On mySimon: Spiewak Durand Jacket
BNET Business Network:
BNET
TechRepublic
ZDNet

May 31st, 2009

Microsoft sneaks in Firefox extension via Update

Posted by Joe Brockmeier @ 6:42 pm

Categories: Business and Open Source, security

Tags: Firefox Extension, Microsoft Corp., Security Update, Extension, Krebs, Security Administration, Patches, Microsoft Windows, Linux, Web Browsers

The good news is that Microsoft is writing extensions for Firefox. The bad news is, the Redmond giant is slipping the extension onto systems without notifying users and making it difficult to get rid of the extension. Even worse? It’s an extension that allows Web sites to install software onto users’ PCs behind the scenes — meaning that Firefox users on Windows may not be as safe as they think.

Brian Krebs, who originally recommended the .Net Framework that sneaks the extension into Firefox writes:

Anyway, I’m sure it’s not the end of the world, but it’s probably infuriating to many readers nonetheless. Firstly — to my readers — I apologize for overlooking this…”feature” of the .NET Framework security update. Secondly — to Microsoft — this is a great example of how not to convince people to trust your security updates.

Krebs is right: It’s not the end of the world. But it seems like a violation of user trust to monkey with a third-party program — and top it off by making it difficult to remove the extension without editing the Windows Registry. By using the update mechanism to sneak software onto the system, Microsoft is telling security conscious users to be suspicious of updates and to deploy them only after they’ve been widely vetted, or choose a more trustworthy vendor.

As a Linux user, it makes little difference to me what Microsoft does via Windows Update –users on openSUSE and other Linux distros can see exactly what updates will do to their system: Down to the source code, if they choose to take the time.

But, failing a source code audit, Microsoft could at least provide a full disclosure of the packages and features modified when a user runs Windows Update. Without that, users should be wary indeed of trusting Microsoft’s updates — and missing a trust relationship for security updates, users should be wary of running Windows in the first place.

Joe 'Zonker' BrockmeierJoe 'Zonker' Brockmeier is a longtime FOSS advocate, and currently works for Novell as the community manager for openSUSE. Prior to joining Novell, Brockmeier worked as a technology journalist covering the open source beat for a number of publications, including Linux Magazine, Linux Weekly News, Linux.com, UnixReview.com, IBM developerWorks, and many others. See his full profile and disclosure of his industry affiliations. Follow Zonker on Twitter.

Email Joe 'Zonker' Brockmeier

Subscribe to Community, Incorporated via Email alerts or RSS.

  • Talkback
  • Most Recent of 49 Talkback(s)
how did you delete it?
My option to uninstall is disabled. (Read the rest)
Posted by: lostarchitect Posted on: 07/01/09 You are currently: a Guest | | Terms of Use
Maybe NoAxe, LD, or Bott would care to explain this?  nizuse | 05/31/09
NoAx and LD Are Having Breakfast In Bed  itanalyst2@... | 06/01/09
About ClickOnce  bradsl@... | 06/01/09
Spoken like an MS damage-control guy  maggietoo9 | 06/01/09
You won't get it  Greenknight_z | 06/02/09
I had to install it, but...  UAC nanny screen | 06/02/09
A very typical MS bully tactic!  RS9 | 06/02/09
RE: Microsoft sneaks in Firefox extension via Update  PeterPac | 05/31/09
uninstalling extensions  Mnighthawk | 06/01/09
RE: Microsoft sneaks in Firefox extension via Update  nospam@... | 05/31/09
It's the .NET Framework Assistant 1.1...  Wolfie2K3 | 05/31/09
and keyclick sniffers  oldbaritone | 06/01/09
thats enough information for a malicious site to dynamically  brokndodge@... | 06/01/09
lol...  twisterjosh@... | 06/01/09
Why does ZDNet permit these blatantly false blogs to appear on their sites?  NonZealot | 05/31/09
It uninstalled in my FF no problem  tech_walker | 06/01/09
NonZealot, you should stop flaming unless...  jtiner | 06/04/09
I don't have any options.  lostarchitect | 07/01/09
Load up WireShark and watch the action  no_zd_user_name | 06/01/09
Thanks for the tip...  20kwfence | 06/01/09
Maybe you should read the manual...  Spiritusindomit@... | 06/01/09
RE: Microsoft sneaks in Firefox extension via Update  Gis Bun | 06/01/09
I have another idea...  goff256 | 06/01/09
RE: I have another idea...  Gis Bun | 06/01/09
RE: Microsoft sneaks in Firefox extension via Update  hantman@... | 06/01/09
miKro$loth sneaks in Malware.  zclayton2 | 06/01/09
RE: Microsoft sneaks in Firefox extension via Update  Barbier@... | 06/01/09
LAWSUIT: from Firefox only, or class action?  Barbier@... | 06/01/09
I require some proof for this  Spiritusindomit@... | 06/01/09
well, i'll comfirm...  lostarchitect | 07/01/09
blatantly false blogs, heh?  Barbier@... | 06/01/09
I think the "sneaking" part is Mozilla's fault..  D. W. Bierbaum | 06/02/09
Re: heavy flow day? obnoxious chauvinist  Barbier@... | 06/01/09
Microsoft isn't the only one who does this...  D. W. Bierbaum | 06/01/09
RE: Microsoft sneaks in Firefox extension via Update  epobirs | 06/01/09
Name please?  WindowWasher | 06/01/09
Tools/Add-ons/  jonrichco | 06/04/09
RE: Microsoft sneaks in Firefox extension via Update  Gis Bun | 06/01/09
RE: M$ sneaks in Firefox extension via (malware) update  bfilipiak@... | 06/01/09
RE: Microsoft sneaks in Firefox extension via Update  KBall1 | 06/01/09
how did you delete it?  lostarchitect | 07/01/09
RE: Microsoft sneaks in Firefox extension via Update  rlk123go | 06/02/09
Thank you! [NT]  RS9 | 06/02/09
Your reply is...  RS9 | 06/02/09
RE: Microsoft sneaks in Firefox extension via Update  Gis Bun | 06/03/09
Firefox zealots  pipercub1941 | 06/03/09
RE: Microsoft sneaks in Firefox extension via Update  pravin3832 | 06/03/09
RE: Microsoft sneaks in Firefox extension via Update  Gis Bun | 06/04/09
RE: Microsoft sneaks in Firefox extension via Update  Gis Bun | 06/04/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    Favorite Links

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
    • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
    • Smart People The best and worst moves in the management and strategy trenches. Learn More