Risk
5/4/2009
06:00 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

NoScript Developer Apologizes For Meddling With AdBlock

His methods caused a furor in the Mozilla community over the weekend because he did not provide clear notification about what his software was doing.

Perhaps more significant than the conflict between two extension makers is the fact that AMO, the Mozilla add-on group, allows authors of popular extensions like NoScript to be "trusted," so their code can be posted without review.

Mozilla did not immediately respond to a request for comment.

Such absence of oversight becomes even more troubling in light of some of the comments on Palant's blog post that suggest attempts to corrupt extension developers may be widespread. One post, ostensibly from another Firefox extension developer, asks whether Palant has been approached by a company called KallOut, seeking a partnership to promote its software aggressively.

"I think this sort of seedy business is just going to increase as the browser becomes the platform," the anonymous developer suggests. "The bigger the ecosystem, the more room for bad actors."

The implication is that conflicts surrounding adware, spyware, Web page framing, and the user's ability to control his or her computer have returned with a vengeance. The battlefield this time is the browser ecosystem rather than the operating system.

KallOut's CEO, Lee Lorenzen, rejects the characterization that his company is promoting unethical software. "We believe our business tactics are completely fair and shouldn't be scary to anyone," he wrote in a post on the Mozilla add-on site. "While not every one of Firefox's 220 million users may agree with them or like them, those who don't can decide not to use our product. However, we don't believe that we have crossed any lines in a way that would be offensive to members of the Firefox community of developers and users."

Whether or not KallOut has been unfairly singled out, with a recession in full swing and ad revenue under pressure, further fights along these lines appear to be inevitable.


InformationWeek Analytics has published an independent analysis on what executives really think about security. Download the report here (registration required).

Previous
2 of 2
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0196
Published: 2015-06-29
CRLF injection vulnerability in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 before 7.0.0.8 Cumulative iFix 2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

CVE-2015-0545
Published: 2015-06-29
EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors.

CVE-2015-1900
Published: 2015-06-29
IBM InfoSphere DataStage 8.1, 8.5, 8.7, 9.1, and 11.3 through 11.3.1.2 on UNIX allows local users to write to executable files, and consequently obtain root privileges, via unspecified vectors.

CVE-2014-4768
Published: 2015-06-28
IBM Unified Extensible Firmware Interface (UEFI) on Flex System x880 X6, System x3850 X6, and System x3950 X6 devices allows remote authenticated users to cause an unspecified temporary denial of service by using privileged access to enable a legacy boot mode.

CVE-2014-6198
Published: 2015-06-28
Cross-site request forgery (CSRF) vulnerability in IBM Security Network Protection 5.3 before 5.3.1 allows remote attackers to hijack the authentication of arbitrary users.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report