Bug 1897585 Comment 7 Edit History

Note: The actual edited comment in the bug view page will always show the original commenter’s name and original timestamp.

Thanks for reporting your concerns. Here are a few extra questions that I hope can explain why this does not seem relevant to us, unless you have good answers for them.

(In reply to :0xbytecode from comment #0)
> so if attacker steal it he can't decrypt back .

Where would you store the encryption key to ensure that this attacker cannot decrypt the data? And how would you make sure that the decrypted data cannot be read by the attacker at the point where Firefox decrypts the data?

(In reply to :0xbytecode from comment #5)
> both of them used some like methods of this and they r patched now
> if they wasn't threat as u say , they wasn't be fixed now . and sure there all 

Do you have evidence of anything being fixed at browser level though?

(In reply to :0xbytecode from comment #5)
> highly detected By AV , EDRS
> highly detected by av,edr

As you say, AV and EDR are responsible for detecting and mitigating malicious activity from software running on your computer. So why are you reporting this here? If you found some way to write malware that is not detected by AV and EDR, shouldn't this be reported to AV and EDR companies instead?
Thanks for reporting your concerns. Here are a few questions that I hope can explain why this does not seem relevant to us, unless you have good answers for them.

(In reply to :0xbytecode from comment #0)
> so if attacker steal it he can't decrypt back .

Where would you store the encryption key to ensure that this attacker cannot decrypt the data? And how would you make sure that the decrypted data cannot be read by the attacker at the point where Firefox decrypts the data?

(In reply to :0xbytecode from comment #5)
> both of them used some like methods of this and they r patched now
> if they wasn't threat as u say , they wasn't be fixed now . and sure there all 

Do you have evidence of anything being fixed at browser level though?

(In reply to :0xbytecode from comment #5)
> highly detected By AV , EDRS
> highly detected by av,edr

As you say, AV and EDR are responsible for detecting and mitigating malicious activity from software running on your computer. So why are you reporting this here? If you found some way to write malware that is not detected by AV and EDR, shouldn't this be reported to AV and EDR companies instead?

Back to Bug 1897585 Comment 7