Firefox3.6/Plugin Update Awareness Security Review: Difference between revisions

Jump to navigation Jump to search
Line 91: Line 91:


is the blocklist transferred to users in a way that's authenticated, or it is vulnerable to MITM?
is the blocklist transferred to users in a way that's authenticated, or it is vulnerable to MITM?
* The default plugins.update.url is on https://www.mozilla.com/, but who knows what Ubuntu's is


since the warning is an infobar, can users tell the difference between our feature (sending them to adobe.com) and a malicious advertisement (sending them elsewhere)?
since the warning is an infobar, can users tell the difference between our feature (sending them to adobe.com) and a malicious advertisement (sending them elsewhere)?
Confirmed users
729

edits

Navigation menu