Untrue. Firefox, unlike IE, is not intimately tied into the OS, and thus is inherently less vulnerable to the most devastating attacks.
The prefs I changed were accessed through about:config. Open a new window. Type ABOUT:CONFIG into the address bar, then enter. Scroll down the list (it's in alphabetical order) and you'll find the entries
dom.disable_window_open_feature.location
dom.disable_window_open_feature.menubar
dom.disable_window_open_feature.status
(I changed these three, but there are other pref values you can change also)
Right click on each of those entries and select "modify" from the context menu. Then change the value "false" to "true" and enter. Then close the browser and restart firefox.
Now click on the spoof test (you can find them here http://www.nd.edu/~jsmith30/xul/test/spoof.html ) and you'll see that the scam is easy to recognize so that you won't fall for it.