Saltar para: Posts [1], Pesquisa [2]

Komputilo

Informática: fichamentos / clippings / recortes de não-ficção. Nonfiction Litblog. Curador é Mestrando em Computação, Especialista em Governança de T.I., Tecnólogo em Redes, Técnico.

Komputilo

Informática: fichamentos / clippings / recortes de não-ficção. Nonfiction Litblog. Curador é Mestrando em Computação, Especialista em Governança de T.I., Tecnólogo em Redes, Técnico.

Mais sobre mim

Subscrever por e-mail

A subscrição é anónima e gera, no máximo, um e-mail por dia.

Arquivo

  1. 2024
  2. J
  3. F
  4. M
  5. A
  6. M
  7. J
  8. J
  9. A
  10. S
  11. O
  12. N
  13. D
  14. 2023
  15. J
  16. F
  17. M
  18. A
  19. M
  20. J
  21. J
  22. A
  23. S
  24. O
  25. N
  26. D
  27. 2022
  28. J
  29. F
  30. M
  31. A
  32. M
  33. J
  34. J
  35. A
  36. S
  37. O
  38. N
  39. D
  40. 2021
  41. J
  42. F
  43. M
  44. A
  45. M
  46. J
  47. J
  48. A
  49. S
  50. O
  51. N
  52. D
  53. 2020
  54. J
  55. F
  56. M
  57. A
  58. M
  59. J
  60. J
  61. A
  62. S
  63. O
  64. N
  65. D
  66. 2019
  67. J
  68. F
  69. M
  70. A
  71. M
  72. J
  73. J
  74. A
  75. S
  76. O
  77. N
  78. D
  79. 2018
  80. J
  81. F
  82. M
  83. A
  84. M
  85. J
  86. J
  87. A
  88. S
  89. O
  90. N
  91. D
  92. 2017
  93. J
  94. F
  95. M
  96. A
  97. M
  98. J
  99. J
  100. A
  101. S
  102. O
  103. N
  104. D
  105. 2016
  106. J
  107. F
  108. M
  109. A
  110. M
  111. J
  112. J
  113. A
  114. S
  115. O
  116. N
  117. D
  118. 2015
  119. J
  120. F
  121. M
  122. A
  123. M
  124. J
  125. J
  126. A
  127. S
  128. O
  129. N
  130. D

🦊 Mozilla ∋ programa de 💼 estágio


Mozilla Careers - Make an Impact:


We hire on a rolling basis from September through March, so please apply early!


Life@Mozilla blog - Make your mark with an internship at Mozilla (08/01/2019):


Recruiting begins in September, and we hire on a rolling basis through March. While there is no set application deadline, openings are limited, so we encourage you to apply early. [...] Mozilla has ten offices around the world, and nearly half of us work remotely from our homes or a coworking space.


Life@Mozilla blog - Paging summer interns (09/18/2019):


Recruiting begins in September, and we hire on a rolling basis through March. The average cohort size is 50 and positions are limited, so apply early!


Life@Mozilla blog - Creating opportunities in FOSS: Apply to Outreachy and contribute to Firefox (03/12/2019):


Did you know that some of [Firefox] contributors are students, who are sponsored or given course credit to make improvements to Firefox? [...] If you’re interested in getting involved, consider signing up to Mozilla’s Open Source Student Network and keep checking for opportunities at Google Summer of Code, Outreachy, codetribute. Finally, you should consider applying for an internship with Mozilla. Applications for the next recruiting cycle (Summer 2020) open in September/October 2019.


Life@Mozilla blog - Remote-Ready: How Mozilla Switched to Virtual Internships in Less Than a Week (07/30/2020):


Mozilla interns had always worked on-site. But [...] remote collaboration was already part of Mozilla [...], with nearly half the company working remotely even before the pandemic struck. “Because we were already so distributed, transitioning interns’ day-to-day work was actually relatively easy.” [...] By Friday, March 20, Frances and her teammates had an entirely remote program in place [...]. [...] What Mozilla learn[ed] in 2020 could help make future programs accessible to a much wider range of people for years to come: “Because we’ve tested this model, we may be able to expand to a more global internship program, where things like time zones won’t be an issue.”


🦊 Firefox: FTP removido ∵ 🔓 inseguro

Firefox Release Notes: 90.0, July 13, 2021.
FTP support has been removed
Caitlin Neiman on Mozilla Addons Blog. What to expect for the upcoming deprecation of FTP in Firefox, Apr 13, 2020.

FTP [...] predates the Web and was not designed with security in mind. Now, we have decided to remove it because it is an infrequently used and insecure protocol. After FTP is disabled in Firefox, people can still use it to download resources if they really want to, but the protocol will be handled by whatever external application is supported on their platform.

Google Group mozilla.dev.platform. Thread Intent to unship: FTP protocol implementation, Mar 18, 2020.
We're doing this for security reasons. FTP is an insecure protocol and there are no reasons to prefer it over HTTPS for downloading resources. Also, a part of the FTP code is very old, unsafe and hard to maintain and we found a lot of security bugs in it in the past.
We added the telemetry probes in bug 1579507 [1] to see how many users still use FTP. The usage was pretty low as you can see in bug 1570155 [2].
It's not right to waste smart network engineering time on decades old legacy code and it's likely even harder to justify a rewrite.
Christoph Kerschbaumer on Mozilla Security Blog. Blocking FTP subresource loads within non-FTP documents in Firefox 61, May 7, 2018.

The File Transfer Protocol (FTP) [is] one of the oldest protocols in use today and has a number of security issues. The fundamental underlying problem with FTP is that any data transferred will be unencrypted and hence sent across networks in plain text, allowing attackers to steal, spoof and even modify the data transmitted. To date, many malware distribution campaigns rely on compromising FTP servers, downloading malware on an end users device using the FTP protocol. Further, FTP makes HSTS protection somewhat useless, because the automated upgrading from an unencrypted to an encrypted connection that HSTS promises does not apply to FTP.

🦊 IRC.Mozilla.org: ⚰️ desligado após 22 anos em uso (1998-2020)

Mike Hoye, Mozilla's lead IRC decomissioner, on his personal blog "blarg?". Brace For Impact. March 6, 2020.

Last Monday we decommissioned IRC.Mozilla.org for good, closing the book on a 22-year-long chapter of Mozilla’s history as we started a new one in our new home on Matrix. [...] About three weeks ago [...] we turned on federation, connecting Mozilla to the rest of the Matrix ecosystem.

Mike Hoye, Mozilla's lead IRC decomissioner, on his personal blog "blarg?". Synchronous Text. April 26, 2019.

I wasn’t in the room when IRC.mozilla.org was stood up, but from what I’ve heard IRC wasn’t “chosen” so much as it was the obvious default, the only tool available in the late ’90s. Suffice to say that as a globally distributed organization, Mozilla has relied on IRC as our main synchronous communications tool since the beginning. For much of that time it’s served us well, if for some less-than-ideal values of “us” and “well”.

Like a lot of the early internet IRC is a quasi-standard protocol built with far more of the optimism of the time than the paranoia the infosec community now refers to as “common sense”, born before we learned how much easier it is to automate bad acts than it is to foster healthy communities.

Mike Hoye, Mozilla's lead IRC decomissioner, on his personal blog "blarg?". The Evolution Of Open. November 9, 2018.

IRC’s [...] ongoing borderline-unusability is a direct product of a notion of openness that leaves admins few better tools than endless spammer whack-a-mole. [...] “Working in the open”, [back in the days] where computation was scarce and expensive, meant working in front of an audience that was lucky enough to:

  • go to university or college;
  • whose parents could afford a computer at home;
  • who lived somewhere with broadband; or
  • had one of the few jobs whose company opened low-numbered ports to the outside world.

What it didn’t mean was [today's]:

  • doxxing;
  • cyberstalking;
  • botnets;
  • gamergaters;
  • weaponized social media tooling;
  • carrier-grade targeted-harassment-as-a-service; and
  • state-actor psy-op/disinformation campaigns rolling by like bad weather.

The relentless, grinding day-to-day malfeasance that’s the background noise of this grudgefuck of a zeitgeist we’re all stewing in just didn’t inform that worldview, because it didn’t exist. [...] We’re definitely not going to find any answers [to what we mean by "open" and its implications for community members] that matter to the present day, much less to the future, if the only place we’re looking is backwards.

🦊 Firefox ∩ 🔒 TLS

O Firefox vem, ao longo do tempo, desativando os padrões obsoletos e inseguros de criptografia de HTTPS, limitando-se ao TLS 1.2 e ao TLS 1.3:

2014 - Firefox 34.0 Release Notes:
Disabled SSLv3.
2018 - Firefox 61.0 Release Notes:
Improved security: On-by-default support for the latest draft of the TLS 1.3 specification.
2020 - Firefox 78.0 Release Notes:
We have disabled TLS 1.0 and TLS 1.1 to improve your website connections. Sites that don't support TLS version 1.2 will now show an error page.

Então agora só há criptografia forte?

Não exatamente... O TLS 1.2, lançado em 2008, se mostrava falho em 2018, na época do lançamento do TLS 1.3:

Mozilla Security Blog: TLS 1.3 Published: in Firefox Today August 13, 2018.
TLS 1.3 removes a lot of outdated cryptography:
  • TLS 1.2 included a pretty wide variety of cryptographic algorithms (RSA key exchange, 3DES, static Diffie-Hellman) and this was the cause of real attacks such as FREAK, Logjam, and Sweet32.
  • TLS 1.3 instead focuses on a small number of well understood primitives (Elliptic Curve Diffie-Hellman key establishment, AEAD ciphers, HKDF).

Porquanto o TLS 1.2 ainda seja amplamente empregado na Web, não foi desabilitado por padrão e, de momento, não possui previsão para sê-lo:

Mozilla Security Blog: Removing Old Versions of TLS. October 15, 2018.
TLS Version Usage (August-September 2018)
Version %
TLS 1.0 1.11%
TLS 1.1 0.09%
TLS 1.2 93.12%
TLS 1.3 5.68%

O que se fez até então foi remediá-lo desabilitando pontualmente algumas características dele, a fim de estender a vida útil do mesmo:

Firefox 78.0 Release Notes, June 30, 2020.
As part of our ongoing effort to deprecate obsolete cryptography, we have disabled all remaining DHE-based TLS ciphersuites by default.

Convém lembrar que criptografia forte não é uma panaceia. Ela serve a um dado propósito, e a outros não. É útil para evitar aulteração e quebra do sigilo dos dados enviados/recebidos (se não for burlada de alguma forma), mas não gera anonimato, por exemplo .

Atualização após a publicação do post:

Securing Connections: Disabling 3DES in Firefox 93, October 5, 2021.

3DES (“triple DES”, an adaptation of DES (“Data Encryption Standard”)) was for many years a popular encryption algorithm. However, as attacks against it have become stronger, and as other more secure and efficient encryption algorithms have been standardized and are now widely supported, it has fallen out of use. Recent measurements indicate that Firefox encounters servers that choose to use 3DES about as often as servers that use deprecated versions of TLS.

As long as 3DES remains an option that Firefox provides, it poses a security and privacy risk. Because it is no longer necessary or prudent to use this encryption algorithm, it is disabled by default in Firefox 93.

🦊 Firefox ∋ Modo Somente 🔒 HTTPS →maior obsolescência do 🔓 HTTP

Mozilla Security Blog - Firefox 83 introduces HTTPS-Only Mode. November 17, 2020.

The majority of websites already support HTTPS, and those that don’t are increasingly uncommon. Regrettably, websites often fall back to using the insecure and outdated HTTP protocol. Additionally, the web contains millions of legacy HTTP links that point to insecure versions of websites. When you click on such a link, browsers traditionally connect to the website using the insecure HTTP protocol.

[...]

HTTPS-Only Mode [is] a brand-new security feature available in Firefox 83 [(released on November, 17 2020)] [...] [that] ensures that Firefox doesn’t make any insecure connections without your permission. When you enable HTTPS-Only Mode, Firefox tries to establish a fully secure connection to the website you are visiting. Whether you click on an HTTP link, or you manually enter an HTTP address, Firefox will use HTTPS instead.

Once HTTPS becomes even more widely supported by websites than it is today, we expect it will be possible for web browsers to deprecate HTTP connections and require HTTPS for all websites.

Efeitos colaterais

  • For the small number of websites that don’t yet support HTTPS, Firefox will display an error message that explains the security risk and asks you whether or not you want to connect to the website using HTTP.
  • It also can happen, rarely, that a website itself is available over HTTPS but resources within the website, such as images or videos, are not available over HTTPS. Consequently, some web pages may not look right or might malfunction. In that case, you can temporarily disable HTTPS-Only Mode for that site by clicking the lock icon in the address bar.

Muito útil também para se esquivar de vigilância na rede, como, por exemplo, de um administrador de rede cujo firewall não tem a capacidade deep-packet inspection. A criptografia do HTTPS, nesse caso, evitará que as páginas acessadas fiquem registradas no log, ficando registrados apenas os endereços IP dos servidores ou o nome de domínio do site acessado.

Convém ter em mente, porém, que é absolutamente essencial dispor de TLS (criptografia) moderno para o HTTPS fazer alguma diferença, do contrário não passaria de um auto-engano.

Mais sobre mim

Subscrever por e-mail

A subscrição é anónima e gera, no máximo, um e-mail por dia.

Arquivo

  1. 2024
  2. J
  3. F
  4. M
  5. A
  6. M
  7. J
  8. J
  9. A
  10. S
  11. O
  12. N
  13. D
  14. 2023
  15. J
  16. F
  17. M
  18. A
  19. M
  20. J
  21. J
  22. A
  23. S
  24. O
  25. N
  26. D
  27. 2022
  28. J
  29. F
  30. M
  31. A
  32. M
  33. J
  34. J
  35. A
  36. S
  37. O
  38. N
  39. D
  40. 2021
  41. J
  42. F
  43. M
  44. A
  45. M
  46. J
  47. J
  48. A
  49. S
  50. O
  51. N
  52. D
  53. 2020
  54. J
  55. F
  56. M
  57. A
  58. M
  59. J
  60. J
  61. A
  62. S
  63. O
  64. N
  65. D
  66. 2019
  67. J
  68. F
  69. M
  70. A
  71. M
  72. J
  73. J
  74. A
  75. S
  76. O
  77. N
  78. D
  79. 2018
  80. J
  81. F
  82. M
  83. A
  84. M
  85. J
  86. J
  87. A
  88. S
  89. O
  90. N
  91. D
  92. 2017
  93. J
  94. F
  95. M
  96. A
  97. M
  98. J
  99. J
  100. A
  101. S
  102. O
  103. N
  104. D
  105. 2016
  106. J
  107. F
  108. M
  109. A
  110. M
  111. J
  112. J
  113. A
  114. S
  115. O
  116. N
  117. D
  118. 2015
  119. J
  120. F
  121. M
  122. A
  123. M
  124. J
  125. J
  126. A
  127. S
  128. O
  129. N
  130. D