ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Firefox 3 final beta to be released in March

Tom Espiner ZDNet.co.uk

Published: 26 Feb 2008 15:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Firefox 3 edges closer to release, with the fourth and final beta of the web browser out "in a couple of weeks", according to Mozilla's vice president of engineering, Mike Schroepfer.

The final Firefox 3 beta release will address issues including memory usage and cross-site XML HTTP requests. Memory usage has been improved in the final release version of Firefox 3 by rewriting "big chunks of the core Firefox code" and tuning the core scripting engine, according to Schroepfer.

Talking to ZDNet.co.uk on Monday, Schroepfer said that security had also been beefed up in Firefox 3. A major security concern for browser developers is browser susceptibility to cross-site scripting attacks (XSS), where code that can exploit browser vulnerabilities is injected into web pages.

Firefox 3 has secure cross-site XML HTTP requests, based on an emerging standard Mozilla, Google and others are developing, said Schroepfer. The standard allows websites to securely exchange information, he added. Essentially whitelists, cross-site XML HTTP request capabilities in browsers negate the need to embed iFrames in websites, which can be exploited, said Schroepfer.

Read this

Q&A
Q&A: When more bugs can mean tighter security

Mozilla Europe's president Tristan Nitot explains why having fewer disclosed vulnerabilities doesn't mean Internet Explorer is safer than the open-source web browser

Read more +

"People are building sites but they're using hacks, including the site having embedded iFrames," said Schroepfer. "People are building complicated [web-facing] mashups, but big sources of attacks are cross-site scripting bugs or problems with implementation."

As well as including secure cross-site XML HTTP requests, Schroepfer said that the final version of Firefox 3 will have anti-malware capabilities. Firefox 3 will block web access to sites blacklisted by StopBadware.org, an organisation contributed to by Google and Mozilla, which lists potentially compromised websites.

"[Firefox] will check against the local list to make sure the URL isn't on the [StopBadware.org] blacklist," said Schroepfer.

This capability is already in the current beta version the browser, Firefox 3 beta 3. Schoepfer said that a "couple of weeks ago" the blacklist utility had a real-world test when the Firebug site got hacked.

"Firebug, the Mozilla debugging website, got hacked, with malware [injected] on the site" said Schroepfer. "Firefox blocked access to the site, which we thought initially was a bug in Firefox. Actually, it really worked."

Schroepfer added that the third beta of Firefox 3 had proved popular, saying it had gained half a million active users since its release on 12 February 12.

When Mozilla started to develop Firefox 3, Schroepfer said the organisation had started an in-depth security review process, with "security experts" and Mozilla developers going through each new feature in detail to discuss possible attack vectors and privacy implications of Firefox features.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
18 out of 18 people found this useful



Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Software Tester, Testing/Quality Professional and Mentor?

To apply or request more information, submit your CV via this website. Software Tester, Testing/Quality Professional and Mentor? Has your knowledge ...

Technical Support Engineers up to 35k + Benefits Bracknell

This role will see you working with my clients product, reporting bugs and enhancement requests to engineering, diagnose and resolve customer ...

ITIL Red Badge - Could You Deliver Training?

To apply or request more information, submit your CV via this website. ITIL Red Badge - Could You Deliver Training? Consider yourself personable, an ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation