Check your Firefox extensions today. Some may leave your system open to attack

firefox 55 adds webvr support
Popular Firefox add-ons may expose systems Kārlis Dambrāns/Flickr
It’s a good idea to check your browser extensions if you use Firefox. Nine of the 10 most popular extensions for Mozilla’s browser open computers to malware and security breaches, according to a research paper presented at the Black Hat conference by a group from Northeastern University.

Among the top Firefox add-ons, only AdBlock Plus doesn’t make your system vulnerable. The nine that do allow potential problems are Video DownloadHelper, Firebug, NoScript Security Suite, DownthemAll!, Greasemonkey, Web of Trust, Flash Video Downloader, FlashGot Mass Downloader, and Download Youtube Videos as MP4. These 10 are all available on the Mozilla website.

The problem occurs when users install Firefox add-ons. Because of the way Firefox is designed, those add-ons aren’t protected from each other. The researchers reported that an add-on with malware can “conceal its malicious behavior by invoking the capabilities of other add-ons.” The bottom line is when you download and subsequently use a trusted add-on with the vulnerability, destructive action may take place in the background while you think everything is working correctly.

Nick Nguyen, VP of product for Firefox, acknowledged the issue in a statement to Digital Trends: “The way add-ons are implemented in Firefox today allows for the scenario hypothesized and presented at Black Hat Asia. The method described relies on a popular add-on that is vulnerable to be installed, and then for the add-on that takes advantage of that vulnerability to also be installed.

“Because risks such as this one exist, we are evolving both our core product and our extensions platform to build in greater security,” continued Nguyen. “The new set of browser extension APIs that make up WebExtensions, which are available in Firefox today, are inherently more secure than traditional add-ons, and are not vulnerable to the particular attack outlined in the presentation at Black Hat Asia. As part of our electrolysis initiative – our project to introduce multi-process architecture to Firefox later this year – we will start to sandbox Firefox extensions so that they cannot share code.“

How to remove Firefox Add-ons

If have Firefox installed on your computer, here’s what you can do today.

In the upper right corner of your display, on the same line where you enter URLs, look on the far right. Click on the icon with three horizontal lines to bring up the settings menu. Click on Add-ons. An Add-on Manager browser tab will open with a menu on the upper left side of your screen. By default the menu will open the Extensions window; this is where you want to check for any of the problem add-ons we mentioned above in this article.

If you find them, our suggestion is to remove them by clicking the Remove button for each. Don’t just click the Disable button to turn them off, you want them gone, so hit Remove.

If you find and remove vulnerable add-ons, it’s a great idea to run antivirus and spam checking software on your system. Set scan options for a full system check, not just the quick check mode most virus and malware scanning programs offer. Computer security, even for single systems at home, is a never-ending concern.

Updated on April 6 at 6 p.m. PT by Jeffrey Van Camp: Firefox got back to us with a quote. We’ve updated the article, which was originally published earlier today.


Back off, photo thieves: Flickr alerts photographers to image theft with Pixsy

Worried about someone swiping your photo off Flickr? The image sharing platform can now integrate with Pixsy accounts to alert photographers when a photo is used without permission by using artificial intelligence to scour the web.

Are flat pillows a pain in your neck? Here are the best pillows for side-sleepers

If you've tried doubling up on pillows or buying larger ones to no avail, then it might just be time for a new pillow – one made for sleeping on your side. We've rounded up the best pillows for side sleepers that give neck and head…
Movies & TV

Did I really watch that? Here's how to delete your Netflix viewing history

Everybody has some skeletons in their streaming closet, but you don't have to live with them if you don't want to. Learning how to delete your Netflix viewing history is easy, and we're here to help.

Here’s how to set up a virtual private network (VPN) on your Xbox One

Online privacy is more important now than it's ever been, and gaming is happening online more than ever before. Here's a quick guide on how to set up a VPN for your Xbox One so you game in safe anonymity.

The best iRobot Roomba deals to make cleaning your home a breeze

Keep your home clean without lifting a finger using a robot vacuum cleaner. These nine iRobot Roomba deals not only help you keep your home tidy, but many also come with advanced features such as automatic scheduling and Wi-Fi connectivity.
Movies & TV

No TV? No problem. Here's how to watch the NCAA championship game online

Whether you want to watch the Big Dance on your phone or on your smart TV, we have the lowdown on all the ways to watch March Madness you can handle. Grab your foam finger and some nachos.
Social Media

Facebook’s tributes section serves as an online memorial for deceased users

Death doesn't stop Facebook users from sharing memories, and now those memorialized posts have a dedicated spot on the network. Facebook Tribute is a section on memorialized profiles for users to write posts and share memories.
Social Media

How to protect yourself from GoFundMe scams before donating

Can you spot a GoFundMe scam? While the fundraising platform says scams make up less than a tenth of one percent of campaigns, some do try to take advantages of others' charity -- like a case last year that made national news.

House votes to restore net neutrality rules, but effort faces long odds

The U.S. House of Representatives has approved the Save the Internet Act, a measure intended to restore net neutrality rules that were repealed in 2017 by the Federal Communications Commission.

Search all of Craigslist at once with these great tools on web and mobile

Not finding what you need in your local area? Craigslist can be great for finding goods and services from further afield too. All you need do is learn these tips for how to search all of Craigslist at once.

The FCC and White House want to bring high-speed internet to rural areas

The FCC and the White House unveiled new initiatives to bring high-speed internet to rural areas, including $20.4 billion in incentives to companies to build infrastructure. The FCC also announced ways to speed up the rollout of 5G.

Internet Explorer zero-day exploit makes files vulnerable to hacks on Windows PCs

Evidence of an Internet Explorer zero-day exploit capable of letting hackers steal files from Windows PCs was published online by a security researcher who also claims Microsoft knew of the vulnerability and opted not to patch it.

Buying airline tickets too early is no longer a costly mistake, study suggests

When you book can play a big role in the cost of airline tickets -- so when is the best time to book flights? Earlier than you'd think, a new study suggests. Data from CheapAir.com suggests the window of time to buy at the best prices is…

Report says 20% of all 2018 web traffic came from bad bots

Distil Networks published its annual Bad Bot Report this week and announced that 20% of all web traffic in 2018 came from bad bots. The report had other similarly surprising findings regarding the state of bots as well.