| Pages: [1] 2 :: one page |
| Author |
Thread Statistics | Show CCP posts - 0 post(s) |

Jim McGregor
Caldari
|
Posted - 2006.09.17 09:52:00 -
[1]
Just wanted everybody to read this, so I decided to create a new thread about it.
Appearently its possible for the Eve firefox extension to access your private username/password. It seems to me that it would also be possible for that data to be sent to the author, if he wanted it to.
Firefox extension thread
Its up to you if you want to trust it. I just think everybody should know its possible, because I personally didnt think it was... :p
--- Eve Wiki | Eve Tribune | Eve Pirate |

Everbane
Underworld Enterprises
|
Posted - 2006.09.17 10:02:00 -
[2]
Is this a bug in the plug in code or by design? There was an update to Firefox this morning (Sunday).
|

d'hofren
Queens of the Stone Age Chimaera Pact
|
Posted - 2006.09.17 10:03:00 -
[3]
Edited by: d''hofren on 17/09/2006 10:05:27 Hang on Jim, you have the wrong end of the stick.
The author of the eve extension for firefox is explaining how firefox can be spoofed into giving up the passwords it has stored locally.
The thread on his forums is warning folks not to allow firefox to remember passwords for you.
Link
|

Jim McGregor
Caldari
|
Posted - 2006.09.17 10:06:00 -
[4]
Originally by: d'hofren Hang on Jim, you have the wrong end of the stick.
The author of the eve extension for firefox is explaining how firefox can be spoofed into giving up the passwords it has stored locally.
The thread on his forums is warning folks not to allow firefox to remember passwords for you.
Yep, but most players have their name/password saved in firefox in order to access these forums without manually logging in every time. If its possible for the extension to access them, and also transmit them to the outside world, people should know about it.
Im not 100% if its possible for the extension to send this data to the outside world without the user knowing about it, but it seems to me it should be very possible?
--- Eve Wiki | Eve Tribune | Eve Pirate |

Eilie
Minmatar
|
Posted - 2006.09.17 10:15:00 -
[5]
Hmm... I was just reading that too...
It seems that it's only a danger if you're storing your password in the Firefox Password Manager, right? So you safe if you just login normally and have account info in normal cookies? 
|

Benco97
Gallente On Ravens Wings
|
Posted - 2006.09.17 10:16:00 -
[6]
What that is actually saying is that ANY plugin could do this so lets all flail around wildliy and uninstall them all, not just the eve one
Head of the Fedo Appreciation Group (F.A.G) and Registered Fedo breeder |

Shiraz Merlot
Octavian Vanguard RAZOR Alliance
|
Posted - 2006.09.17 10:17:00 -
[7]
BREAKING NEWS: Sources claim that a "computer" can store data that is typed into it!!!!!!1111
Film at 11.
|

Jim McGregor
Caldari
|
Posted - 2006.09.17 10:20:00 -
[8]
Originally by: Eilie Hmm... I was just reading that too...
It seems that it's only a danger if you're storing your password in the Firefox Password Manager, right? So you safe if you just login normally and have account info in normal cookies? 
Well, if the info isnt saved anywhere, then the plugins cant access it. So then you should be safe.
And yep, this goes for all plugins. I actually didnt know it was possible for them to access saved data like this.
Nothing is stopping someone from creating a nice popular plugin and then get access to everything the user has saved in Firefox. Its quite a security risk, because you dont know who the plugin is communicating with. The firewalls usually allow firefox to do what it wants, once you allow it through.
--- Eve Wiki | Eve Tribune | Eve Pirate |

Eilie
Minmatar
|
Posted - 2006.09.17 10:26:00 -
[9]
Originally by: Jim McGregor
Originally by: Eilie Hmm... I was just reading that too...
It seems that it's only a danger if you're storing your password in the Firefox Password Manager, right? So you safe if you just login normally and have account info in normal cookies? 
Well, if the info isnt saved anywhere, then the plugins cant access it. So then you should be safe.
And yep, this goes for all plugins. I actually didnt know it was possible for them to access saved data like this.
Nothing is stopping someone from creating a nice popular plugin and then get access to everything the user has saved in Firefox. Its quite a security risk, because you dont know who the plugin is communicating with. The firewalls usually allow firefox to do what it wants, once you allow it through.
Well the info is saved (in cookies) so I was asking if the plugins can read the cookies too?
|

Jim McGregor
Caldari
|
Posted - 2006.09.17 10:34:00 -
[10]
Originally by: Eilie
Well the info is saved (in cookies) so I was asking if the plugins can read the cookies too?
This warning is just about the info that is stored by using the firefox password manager. I dont know if the extensions can access the firefox cookies as well.
--- Eve Wiki | Eve Tribune | Eve Pirate |

Jim McGregor
Caldari
|
Posted - 2006.09.17 10:46:00 -
[11]
Originally by: Everbane Is this a bug in the plug in code or by design? There was an update to Firefox this morning (Sunday).
I ran the test plugin from the site linked in the original post, and it managed to get my account details. Im using Firefox 1.5.0.7 which I got via auto-update only yesterday.
--- Eve Wiki | Eve Tribune | Eve Pirate |

Caleb Paine
adeptus gattacus Lotka Volterra
|
Posted - 2006.09.17 10:58:00 -
[12]
Funny, if Firefox would have been a Microsoft product the whole world would have started WWIII on Gates and talk about how bad a program it is... with this one people are talking it down.
-------------------------------- I'm looking for a good signature artist click here |

Plutoinum
German Cyberdome Corp Veritas Immortalis
|
Posted - 2006.09.17 11:12:00 -
[13]
Edited by: Plutoinum on 17/09/2006 11:12:39 Interesting. That sux. I believed that the password would be encrypted in a way that only the browser itself can use it, if the page is accessed and not every plug-in that wants to when it likes. Ok, thanks. important saved passwords removed.
|

Patch86
Di-Tron Heavy Industries Knights Of the Southerncross
|
Posted - 2006.09.17 11:27:00 -
[14]
Obviously, tin-foil hats permitting we should all take this with a pinch of salt, but on THIS official website of the plugin, they acknowledge this security thingy, and proclaim that they are safe.
|

Major Stormer
Caldari Demon Womb Xelas Alliance
|
Posted - 2006.09.17 11:38:00 -
[15]
More proof that Firefox isnt the one stop shop to safety Any 3rd party program that can access my account details and isnt covered by a legal binding EULA etc i refuse to use. --------------------------
AHH the Stupid forum DELETED(!) all my mod chat in my sig when i added this image :( |

Sir Juri
Caldari Caldari Provisions
|
Posted - 2006.09.17 11:44:00 -
[16]
Originally by: Major Stormer More proof that Firefox isnt the one stop shop to safety Any 3rd party program that can access my account details and isnt covered by a legal binding EULA etc i refuse to use.
Then just make it so firefox doesnt store it! this thread is pointless, think I read this discussion back in 1994 or something.
damn need to make a new sig... |

Tachy
|
Posted - 2006.09.17 11:45:00 -
[17]
One of the base rules in computer&security: Do not let software remember any login data.
Hard to remember, eh? It works parallel to the other rule: Do not trust anyone on the net. --*=*=*--
No Thread with this ID This thread does not exist. Go back One page | Go back to forums |

Dark Shikari
Caldari Imperium Technologies Firmus Ixion
|
Posted - 2006.09.17 12:26:00 -
[18]
Originally by: Major Stormer More proof that Firefox isnt the one stop shop to safety Any 3rd party program that can access my account details and isnt covered by a legal binding EULA etc i refuse to use.
Then don't use extensions if you're paranoid, but hell you can even download the source code and analyze them yourself.
The entire Windows operating system is unaudited and for all you know could be sending your EVE passwords to everyone out there.
--[23] Member--
Originally by: DB Preacher The only time BoB's backs are to the wall is when Backdoor Bandit is in local.
|

Grez
Minmatar The Raven Warriors
|
Posted - 2006.09.17 12:37:00 -
[19]
Axkiller has come onto my Ventrilo server after I requested Ventrilo supported, and I've talked with him, not to mention he's an old EVE player. I've used DT and the FF plugin for a while now, my account hasn't been hacked, and I know he wouldn't do such a thing. There's also the source code available for download on the website if you looked. -
Corp: www.ravenwarriors.com Cache Clearer
Still waiting for a Wrangler-edit! |

Michiyo Daishi
Royal Knights of Khanid
|
Posted - 2006.09.17 12:48:00 -
[20]
its interesting to note that potentially "safe" plugins may not exist anymore for Firefox, lets all get into our nuke shelters everyone, do not panic... >
want a sig like mine? :D
|

Fliewatuet
Angelus dos Business
|
Posted - 2006.09.17 12:49:00 -
[21]
Uhm... and where is the new stuff? This is not a simply javascript executed by some random website out there. This is a real extension of Firefox. That means, it has to have more rights - it should be able to do everything that firefox itself can so it really extends the browser. There are lots of extensions out there and a lot of them are great. Half of them wouldn't be possible if they are only allowed to ran in some sort of a sandbox without any bigger rights.
Why do you assume those login informations in firefox have to be excluded from extensions? Whatelse should be excluded? Filesystem access? Access to the internet so the extension cannot transfer data? Forget it, thats why its called an extension. *sigh*
Just because someone is amazed what he can do within an extension doesn't mean it shouldn't be exactly like that. Ppl have to install an extension. They have to say yes explicitly. Its like installing a real application on your PC.
Regards, Fliewatuet -- NPC infos? Calculating DPS for a mission? Have a look at http://eve.neodoomer.de/npc/ and have fun. |

Virtua Ursula
|
Posted - 2006.09.17 12:49:00 -
[22]
All of this is made as a prevention.
We all know that every program is not safe but the fact here that made us talk about it, is to make people aware about that. We can prevent the worse as It looks like it never happend before in the history of Eve-Online hacking. Here we only talk about eve-online, the rest it's up to you.
|

robacz
Gallente
|
Posted - 2006.09.17 13:01:00 -
[23]
Originally by: Fliewatuet Uhm... and where is the new stuff? This is not a simply javascript executed by some random website out there. This is a real extension of Firefox. That means, it has to have more rights - it should be able to do everything that firefox itself can so it really extends the browser. There are lots of extensions out there and a lot of them are great. Half of them wouldn't be possible if they are only allowed to ran in some sort of a sandbox without any bigger rights.
Why do you assume those login informations in firefox have to be excluded from extensions? Whatelse should be excluded? Filesystem access? Access to the internet so the extension cannot transfer data? Forget it, thats why its called an extension. *sigh*
Just because someone is amazed what he can do within an extension doesn't mean it shouldn't be exactly like that. Ppl have to install an extension. They have to say yes explicitly. Its like installing a real application on your PC.
Regards, Fliewatuet
Sorry but why would extensions need access to my passwords? In my opinion it is incredibly stupid to let extensions to retrieve passwords so easily. At least it should ask you about that, or demand master password when some extension want to access passwords list. 
___________ Buying/Selling: Implants, Cargo Expanders and more |

Virtua Ursula
|
Posted - 2006.09.17 13:06:00 -
[24]
Originally by: Fliewatuet Uhm... and where is the new stuff? This is not a simply javascript executed by some random website out there. This is a real extension of Firefox. That means, it has to have more rights - it should be able to do everything that firefox itself can so it really extends the browser. There are lots of extensions out there and a lot of them are great. Half of them wouldn't be possible if they are only allowed to ran in some sort of a sandbox without any bigger rights.
Why do you assume those login informations in firefox have to be excluded from extensions? Whatelse should be excluded? Filesystem access? Access to the internet so the extension cannot transfer data? Forget it, thats why its called an extension. *sigh*
Just because someone is amazed what he can do within an extension doesn't mean it shouldn't be exactly like that. Ppl have to install an extension. They have to say yes explicitly. Its like installing a real application on your PC.
Regards, Fliewatuet
I'm not sure you got the problem right. An program's extension can do whatever, ok, Don't you think it is too easy and too accessible to noobs to get such data. Yes it is like a program but I think that firefox should ask if we do want or not to let extensions access logins and passwords, and let us know first that it was possible. With a windows program that wouldn't be that easy to get those passwords, I don't tell It is not possible though. For me It is really a security issue compare with other programs can do and how easy they can do.
|

prsr
Gallente
|
Posted - 2006.09.17 13:42:00 -
[25]
Edited by: prsr on 17/09/2006 13:42:59
Originally by: Major Stormer More proof that Firefox isnt the one stop shop to safety Any 3rd party program that can access my account details and isnt covered by a legal binding EULA etc i refuse to use.
Thats funny, I always safely ignore EULA's since they aren't legally binding anyway.
Also, interesting note maybe, any software you execute on your PC can do anything you do. It's a trust thing between you and the maker that the program won't do anything you don't want it to do every single time you run it. At least, thats the case when you use closed source software at least.
-- .sig apathy ftw |

Jim McGregor
Caldari
|
Posted - 2006.09.17 13:57:00 -
[26]
Originally by: prsr Edited by: prsr on 17/09/2006 13:42:59
Originally by: Major Stormer More proof that Firefox isnt the one stop shop to safety Any 3rd party program that can access my account details and isnt covered by a legal binding EULA etc i refuse to use.
Thats funny, I always safely ignore EULA's since they aren't legally binding anyway.
Also, interesting note maybe, any software you execute on your PC can do anything you do. It's a trust thing between you and the maker that the program won't do anything you don't want it to do every single time you run it. At least, thats the case when you use closed source software at least.
Yep, but knowledge about the technical possibilities is always good. I could create a firefox plugin to provide quick access to all kinds of killboards for example. Would probably become very popular. With a few lines of code I could ask it to send your saved username/passwords in firefox to a server, and you probably wouldnt even know it did.
Then I would become very rich in Eve. :)
--- Eve Wiki | Eve Tribune | Eve Pirate |

Patch86
Di-Tron Heavy Industries Knights Of the Southerncross
|
Posted - 2006.09.17 14:35:00 -
[27]
Incidentally, shouldn't this be on the Out Of Pod Experience forum? Last time I checked, debates about Firefox security protocols wern't exactly game related 
|

Fliewatuet
Angelus dos Business
|
Posted - 2006.09.17 14:37:00 -
[28]
Originally by: robacz Sorry but why would extensions need access to my passwords? In my opinion it is incredibly stupid to let extensions to retrieve passwords so easily. At least it should ask you about that, or demand master password when some extension want to access passwords list. 
Based on the mechanisms an extension uses its more like an integral part of the browser than a simple macro. If you start restricting it it will be just a simple macro and nothing more.
Remember: An extension should extend major parts of the browser. Perhaps you should start developing an extension yourself, one that implements your need for safety and the master password you asked for? ;) Hey, thats why there are extensions at all: To fill the gaps ppl are missing. There are quite a few security related extensions, for generating passwords, encrypting them, protecting them from keyloggers (dangerous, especially if you do not safe them since then you have to enter them every time and they can be logged).
Perhaps you want to export your safed passwords. After all, one of the biggest problems with safing them in the browser is that you don't have to remember them that often. Perhaps you even want to share your filled forms and passwords entered on your desktop with your laptop.
Originally by: Virtua Ursula I'm not sure you got the problem right. An program's extension can do whatever, ok, Don't you think it is too easy and too accessible to noobs to get such data. Yes it is like a program but I think that firefox should ask if we do want or not to let extensions access logins and passwords, and let us know first that it was possible.
If you want a computer to protect the user from their own stupidity then just cut the wire to the internet. I for my part think its better to open up possibilities for those that know what to do and what not - or for those who are willing to learn it - than to cripple software with too many "are you really sure you really not want to allow xyz to do abc"s. I know exactly well that with downloading and activating an extension of firefox, i add those function to the browser itself - for better or worse.
Just my 2 cents... perhaps it would be easier to just not use the same password for the client login as well as the browser login. Oh, and on another side note: The login on the webpage and the use of the session after that is totally unencripted and open to simple listeners on the network.
If you are online over wlan, don't ever login to eve-o webpage! Everyone can listen to your login and password with a simple traffic analyzer like Ethereal! I wonder why ppl are getting nervous because a browser extension (which has to willingly be installed beforehand) can access data and noone says anything about danger the user has to risk every time they use the webpage, regardless of browser.
Regards, Fliewatuet -- NPC infos? Calculating DPS for a mission? Have a look at http://eve.neodoomer.de/npc/ and have fun. |

Fliewatuet
Angelus dos Business
|
Posted - 2006.09.17 14:38:00 -
[29]
Originally by: Patch86 Incidentally, shouldn't this be on the Out Of Pod Experience forum? Last time I checked, debates about Firefox security protocols wern't exactly game related 
I guess we should move back to eve security matters then. ;-) -- NPC infos? Calculating DPS for a mission? Have a look at http://eve.neodoomer.de/npc/ and have fun. |

Jim McGregor
Caldari
|
Posted - 2006.09.17 14:49:00 -
[30]
Originally by: Patch86 Incidentally, shouldn't this be on the Out Of Pod Experience forum? Last time I checked, debates about Firefox security protocols wern't exactly game related 
I guess. The post was originally about the Eve Downtime extention, but evolved into being about all extentions. I just wanted to share the information so people would know. Besides, isnt it nice this isnt a whine post? :)
--- Eve Wiki | Eve Tribune | Eve Pirate |
| |
|
| Pages: [1] 2 :: one page |
| First page | Previous page | Next page | Last page |