Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Phishers Luring Mules into Money Scams | Main | NIST Recommends Penetration Testing »

Firefox 3 Brings More Security Features

Firefox 3 is in beta 2 now and with the new release comes some welcome features, like better protection against some forms of cross site data leaks, easier access to SSL certificate details, and anti-malware protection (via blacklists). Support for Extended Validation (EV) Certificates is coming later. (Internet Explorer 7 has EV SSL support now and you can get an add-on from Verisign that works with Verisign, Thawte, and GeoTrust certificates, but not others.) Here are some of the key features according to Mozilla's release notes:

* One-click site info: Click the site favicon in the location bar to see who owns the site. Identity verification is prominently displayed and easier to understand. In later versions, Extended Validation SSL certificate information will be displayed.
* Malware Protection: malware protection warns users when they arrive at sites which are known to install viruses, spyware, trojans or other malware. You can test it here (note: our blacklist of malware sites is not yet activated).
* New Web Forgery Protection page: the content of pages suspected as web forgeries is no longer shown. You can test it here.
* New SSL error pages: clearer and stricter error pages are used when Firefox encounters an invalid SSL certificate.
* Add-ons and Plugin version check: Firefox now automatically checks add-on and plugin versions and will disable older, insecure versions.
* Secure add-on updates: to improve add-on update security, add-ons that provide updates in an insecure manner will be disabled.
* Anti-virus integration: Firefox will inform anti-virus software when downloading executables.
* Vista Parental Controls: Firefox now respects the Vista system-wide parental control setting for disabling file downloads.
* [Improved in Beta 2!] Effective top-level domain (eTLD) service better restricts cookies and other restricted content to a single domain.
* [Improved in Beta 2!] Better protection against cross-site JSON data leaks.

ComputerWorld also has an article its 5 favorite features in Firefox 3 that covers some non-security features.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/575

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net