Thursday, November 08, 2007

Gmail + Firefox Extension Detection

This morning I check one of my gmail accounts like normal. However, today it is a little different at the top I see the below notification.


Now I guess it is nice that they let me know of the performance issue and they are just trying to make the user experience the best it can be. However, there are two "bad" things that come from this in my mind.
1) Google is looking at the extensions that are installed on my browser, what else are they looking at?
2) With this idea in mind I can think of the following scenario. A "security researcher" finds a zero-day in Firebug (this has happened before) and does not disclose it. They setup a site using the same code as Gmail but instead of posting a nice message exploits the zero-day and takes over the people's browser.

I am not the first person to think of this. But I was just reminded of it this morning. Thankfully I don't keep my Firebug enabled but I am sure quite a few people do.

I guess I will have to add this on to my research list.

0 Comments:

Post a Comment

<< Home