Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Is there an issue with mitm attacks at hostile wifi points of access? Dns pointing to a bunk certificate authority maybe? I am not fully versed on this though so I don't know how possible this attack is.


The update payload itself is signed with a private key controlled directly by Mozilla, to avoid vulnerability to CA compromises [1]. The connection to the update server performs additional checks to ensure not only that the SSL certificate is valid, but that it matches one of a small list of known certs or issuers, so that a fraudulent CA can't hijack the connection with a forged certificate [2][3].

[1]: https://wiki.mozilla.org/Security/Reviews/Firefox10/SilentUp...

[2]: https://bugzilla.mozilla.org/show_bug.cgi?id=544442#c24

[3]: https://bugzilla.mozilla.org/show_bug.cgi?id=583678

(As a side note, the fact that this is necessary points out some of the major risks in the current CA system, which will hopefully be addressed in whatever eventually replaces it...)


Even if possible, all of those would be independent on whether updates install silently or not - they have always been downloaded in the background automatically.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: