SecurityGarden

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Friday, June 22, 2012

Firefox 'New Tab' Feature Exposes Secure Information

Posted on 4:28 PM by Unknown

A report at The Register indicates that the "New Tab" thumbnail feature in Firefox 13 is "taking snapshots of the user's HTTPS session content".

The reader of The Register indicated when he opened a new tab, he was presented with his earlier online banking and webmail sessions, complete with account number information, balance, etc.
 
On the computer where I generally have 16-20 tabs open, the new tab did indeed include thumbnails of cached pages of sites I had logged on to. On a second computer that generally has only four tabs open, my email page was prominently displayed.

Although the display of the cached pages is highly undesirable, since my Firefox profile is associated with my computer logon, I can see that the thumbnail is displaying the past page visited and, in some cases, the page currently displayed on another tab! 

Recommendations

If you use a shared or public computer use the Private Browsing feature:   
At the top of the Firefox window, click the Firefox button (Tools menu in Windows XP) and select "Start Private Browsing" (Keyboard shortcut = Ctrl+Shift+P).
 
Although it will not help for an existing session, use the setting to clear history when Firefox closes.    
At the top of the Firefox window, click the Firefox button (Tools menu in Windows XP).  Select Options > Privacy > Clear history when Firefox closes.  When you relaunch Firefox and click the "New Tab" button, empty thumbnails with just the site name are presented.

According to Mozilla, the new tab appears when you click the “+” at the end of your tab strip. Strangely, although I have the latest version installed, some customizations or an installed add-on apparently result in no "+" at the end of the tab strip. For standard installations, apparently there is a small button, in the upper right corner that hides the site tiles, leaving only the small button visible.  Perhaps a Security Garden reader can confirm that and provide a link to a screen capture.


Mozilla Statement

Following is the statement provided by Mozilla when presented with the issue by The Register:


"We are aware of the concern and have a fix that will be released in a future version of Firefox. Mozilla remains resolute in its commitment to privacy and user control. The new tab thumbnail feature within Firefox does not  transmit nor store personal information outside the user's direct control.

The new tab thumbnails are based on  users' browsing history. All information is contained within the browser and can be deleted at any time. Users can also switch back to using blank new tab screens by clicking the square icon in the top right corner of the browser. That will change the default preference to show a blank page, rather than the most visited websites when a new tab is opened.
Users who share their computer or use Firefox on a public computer should follow best practices for protecting their privacy by utilizing the built-in privacy tools in in Firefox, such as Private Browsing Mode.

Reference

  • The Register:  Firefox 'new tab' feature exposes users' secured info: Fix promised
 


Remember - "A day without laughter is a day wasted."
May the wind sing to you and the sun rise in your heart...


Email ThisBlogThis!Share to XShare to Facebook
Posted in Firefox, Mozilla, Security | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Security Bulletin Advance Notice for August, 2013
    On Tuesday, August 13, 2013, Microsoft is planning to release eight (8) bulletins.  Three of the bulletins are identified as Critical with f...
  • Critical Out-of-Band Update Released for MS10-046
    Microsoft released Security Bulletin MS10-046 out-of-band to address a vulnerability in Windows. The security update is identified as crit...
  • Hotmail Security to Protect and Recover Your Account
    Time and time again I see reports from Hotmail users who have lost control of their e-mail account.  As explained by Walter Harp, Director o...
  • Long Awaited Outlook.com Calendar Refresh Rollout
    The long-awaited Outlook.com calendar refresh has been released and is in the process of being rolled out. Because the servers are grouped i...
  • Microsoft Security Advisory 2269637 Released
    Microsoft released Security Advisory 2269637 which relates to a remote attack vector to a class of vulnerabilities affecting applications t...
  • Oracle Java Update
    Oracle released the Java SE 7u40 today.  In addition to bug fixes and enhancements, the update includes the following: advanced monitoring ...
  • Adobe Reader Security Updates
    Adobe has released security updates for Adobe Reader and Acrobat XI (11.0.03) and earlier versions for Windows and Macintosh. Adobe identif...
  • Advance Notice: Security Updates for Java SE
    The Sun Security Blog published the following update announcement: "On November 3, 2009, Sun will release the following security update...
  • Adobe Flash Player and Adobe Air Security Updates
    Adobe released updates to both Adobe Flash Player and Adobe AIR to correct a critical vulnerability in both products. From the Adobe Securi...
  • Waledac Botnet Takedown
    The Waledac botnet had the capability of sending 1.5 billion spam e-mails per day. During a three-week period in December, 2009, approximat...

Categories

  • Adobe
  • Advisory
  • Amero
  • AntiVirus
  • Apple
  • Ask
  • AVG
  • Bing
  • Browser
  • Child Safety
  • email
  • ESET
  • Ethics
  • Facebook
  • Firefox
  • Firewall
  • FixIt
  • Fraud
  • General
  • Google
  • Hotmail
  • IE10
  • IE6
  • IE7
  • IE8
  • IE9
  • Java
  • Lavasoft
  • malware
  • Microsoft
  • Microsoft Apps
  • Mozilla
  • MVP
  • NCSAM
  • Office
  • Office 2007
  • Office 2010
  • Opera
  • Outlook.com
  • Phishing
  • Privacy
  • safety
  • Search
  • Security
  • Service Pack
  • SkyDrive
  • Skype
  • Software
  • SP1
  • sp2
  • SP3
  • Spotlight
  • Sumatra
  • tutorial
  • UAC
  • Updates
  • Vulnerabilities
  • Windows
  • Windows 7
  • Windows 8
  • Windows Live
  • Windows Live OneCare
  • Windows Vista
  • Windows XP
  • WinPatrol

Blog Archive

  • ►  2013 (93)
    • ►  October (2)
    • ►  September (8)
    • ►  August (9)
    • ►  July (5)
    • ►  June (8)
    • ►  May (7)
    • ►  April (15)
    • ►  March (9)
    • ►  February (16)
    • ►  January (14)
  • ▼  2012 (98)
    • ►  December (7)
    • ►  November (6)
    • ►  October (11)
    • ►  September (5)
    • ►  August (10)
    • ►  July (8)
    • ▼  June (12)
      • Microsoft .NET Framework Repair Tool
      • Firefox 'New Tab' Feature Exposes Secure Information
      • Adobe Flash Player "Plug-in Version" Updated
      • Mozilla Firefox 13.0.1 Addresses Adobe Flash Crashes
      • Microsoft Security Advisory 2719615 + Fix it Solution
      • Oracle Java SE Critical Security Update
      • Microsoft June 2012 Security Bulletin Release
      • Flash Player Update Causes Firefox Crashes
      • Adobe Flash Player Security Update
      • Security Bulletin Advance Notice for June
      • Mozzila Firefox 13 Released With Critical Security...
      • Security Advisory & Update Related to Flame
    • ►  May (7)
    • ►  April (12)
    • ►  March (6)
    • ►  February (6)
    • ►  January (8)
  • ►  2011 (130)
    • ►  December (8)
    • ►  November (10)
    • ►  October (7)
    • ►  September (12)
    • ►  August (9)
    • ►  July (6)
    • ►  June (13)
    • ►  May (14)
    • ►  April (13)
    • ►  March (15)
    • ►  February (10)
    • ►  January (13)
  • ►  2010 (146)
    • ►  December (10)
    • ►  November (15)
    • ►  October (19)
    • ►  September (15)
    • ►  August (14)
    • ►  July (8)
    • ►  June (19)
    • ►  May (5)
    • ►  April (11)
    • ►  March (6)
    • ►  February (14)
    • ►  January (10)
  • ►  2009 (33)
    • ►  December (11)
    • ►  November (11)
    • ►  October (11)
Powered by Blogger.

About Me

Unknown
View my complete profile