Skip to content
View in the app

A better way to browse. Learn more.

Thailand News and Discussion Forum | ASEANNOW

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Mozilla says 'minimal risk' after leaving addons database on public server

Featured Replies

Mozilla says 'minimal risk' after leaving addons database on public server

2010-12-29 15:17:40 GMT+7 (ICT)

MOUNTAIN VIEW, CALIFORNIA (BNO NEWS) -- Mozilla on Tuesday admitted to have accidentally left a partial database of addons.mozilla.org user accounts on its public server earlier this month.

Mozilla was notified by a security researcher about the incident on December 17, reporting the issue via its web bounty program. However, the company said the incident has a "minimal risk."

"We were able to account for every download of the database," Chris Lyon, Director of Infrastructure Security, said. "This issue posed minimal risk to users, however as a precaution we felt we should disclose this issue to people affected and err on the side of disclosure."

The database included 44,000 inactive accounts using older, md5-based password hashes, Mozilla explained, saying that they erased all the md5-passwords, rendering the accounts disabled.

Lyon explained that all current addons.mozilla.org accounts use a more secure SHA-512 password hash with per-user salts. SHA-512 and per user salts has been the standard storage method of password hashes for all active users since April 9th, 2009.

"It is important to note that current addons.mozilla.org users and accounts are not at risk. Additionally, this incident did not impact any of Mozilla's infrastructure," Lyon added. "This information was also sent to impacted users by email on December 27th."

tvn.png

-- © BNO News All rights reserved 2010-12-29

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.