Advertisement
Promo

Security threats Toolkit

Firefox 3 final beta to be released in March

Tom Espiner ZDNet.co.uk

Published: 26 Feb 2008 15:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Firefox 3 edges closer to release, with the fourth and final beta of the web browser out "in a couple of weeks", according to Mozilla's vice president of engineering, Mike Schroepfer.

The final Firefox 3 beta release will address issues including memory usage and cross-site XML HTTP requests. Memory usage has been improved in the final release version of Firefox 3 by rewriting "big chunks of the core Firefox code" and tuning the core scripting engine, according to Schroepfer.

Talking to ZDNet.co.uk on Monday, Schroepfer said that security had also been beefed up in Firefox 3. A major security concern for browser developers is browser susceptibility to cross-site scripting attacks (XSS), where code that can exploit browser vulnerabilities is injected into web pages.

Firefox 3 has secure cross-site XML HTTP requests, based on an emerging standard Mozilla, Google and others are developing, said Schroepfer. The standard allows websites to securely exchange information, he added. Essentially whitelists, cross-site XML HTTP request capabilities in browsers negate the need to embed iFrames in websites, which can be exploited, said Schroepfer.

Read this

Q&A
Q&A: When more bugs can mean tighter security

Mozilla Europe's president Tristan Nitot explains why having fewer disclosed vulnerabilities doesn't mean Internet Explorer is safer than the open-source web browser

Read more +

"People are building sites but they're using hacks, including the site having embedded iFrames," said Schroepfer. "People are building complicated [web-facing] mashups, but big sources of attacks are cross-site scripting bugs or problems with implementation."

As well as including secure cross-site XML HTTP requests, Schroepfer said that the final version of Firefox 3 will have anti-malware capabilities. Firefox 3 will block web access to sites blacklisted by StopBadware.org, an organisation contributed to by Google and Mozilla, which lists potentially compromised websites.

"[Firefox] will check against the local list to make sure the URL isn't on the [StopBadware.org] blacklist," said Schroepfer.

This capability is already in the current beta version the browser, Firefox 3 beta 3. Schoepfer said that a "couple of weeks ago" the blacklist utility had a real-world test when the Firebug site got hacked.

"Firebug, the Mozilla debugging website, got hacked, with malware [injected] on the site" said Schroepfer. "Firefox blocked access to the site, which we thought initially was a bug in Firefox. Actually, it really worked."

Schroepfer added that the third beta of Firefox 3 had proved popular, saying it had gained half a million active users since its release on 12 February 12.

When Mozilla started to develop Firefox 3, Schroepfer said the organisation had started an in-depth security review process, with "security experts" and Mozilla developers going through each new feature in detail to discuss possible attack vectors and privacy implications of Firefox features.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
18 out of 18 people found this useful


Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Climate research centre compromised

One of the UK's leading climate change research centres has had a security breach. The Climate Research Unit at the University of East Anglia (UEA) suffered a compromise of information,... More

1 comment

Government web-monitoring plans on hol...

Government plans to compel ISPs to process and store details of all web communications have been put on hold until after the next election. The Home Office told ZDNet UK on Wednesday... More

1 comment

Watchdog reveals illegal sale of phone...

The Information Commissioner's Office is preparing a prosecution file against a mobile operator's employees who allegedly sold on thousands of customers' details to a competitor. The... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters