Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Firefox does not use the OS's certificate store. They use their own, and each root cert must pass Mozilla's own policies. There are long discussions about some cert issuers; see Mozilla's "dev-security-policy" mailing list.

Somebody should file criminal charges against some of these outfits for violation of the Computer Fraud and Abuse Act. From the article: "the installers are so tricky and convoluted that we aren’t sure who is technically doing the “bundling,”". Now that's a good argument that the user gave the "bundler" permission, and they have thus "exceeded authorized access", as the Computer Fraud and Abuse Act puts it.



That would be great if the CFAA and the relevant police resources were actually used against fraud and abuse, rather than being used against copyright infringers all the time.


A few years ago, the FBI's online crime staffing was 50% "national security", 40% kiddie porn, and 10% everything else. Don't know if that's changed.

Someone hit by this should file a criminal complaint. If nothing is done about it, that can be publicized.


Fair point (and kudos to Mozilla), but unfortunately this doesn't protect 90% of other traffic passing through the host. As many (if not all) of the victims of this kind of attack are laypeople, a broader approach may be warranted.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: