Welcome | Sign In
ECommerceTimes.com
Exploits & Vulnerabilities

Firefox Locks Out Microsoft's App Dev Tech

Print Version
E-Mail Article
Reprints
Firefox Locks Out Microsoft's App Dev Tech

Developers who use Firefox found themselves without some Microsoft add-ons after Mozilla blocked them due to security concerns. Browser access to one of the tools, .Net Framework Assistant, has been restored. The companies are working together to come up with a way to safely reopen access to Windows Presentation Foundation.


Listen to Your Customers, Grow Your Bottom Line.
Learn how loyal customers can be your best advocates for evangelizing your products and brand, while helping you to dramatically gain new business. Download "Customer Experience Management: Engaging Loyal Customers to Evangelize Your Brand."

Microsoft (Nasdaq: MSFT) technology used to program applications that can be accessed through a browser continued to be blocked for Firefox users Monday.

Mozilla had been blocking two Microsoft plug-ins after the discovery that Microsoft's .Net 3.5 SP1 install silently adds a plug-in to Firefox allowing the surreptitious launch of a malicious XAML browser application that could take over infected machines.

One add-on, the Windows Presentation Foundation, aids programmers in developing applications using Microsoft technologies, including Silverlight, that can be accessed via a browser. It remains blocked, but Mozilla Vice President of Engineering Mike Shaver wrote in a blog posting on Sunday that the Firefox team is working to find an alternative.

Restoration Timing Uncertain

Mozilla initially blocked Microsoft's .Net Framework Assistant as well, but reversed that policy after speaking with Microsoft engineers over the weekend and learning that it does not provide access to the same vulnerability.

The current blockade is redundant for users who have already applied Microsoft's patch for the vulnerability, which rolled out Oct. 12 as part of what Microsoft described as its largest vulnerability patch of 2009.

Although Microsoft has patched against the vulnerability, it's unclear when the Windows Presentation Foundation access will be restored.

Mozilla's press office did not return an email message seeking comment by deadline for this article.

Microsoft's Misbehavior

Most home users likely didn't notice anything more than an odd security warning when they fired up their browsers, but some may have encountered malfunctioning Web apps. Also, some enterprise users and designers may have faced trouble accessing custom applications and design capabilities through Firefox with the technologies blocked, said Wolfgang Kandek, CTO of Qualys, a vulnerability management company.

This is the second time this year Microsoft has been called out for silently installing plug-ins into Firefox. The first time was when the company included the Framework Assistant add-on in a service pack for the .Net application framework without alerting users.

"That normally is not considered to be good behavior," Kandek told TechNewsWorld.

Microsoft didn't respond to requests for comment by deadline.

Cooperation Between Competitors

While it appears that Mozilla initially overreacted in blocking the .Net Framework assistant, which is necessary for many third-party applications to run, it restored access to the plug-in quickly.

Mozilla and Microsoft appear to be working well together to address the issue for the benefit of users, Kandek said.

"I thought it was a great example of cooperation between two companies that are competing a lot," he said.


Print Version E-Mail Article Reprints More by Mike Pearson


Talkback: Join the Discussion.
For those that want to remove it
hairyfeet
Posted 2009-10-20
instead of just disable it, or want to get rid of the Java plugin, here is where they can be ...

More by Mike Pearson

Microsoft Gives Devs a Glimpse of HTML 5-Friendly IE9
March 17, 2010
Microsoft's preview of IE9 got a warm reception at MIX10 for its speed and support for HTML 5. However, XP diehards won't be able to use it, due to advances intended to reduce limitations on Web design and development. Creating a great next version of Explorer is critical for Microsoft as it attempts to build on the early success of Windows 7.
Facebook Traffic: A Whole Lot of Hustle but Not Much Flow
March 17, 2010
What does the mad rush of traffic to Facebook mean, really? The social networking colossus drew more traffic than Google for the third time this year, but Facebook still hasn't figured out how to turn all that activity into gold. It's not as though users are turning to Facebook as their primary Internet search tool -- and advertisers apparently don't see it that way either.
Analyst: WinPho7 App Tools Likely to Please Devs
March 15, 2010
Microsoft could become a contender in the smartphone space after all. It just introduced a set of developer tools for its Windows Phone 7 Series operating system with an emphasis on gaming. "If you think abut the smartest devices in the land -- prior to the iPhone -- that were mobile and handheld, they were the Nintendo Game Boys, the DSis and so on," noted IDC analyst Al Hilwa.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Free eBook: Secure Your Datacenter
Click here to download today.
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network