Free Republic
Browse · Search
General/Chat
Topics · Post Article

Seems to be working fine in my standard user account OSX install that I use to regularly surf the Internet.

I like how these people headline OSX as being flawed, but then add, parenthetically, that Windows and Linux are also affected by the vulnerability.

How about it? Are any of you "grayed out" from updating FireFox? I'm not.

I call it a FUD article on all three platforms!

1 posted on 08/17/2009 2:49:24 AM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies ]


To: ~Kim4VRWC's~; 1234; 50mm; 6SJ7; Abundy; Action-America; acoulterfan; Aliska; altair; ...
I think this article is FUD... are any of you seeing your FireFox "Check for updates..." grayed out if you are not an Administrator User? Mine's not. PING!

How about you Windows and Linux users? This guy says it affects ALL...


Mac OSX Ping!

If you want on or off the Mac Ping List, Freepmail me.

2 posted on 08/17/2009 2:52:30 AM PDT by Swordmaker (Posted using my iPhone!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: All
Here is the primary source article for the claim above:

I have found a fundamental security problem with Firefox updates on OS X.

Simply put, if you run as a non-admin user on OS X (which is the sensible thing to do), Firefox grays out the Check For Updates menu item, and certainly doesn’t do any automatic notification of security updates, so you can go for days, weeks or even months without realising that an important security update has been released.

Investigation shows that Firefox only enables Update Checking when you have write access to the Firefox application. This completely misses the point that any mildly security conscious person will do ther daily work in a non-privileged account. Heaven help those home users who know nothing about security!

The also begs the question "Do the Firefox folks know their arse from their elbow when it comes to security?"

Yes folks, I am quite angry about this, because I was left exposed myself. Fortunately my use of Firefox is fairly minimal. Lucky me - I would really like to know how many folks got pwned because of this one?

I have pointed out this flaw over at Secure IT Foundation, and the answer I received states that it's also a problem for non-admin WIndows users. They responded with this interesting idea:

...Firefox should be managed as part of a home security policy like the Secure IT Foundation’s Home Computer Policy which includes patching on a regular / urgent basis.

This is also an issue for Ubuntu users, so I suspect it applies to other Unix/Linux variants.

The evidence to date says that at least 3 platforms are affected:

  • MS Windows
  • Linux
  • OS X

The only workaround I can think of on OS X is to keep your eye on the IT news, and log in to a suitably privileged account to check out the availability of Firefox security updates.

Update: A Solaris sysadmin has just informed me that Firefox updates are catered for by the Solaris software update system.

Firefox from a privileged account can have problems too

I forgot to mention the scenario below, which is where I first encountered the problem.

  1. I originally installed Firefox under privileged account User 1.
  2. As part of a spring cleaning exercise, I created a new account User 2 with privileged status and demoted User 1 to non-privileged status.
  3. I created another non-privileged account User 3 for my daily work.

The result of this was that Firefox.app was owned by User 1, therefore my privileged account User 2 didn't have write access to it. Firefox in its wisdom decided from this that it disabled Update Checking for User 2 and I went for a while without any Firefox updates.


3 posted on 08/17/2009 2:59:32 AM PDT by Swordmaker (Posted using my iPhone!)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker
On this linux (Fedora Core 11) box I'm running on, the option is grayed out.

I strongly disagree with the implication that this is a security issue, however, as the system is set up (by default) to have "root" check for package updates (including installed third-party packages packages, such as Firefox). It's the main reason to stick with installing via "yum" rather than downloading and compiling on your own -- automated package control.

5 posted on 08/17/2009 4:09:27 AM PDT by kevkrom (Obama: Stuck on "Stupidly")
[ Post Reply | Private Reply | To 1 | View Replies ]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

11 posted on 08/17/2009 6:34:15 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker
Would this affect Camino on OSX? I checked for updates and it said I was current...
13 posted on 08/17/2009 6:55:50 AM PDT by tubebender (In just two days from today tomorrow will be yesterday...)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

On Linux, you generally get updates from your distribution, anyhow. So, this is pretty much a non-issue.


14 posted on 08/17/2009 6:58:00 AM PDT by B Knotts (Calvin Coolidge Republican)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker
I like how these people headline OSX as being flawed, but then add, parenthetically, that Windows and Linux are also affected by the vulnerability.

There are a few people who post here (and will probably chime in on this thread) who will do anything to try to tear down Apple - they don't mind lying, misrepresenting, or just plain ignoring facts to do it. I wouldn't be surprised if one of those posters penned that "article".

And no, it does not appear to affect this machine I am on.

15 posted on 08/17/2009 7:27:19 AM PDT by TheBattman (Pray for our country...)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

Mine is greyed out on my Win7 box, but not my Ubuntu boxes, nor XP. So, maybe it’s an UAC issue, at least on Windows?

That said, Auto Updates work regardless on which user is logged in. Check yours.


20 posted on 08/17/2009 9:52:58 AM PDT by papasmurf (RnVjayB5b3UsIDBiYW1hLCB5b3UgcGllY2Ugb2Ygc2hpdCBjb3dhcmQh)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Swordmaker

Also, I don’t see any mention of versions or if Firefox was installed under Admin rights or user rights.


21 posted on 08/17/2009 9:54:29 AM PDT by papasmurf (RnVjayB5b3UsIDBiYW1hLCB5b3UgcGllY2Ugb2Ygc2hpdCBjb3dhcmQh)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson