Home > Security Tips > Web Security Advisor > Where's the Firefox security button?
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

Where's the Firefox security button?


Nigel McFarlane
04.25.2005
Rating: -3.33- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



What you will learn in this tip: The security options available in Firefox and how they compare to Internet Explorer's.

Anyone who has spent more than a minute or two administering a Microsoft Windows PC knows about Internet Options. It's a dialog box that you can call up from the Tools/Internet Options menu of Internet Explorer (IE). It also appears as an icon in the control panel. Inside that dialog box is the security tab, where zones are to be found. You pick a zone, and from then on the collection of features that make up that zone dictate how secure surfing the Web with IE will be. Nailing down the right zone cocktail is one of the first tasks a network administrator thinks about when there's a heap of users all needing access to the Web.

Now that Firefox is knocking on the door of enterprise environments, it's natural to ask: Where are the equivalent Firefox security settings? Surely, there must be something that needs to be clicked, ticked, checked or changed? Where is the Firefox security button?

The short answer is: There isn't one. Firefox's security model is different from Internet Explorer's. The basic premise of Firefox, and of all Mozilla tools, is that Web security is not something that you can define to suit yourself. That's different from Internet Explorer, where you can create a custom zone and permit or refuse whatever options seem like a good idea on Tuesday.

Firefox treats security as a promise, not as a creative arrangement. Security is a complex matter, and the Mozilla developers have opted to plug every imaginable security hole as emphatically as possible. In practical terms, there's very little that the user can unknowingly press in the Firefox user interface that will open up a hole in the security system.

Of course, securit



y is never quite that simple, and I'm sure you're hankering for a longer explanation of Firefox's security model.

So, let's start in the Tools/Options dialog box of Firefox. There, the user can peck at the edges of security a little bit. He can enable a few window pop-up features that might allow denial-of-service attacks or confusing messages. He can even save Web site passwords locally, where idle wayfarers might find them. (He can do those things in Internet Explorer, too). More controversially, he can choose to trust extensions delivered from Web sites other than the default site of http://update.mozilla.org.

None of these modifications represent a whole new security regime. There's only one security regime in a standard Firefox install, and it aims to provide complete safety.

The standard Firefox install can also be modified in a number of minor ways, which can also have an impact on security. Clever people such as John Haller have unpacked the standard Firefox install (with tools UPX and 7-Zip), modified some configuration items and re-packed that same install into a new distribution. This is the kind of strategy that IT managers looking to deploy Firefox should examine closely.

With its basic security promise always in place, only very small customizations are ever required to the standard Firefox install. These small customizations can't negotiate away that basic promise, so such re-bundled versions of Firefox can be used as confidently as the standard install.

Whether user-tweaked, rebundled or standard, it's the central idea of a single security promise that keeps Firefox deployment simple. Don't bother looking for a security button.


MORE INFORMATION:

This tip originally appeared on sister site SearchEnterpriseLinux.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Web Security Advisor,   Application and Platform Security,   Web Security Tools and Best Practices,   Web Browser Security,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Web Security Advisor
DNS rebinding defenses still necessary, thanks to Web 2.0
New defenses for automated SQL injection attacks
PCI compliance and Web applications: Code review or firewalls?
Worst practices: Bad security incidents to avoid
Web scanning and reporting best practices
Social networking Web site threats manageable with good enterprise policy
Enterprise security in 2008: Building trust into the application development process
PCI DSS Section 6: A plan for tackling application security
Making the case for Web application vulnerability scanners
Preparing for uniform resource identifier (URI) exploits

Web Browser Security
Security researchers develop browser-based darknet
Microsoft cracks down on click fraud ring
Mozilla patches 11 Firefox security flaws, JavaScript errors
Microsoft patches WebDAV security vulnerability in bevy of updates
IT pros can detect, prevent website vulnerabilities, thwart attacks
Stolen FTP credentials likely in massive website attacks
Trust eroding as social engineering attacks climb in 2009, says Kaspersky expert
US-CERT warns of Gumblar, Martuz drive-by exploits
Google study backs browser silent auto update feature
Firefox update addresses several security flaws
Web Browser Security Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
browser hijacker  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cache poisoning  (SearchSecurity.com)
honey monkey  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
NCSA  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts