Mozilla To Force All Add-On Devs To Use 2FA To Prevent Supply-Chain Attacks – Comments

By   muhammad malik
Chief Editor , Information Security Buzz | Dec 16, 2019 04:17 am PST

Mozilla announced last week that all developers of Firefox add-ons must enable a two-factor authentication (2FA) solution for their account.

Subscribe
Notify of
guest
1 Expert Comment
Newest
Oldest Most Voted
Inline Feedbacks
View all comments
Ameet Naik
Ameet Naik , Security Evangelist
December 16, 2019 1:01 pm

The client-side is becoming the new battleground in the effort to secure web applications. According to a recent study from Osterman Research, 70% of the scripts running on a typical website are third-party scripts. Further, browser extensions wield potentially limitless power over web applications. These extensions are able to inject additional scripts, read all activity and harvest PII from web pages–all without the users’ knowledge. Website owners have no control over this either, but they carry a disproportionate amount of risk. This tarnishes their brand experience and hurts the users’ path to purchase.

We applaud this move by Mozilla to further secure the supply chain for browser extensions by enforcing two-factor authentication (2FA). This would make it harder for hackers to hijack third-party browser extensions and carry out digital skimming attacks.

Last edited 4 years ago by Ameet Naik

Recent Posts

1
0
Would love your thoughts, please comment.x
()
x