Flash/HTML5 in Firefox

Friday, July 31st, 2015

I've been asked a lot lately about uninstalling Flash in Firefox and why users are still being served the Flash versions on Youtube, for example, and requiring them to install it before displaying the video.  I was asked again today and thought I would quickly post something about it. The easiest ...

Beware: Hola VPN turns your PC into an exit node and sells your traffic

Thursday, May 28th, 2015

Hola is a popular virtual private network (VPN) provider that is available for various web browsers including Google Chrome, Mozilla Firefox and Internet Explorer, as well as desktop and mobile operating systems. It is free to use and if you check ratings and users on Chrome's Web Store alone, you will ...

All Major Web Browsers Fall in Pwn2Own Hacking Contest

Friday, March 20th, 2015

Security researchers nabbed $552,500 in bounties at this year's Pwn2Own hacking contest, demonstrating exploits against the top four Web browsers, plus Adobe Reader and Flash Player. On Thursday, the second and final day of the competition, the star of the show was South Korean security researcher JungHoon Lee, aka "lokihardt," who ...

A secure version of user.js to harden Firefox installations

Sunday, December 21st, 2014

Warning: Backup your existing user.js file (if it exists) and use with caution.  Some website functionality may break. Some of the settings in this user.js file might seem redundant, as some of them are already set to the same values by default. However, the user.js file has this nice property, that ...

All major browsers fall during second day at Pwn2Own hacking contest

Friday, March 14th, 2014

Security researchers demonstrated zero-day exploits against Google Chrome, Microsoft Internet Explorer, Apple Safari, Mozilla Firefox and Adobe Flash Player during the second day of the Pwn2Own hacking competition Thursday, racking up total prizes of US$450,000. A team from French vulnerability research firm Vupen hacked Google Chrome by exploiting a use-after-free vulnerability ...