The Register® — Biting the hand that feeds IT

Feeds

Mozilla site to offer multi-browser add-on security check

Keeps tabs on more than just Firefox

Customer Success Testimonial: Recovery is Everything

Mozilla plans to expand the reach of its web-based Plugin Check service so that it monitors whether add-ons on browsers from other suppliers are up to date and secure.

An earlier version of Plugin Check only checked whether Firefox installations were running with the latest version of Adobe Flash and Apple's QuickTime, for example. It's then up to surfers to visit relevant signposted websites and apply updates, which are not automatically downloaded.

The next version of the service provides a comparable check with Chrome, Safari and Opera add-ons. The technology will also work with new versions (7 and 8) of IE - although only a limited number of plug-ins to Microsoft's browser are checked by Mozilla's technology, Computerworld reports.

The cross-browser security check site, an extension of Firefox-only technology that launched last October, was due to debut on Wednesday but is not yet fully activated at the time of writing on Thursday. Checks on versions of Safari and Chrome running on a Mac detected version numbers of plug-ins but provided no information on whether they were up-to-date or not.

Security notification firm Secunia, which already provides similar functionality on the latest version of its Personal Software Inspector patching tool, which is available at no charge to home users, nonetheless welcomed Mozilla's move towards offering multi-browser security checks.

Thomas Kristensen, chief security officer at Secunia, told The Register that even though the Personal Software Inspector's coverage was "somewhat more extensive than what Mozilla offers" the browser maker's actions would help highlight the need to patch browser add-ons. "Lets hope that more [browser suppliers] will join the battle to thwart old insecure software," Kristensen said. "Patching is more important than having an anti-virus program and a personal firewall," he added. ®

Customer Success Testimonial: Recovery is Everything

@AC 17:03

It's not a software product, it's a webpage that speaks directly to your plugins (using <about:plugins> or the equivalent in javascript). The webpage itself can't be a security problem. If something breaks, it's the problem of your browser or your plugins.

1
0

Hmmm

Shouldn't they actually make sure it can detect FF plug-in versions properly first? On my systems the only plug-in it reliably detects the version of is Flash. It is a bit funny seeing things like "VLC Multimedia Plug-in Version 1.0.5 - Unable to Detect Plugin Version".

1
0

It couldn't even detect flash on mine..

"Silverlight 3.0.50106.0" ... "Unable to detect plugin version"

"Shockwave Flash 10.0 r42" ... "Unable to detect plugin version"

etc. etc.

FFS guys you *printed* the version.

0
0

More from The Register

Nuke plants to rely on PDP-11 code UNTIL 2050!
Programmers and their walking sticks converge in Canada
Bjarne Again: Hallelujah for C++
Plus: Now officially OK to admit you never used STL algorithms
Interwebs taunt Sir Jony over Apple eye candy makeover
Hey Ive, Ive... add more unicorns, willya?
SCO vs. IBM battle resumes over ownership of Unix
Zombie lawsuit back and wants to suck the brains out of Linux
Red Hat to ditch MySQL for MariaDB in RHEL 7
So long, Oracle! Don't let the door hit you on the way out
Shy? Socially inadequate? Fiddling with your phone could help
App 'tells the brutal truth' about social inadequates' chatup lines
Java EE 7 melds HTML5 with enterprise apps
New release arrives with GlassFish, NetBeans support
 breaking news
'Office Facebook' firm Tibbr wants you to PAY for mobe-meetings app
Great idea. Punters won't cough for it though
 breaking news
The only Waze is Google: Ad giant tipped to gobble map app 'for $1.3bn'
Pac-Man-satnav-ish upstart in bidding war with Apple, Facebook
 breaking news
PM Cameron calls for modern, programmable computers! (We think)
IT education musings to G8 chiefs to mystify IT industry