Breaking News

Micron Announces Exit from Crucial Consumer Business!! Sony Launches Alpha 7 V and FE 28-70mm f/3.5-5.6 OSS II Samsung announces Galaxy Z TriFold DeepCool Introduces CL6600 Case – A New Breakthrough in Performance Case Design KIOXIA AiSAQ and memory-centric AI innovations enable AI-based automatic image recognition for logistics processes

logo

  • Share Us
    • Facebook
    • Twitter
  • Home
  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map

Search form

Mozilla and Opera Disable Web Sockets In Their Browsers Due To Vulnerabilities in the Protocol

Mozilla and Opera Disable Web Sockets In Their Browsers Due To Vulnerabilities in the Protocol

Enterprise & IT Dec 10,2010 0

Mozilla and Opera put their Web Socket plans on hold this week after a recently demonstrated attack against the protocol. The Web Sockets technology, a W3C Specification, opens up a live communication link between a browser and a server. The currently available "working draft" specifications defines an API that enables Web pages to use the Web Sockets protocol for two-way communication with a remote host. The rotocol is an important part of plans to make the Web a home for more dynamic, interactive sites.

Google's Chrome 4+ has been the first to implement it in a "final RTW build" at the end of 2009, followed by Apple's Safari 5.0.2. Instead Firefox was planning to support them in the version 4beta and Opera in version 11, but they never went in production. Microsoft's IE doesn?t implement this spec in current build.

Mozilla and Opera put their Web Socket plans on hold, at least for now, after Adam Barth demonstrated some serious attacks against the protocol that could be used by an attacker to poison caches that sit in between the browser and the Internet.

"We?ve decided to disable support for WebSockets in Firefox 4, starting with beta 8 due to a protocol-level security issue. Beta 7 included support for the -76 version of the protocol, the same version that?s included with Chrome and Safari, " Christopher Blizzard, an open Source Evangelist working for the Mozilla Corporation, wrote on his blog.

"Once we have a version of the protocol that we feel is secure and stable, we will include it in a release of Firefox, even a minor update release," he addded.

"To be clear, we?re still excited about what WebSockets offers and we?re working hard with the IETF on a new WebSocket protocol."

Anne van Kesteren of Opera Software also announced Opera's response to the report.

"Adam Barth reported on vulnerabilities with the current WebSocket protocol handshake. Reportedly you can poison the cache of transparant/intercepting proxies affecting all users of that proxy. So rather than e.g. http://www.google-analytics.com/ga.js you would get a JavaScript file from an attacker. This attack affects Flash and Java as well, but we have higher standards for browsers. This means that until the new WebSocket protocol handshake is sorted out by the IETF it will be behind a preference in Opera," she wrote at her blog.

Apple also appears to be concerned too, while Microsoft was more cautious about Web Sockets support even before the security problem arose.

"Rushing the implementation of a specific feature and call it "done deal" is dangerous and in some circumstance can bring to unpleasant results," Sardo said.

However Google, who will natively support the Web Spckets protocol in the Chrome browser, sees things differently. Web Sockets editor Ian Fette said in a statement to CNET:

"We are not hiding it behind a flag at the current point in time. We released the details of the research to help guide the working group towards what we believe will be a more secure version of the Web Sockets protocol, and are hoping that the group will reach consensus in the next few weeks. We already have detailed a proposal for a more secure version, and are addressing various concerns that have been raised by others in the standards community.

"It's important to note that the research paper Adam Barth published does not demonstrate a working attack against the actual Web Socket implementation, but rather against one part [of] the protocol taken in isolation. There are other parts of the protocol that would make an actual attack more complicated in practice. We believe there will be consensus on a new version of the protocol, and implementation in Chrome of that new version, before someone is able to actually demonstrate an attack against the full Web Socket protocol as currently shipping in Chrome."

Tags: MozillainternetOpera
Previous Post
Kaleidescape Introduces First Blu-ray Movie Server
Next Post
WikiLeaks Employee To Launch Rival Website OpenLeaks

Related Posts

  • How to Navigate the Internet Safely 4 Essential Tips

  • Facebook Works With Telecoms on 2Africa Subsea Cable for Future Internet Connectivity

  • Opera Adds Built-in Instagram to Desktop Browser

  • New Opera for Android Offers More Data Savings, New Blockchain-browsing Features

  • Scroll Partners With Firefox to Build a Better Internet

  • Opera Lets US Users Buy Crypto With Apple Pay or Debit Card

  • Facebook Needs to Get Remaining 3.5 Billion People Online

  • Opera R2020 Browser is Here With New Features and Support for DoH

Latest News

Micron Announces Exit from Crucial Consumer Business!!
Enterprise & IT

Micron Announces Exit from Crucial Consumer Business!!

Sony Launches Alpha 7 V and FE 28-70mm f/3.5-5.6 OSS II
Cameras

Sony Launches Alpha 7 V and FE 28-70mm f/3.5-5.6 OSS II

Samsung announces Galaxy Z TriFold
Consumer Electronics

Samsung announces Galaxy Z TriFold

DeepCool Introduces CL6600 Case – A New Breakthrough in Performance Case Design
Cooling Systems

DeepCool Introduces CL6600 Case – A New Breakthrough in Performance Case Design

KIOXIA AiSAQ and memory-centric AI innovations enable AI-based automatic image recognition for logistics processes
Enterprise & IT

KIOXIA AiSAQ and memory-centric AI innovations enable AI-based automatic image recognition for logistics processes

Popular Reviews

be quiet! Dark Mount Keyboard

be quiet! Dark Mount Keyboard

Terramaster F8-SSD

Terramaster F8-SSD

be quiet! Light Mount Keyboard

be quiet! Light Mount Keyboard

Soundpeats Pop Clip

Soundpeats Pop Clip

Akaso 360 Action camera

Akaso 360 Action camera

Dragon Touch Digital Calendar

Dragon Touch Digital Calendar

Noctua NF-A12x25 G2 fans

Noctua NF-A12x25 G2 fans

be quiet! Pure Loop 3 280mm

be quiet! Pure Loop 3 280mm

Main menu

  • Home
  • News
  • Reviews
  • Essays
  • Forum
  • Legacy
  • About
    • Submit News

    • Contact Us
    • Privacy

    • Promotion
    • Advertise

    • RSS Feed
    • Site Map
  • About
  • Privacy
  • Contact Us
  • Promotional Opportunities @ CdrInfo.com
  • Advertise on out site
  • Submit your News to our site
  • RSS Feed