which are about how a web surfer can customize their experience. CSP is focused on letting site authors declare the expected content of each page so the browser can help prevent unintended content from being injected.</p>
<p>Apart from CSP, plain vanilla Firefox can block cookies and images per site, and on a global basis you can disable JavaScript and Flash (and/or other plugins). You can also disable the Referer header but that requires twiddling an &#8220;about:config&#8221; settings. The average web surfer does not use those features, but yeah, if you&#8217;re in the power-user minority that needs more than that then you have to install an add-on to get the full per-site flexibility Opera has &#8216;out of the box&#8217;.</p>
<p>I don&#8217;t understand your complaint about the search engine choice. Like Opera we default to a Google search. Like Opera there&#8217;s a drop-down that lets you switch engines with a handful of preinstalled choices (a lot of the same choices, like Yahoo, Wikipedia, Amazon, eBay, Answers.com). Like Opera you can add more. We even provide a link to our addons site where we have hundreds of choices. And you can right-click on any search form in any page, anywhere to create a keyword search you can later access from the URL bar at any time</p>
<p>But really, if you prefer Opera that&#8217;s fine by us. A Firefox monopoly would be a failure of our mission to bring choice and innovation to the internet.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: home computer</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-107951</link>
		<dc:creator>home computer</dc:creator>
		<pubDate>Fri, 02 Oct 2009 14:32:02 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-107951</guid>
		<description>XSS protection ok but not enough. We want a really secure browser (which Firefox is NOT by far) that is able -without add-ons- to also block on demand:
cookies (Opera has it)
referrers (Opera has it)
javascript (Opera has it)
flash (Opera has it, Plugins off)

external active content (firewall)
hidden frames (firewall)
webbugs (firewall, pixel webbugs)
XXS protect (firewall)
add-servers, most Google shit (firewall)
modified Hosts file 

and the possibility to choose our own search engine and not the ones that have been pre-choosen by Mozilla (i.e. Scroogle in stead of that
intrusive Google shit, which is the biggest thread to privacy ever !)
Mozilla sold out to Google, i never will.

Until that day arrives I will stay with Opera (10) (and never ever use Firefox) combined with webcontrol by a third party firewall. 

Still a long way to go for Firefox intill it will be a secure browser.</description>
		<content:encoded><![CDATA[<p>XSS protection ok but not enough. We want a really secure browser (which Firefox is NOT by far) that is able -without add-ons- to also block on demand:<br />
cookies (Opera has it)<br />
referrers (Opera has it)<br />
javascript (Opera has it)<br />
flash (Opera has it, Plugins off)</p>
<p>external active content (firewall)<br />
hidden frames (firewall)<br />
webbugs (firewall, pixel webbugs)<br />
XXS protect (firewall)<br />
add-servers, most Google shit (firewall)<br />
modified Hosts file </p>
<p>and the possibility to choose our own search engine and not the ones that have been pre-choosen by Mozilla (i.e. Scroogle in stead of that<br />
intrusive Google shit, which is the biggest thread to privacy ever !)<br />
Mozilla sold out to Google, i never will.</p>
<p>Until that day arrives I will stay with Opera (10) (and never ever use Firefox) combined with webcontrol by a third party firewall. </p>
<p>Still a long way to go for Firefox intill it will be a secure browser.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Julian Reschke</title>
		<link>http://blog.mozilla.com/security/2009/09/30/a-glimpse-into-the-future-of-browser-security/comment-page-1/#comment-107950</link>
		<dc:creator>Julian Reschke</dc:creator>
		<pubDate>Fri, 02 Oct 2009 14:19:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=176#comment-107950</guid>
		<description>It appears CSP allows multiple header instances, but fails to use the single syntax allowed for that (see : &quot;Multiple message-header fields with the same field-name MAY be present in a message if and only if the entire field-value for that header field is defined as a comma-separated list [i.e., #(values)].&quot;</description>
		<content:encoded><![CDATA[<p>It appears CSP allows multiple header instances, but fails to use the single syntax allowed for that (see : &#8220;Multiple message-header fields with the same field-name MAY be present in a message if and only if the entire field-value for that header field is defined as a comma-separated list [i.e., #(values)].&#8221;</p>
]]></content:encoded>
	</item>
</channel>
</rss>

