Home > Security Tips > Web Security Advisor > Where's the Firefox security button?
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

Where's the Firefox security button?


Nigel McFarlane
04.25.2005
Rating: -3.33- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



What you will learn in this tip: The security options available in Firefox and how they compare to Internet Explorer's.

Anyone who has spent more than a minute or two administering a Microsoft Windows PC knows about Internet Options. It's a dialog box that you can call up from the Tools/Internet Options menu of Internet Explorer (IE). It also appears as an icon in the control panel. Inside that dialog box is the security tab, where zones are to be found. You pick a zone, and from then on the collection of features that make up that zone dictate how secure surfing the Web with IE will be. Nailing down the right zone cocktail is one of the first tasks a network administrator thinks about when there's a heap of users all needing access to the Web.

Now that Firefox is knocking on the door of enterprise environments, it's natural to ask: Where are the equivalent Firefox security settings? Surely, there must be something that needs to be clicked, ticked, checked or changed? Where is the Firefox security button?

The short answer is: There isn't one. Firefox's security model is different from Internet Explorer's. The basic premise of Firefox, and of all Mozilla tools, is that Web security is not something that you can define to suit yourself. That's different from Internet Explorer, where you can create a custom zone and permit or refuse whatever options seem like a good idea on Tuesday.

Firefox treats security as a promise, not as a creative arrangement. Security is a complex matter, and the Mozilla developers have opted to plug every imaginable security hole as emphatically as possible. In practical terms, there's very little that the user can unknowingly press in the Firefox user interface that will open up a hole in the security system.

Of course, security is never quite that simple, and I'm sure you're hankering for a longer explanation of Firefox's security model.

So, let's start in the Tools/Options dialog box of Firefox. There, the user can peck at the edges of security a little bit. He can enable a few window pop-up features that might allow denial-of-service attacks or confusing messages. He can even save Web site passwords locally, where idle wayfarers might find them. (He can do those things in Internet Explorer, too). More controversially, he can choose to trust extensions delivered from Web sites other than the default site of http://update.mozilla.org.

None of these modifications represent a whole new security regime. There's only one security regime in a standard Firefox install, and it aims to provide complete safety.

The standard Firefox install can also be modified in a number of minor ways, which can also have an impact on security. Clever people such as John Haller have unpacked the standard Firefox install (with tools UPX and 7-Zip), modified some configuration items and re-packed that same install into a new distribution. This is the kind of strategy that IT managers looking to deploy Firefox should examine closely.

With its basic security promise always in place, only very small customizations are ever required to the standard Firefox install. These small customizations can't negotiate away that basic promise, so such re-bundled versions of Firefox can be used as confidently as the standard install.

Whether user-tweaked, rebundled or standard, it's the central idea of a single security promise that keeps Firefox deployment simple. Don't bother looking for a security button.


MORE INFORMATION:

This tip originally appeared on sister site SearchEnterpriseLinux.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Web Security Advisor
New defenses for automated SQL injection attacks
PCI compliance and Web applications: Code review or firewalls?
Worst practices: Bad security incidents to avoid
Web scanning and reporting best practices
Social networking Web site threats manageable with good enterprise policy
Enterprise security in 2008: Building trust into the application development process
PCI DSS Section 6: A plan for tackling application security
Making the case for Web application vulnerability scanners
Preparing for uniform resource identifier (URI) exploits
How to avoid dangling pointers: Tiny programming errors leave serious security vulnerabilities

Firefox Security and Mozilla Security
Shrewd attackers bypass old security defenses with Web attacks
Firefox 3 security looks promising, testers say
Mozilla plugs Firefox flaws
Mozilla to rush update for Firefox bugs
Will Web browsers ever be fully equipped to detect and remove malware?
Mozilla fixes multiple Firefox flaws
Preparing for uniform resource identifier (URI) exploits
Mozilla closes QuickTime attack vector in Firefox
Firefox security issues persist despite update
Mozilla to extend security in major Firefox update
Firefox Security and Mozilla Security Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
browser hijacker  (SearchSecurity.com)
NCSA  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts