Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Call me paranoid, but after I read about this service I immediately started thinking what would happen if the browser was compromised - no UAC prompt and elevated privileges through the service...


I should hope the service does not use the browser to configure itself. It should directly contact mozilla servers including verifying some kind of encryption signature.

So if anything it could mitigate a compromised browser by overwriting it with a good one.


the service could verify that the browser is constantly in a safe state monitoring file changes, SHAs, etc


The service wouldn't give the browser elevated privileges. If you're worried about an update being compromised, then don't, since they're delivered over SSL and (I believe) are also signed separately.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: