Mozilla To Force All Add-On Devs To Use 2FA To Prevent Supply-Chain Attacks – Comments

Mozilla announced last week that all developers of Firefox add-ons must enable a two-factor authentication (2FA) solution for their account.

Subscribe
Notify of
guest
1 Expert Comment
Newest
Oldest Most Voted
Inline Feedbacks
View all comments
Ameet Naik
Ameet Naik , Security Evangelist
InfoSec Expert
December 16, 2019 1:01 pm

The client-side is becoming the new battleground in the effort to secure web applications. According to a recent study from Osterman Research, 70% of the scripts running on a typical website are third-party scripts. Further, browser extensions wield potentially limitless power over web applications. These extensions are able to inject additional scripts, read all activity and harvest PII from web pages–all without the users’ knowledge. Website owners have no control over this either, but they carry a disproportionate amount of risk. This tarnishes their brand experience and hurts the users’ path to purchase.

We applaud this move by Mozilla to further secure the supply chain for browser extensions by enforcing two-factor authentication (2FA). This would make it harder for hackers to hijack third-party browser extensions and carry out digital skimming attacks.

Last edited 2 years ago by Ameet Naik
1
0
Would love your thoughts, please comment.x
()
x