Showing posts with label Firefox. Show all posts
Showing posts with label Firefox. Show all posts

Thursday, February 7, 2013

Nerd News: Flash Update

YMMV but Firefox wasn't showing that I needed to update Flash yet, and this isn't the first time this has happened to me, perhaps they only update that once or twice a day or something?

Anyway, there is a new version of Flash out, and to avoided getting Hacked you should update/patch Flash if you use it.

This page http://www.adobe.com/software/flash/about/ will show you in a little box on right near top what version of Flash your running if you don't have it disabled.

It will even show the Chrome (Pepper Based) version of Flash.  Though you shouldn't have to worry about patching Chrome's version this way.


Below that little box, is a bigger box showing most recent versions of Flash for all OS & Browser combinations, so you can easily see if your running most current version or not.

You can download current version from here http://get.adobe.com/flashplayer/.

For Chrome, all you need to do to check, is click the Chrome Menu/three bar button, then click About Google Chrome, that will trigger update for Chrome.

Note I generally include full links so people can Google links easily, just highlight and right click "search Google for", instead of just clicking if they have any doubt about link being legit.

I do skip full links sometimes when they are just to long IMO, or I am using several in a row with text, where I feel the confusion factor vs transparency ratio gets out of whack.

You can also use siteadvisor https://www.siteadvisor.com/sites/ or WOT http://www.mywot.com/en/scorecard to check links.

Unshort.me, http://unshort.me/, is also a very useful tool, it will unshorten URL from Twitter or whatever, so you can see real target without having to go to site.

I tend to use siteadvisor, which is a McAfee service, don't like their AV but do like siteadvisor, I tend to use WOT for things not on siteadvisor or for "gray" sites.

Wednesday, January 9, 2013

Security & Hacking: Adobe & Microsoft Update Patches

http://krebsonsecurity.com/2013/01/adobe-microsoft-ship-critical-security-updates/

http://www.livehacking.com/2013/01/09/in-brief-adobe-fixes-at-least-26-security-problems-in-adobe-acrobat-and-adobe-reader/

Short Version:  Make sure your Updated & Patched!

Also, use Firefox with Noscript (Addblockplus as well is good idea, you can Whitelist ie allow sites you want to support or trust) or Chrome, (again with Addblockplus) Chrome has functionality that is similar to Noscript!

Stop using IE unless your forced to, if your forced to use IE set updates to auto AND check updates second Wednesday (Microsoft issues patches every second Tuesday, but checking Wednesday you generally avoid checking to early in the day, and also usually have bit faster download speeds).

Wednesday, October 24, 2012

Security & Hacking: Hacker Halted "Malicious Browser Extensions"

See http://www.prweb.com/releases/browserextensions/ZoltanBalazs/prweb9802144.htm and http://www.computerworld.com/s/article/9232848/Researcher_to_demonstrate_feature_rich_malware_that_works_as_a_browser_extension
for full story.

Short version, based on my understanding, is that this is a presentation by Zoltan Balazs, with Proof of Concept of an extension that the user has to be tricked into installing with Firefox (ie Social Engineering).

On the other hand, with Chrome it would need to get on official Chrome Store, so much higher barrier for success on Chrome.

If user makes the mistake of installing this malware on their browser, then they are pretty much pwned.

Defeats security of at least some types of Two Factor Authentication, they specifically mention Google's.

Two things stood out to me, quoted below from the Computerworld aricle:
"Chrome's support for Native Client (NaCl), a sandboxing technology that allows Web applications to run C or C++ code inside the browser, can be leveraged by the Chrome extension to efficiently crack password hashes."

"The Safari version was easy to create because Chrome extensions can be easily converted to Safari extensions, Balazs said."

Related links:

Sunday, June 17, 2012

Interesting Software

http://portableapps.com/

Heard this mentioned on recent Security Now podcast, a listener emailed them that he runs "portable Firefox from PortableApps.com in my Dropbox" so all his Tabs are synced, said he has being doing that for years.

Just thought that was such a neat idea, that I had to blog it, figured people might build on it and think of some more creative solutions to problems.

Thursday, January 5, 2012

Nerd News: Firefox ditching 3.6 this April

Full story at http://www.ghacks.net/2012/01/05/firefox-3-6-support-to-end-on-april-24-2012/

This really annoys me, I like a lot of features that Firefox offers.

But they really changed some of the core elements of the UI with all the versions after 3.6 and I will start looking at other browsers to use because of this, probably end up with Chrome, even though there are things I really don't like about it.

Chrome will be more user friendly for my blogging, among some other key features.

From several reports I have seen over the years, users of Firefox tended to update to current version at much higher % and much faster than most of the other main browsers.  That changed with Firefox 4, but Mozilla doesn't seem to care, or even ask why that changed.

I know the majority of my readers use Firefox, any thoughts or comments from you?

I'll note that Chrome is in a very close 2nd place to Firefox for my readers, I'm betting that is going to change this year, and Chrome will be way ahead of Firefox.

Also Firefox + Chrome = 68% of my readers.  Maybe someone from Firefox will read this, and respond.