Closed
Bug 1203170
Opened 9 years ago
Closed 4 years ago
redesign the distribution/ feature to support signing or search plugins with low startup impact
Categories
(Firefox :: Search, defect, P4)
Firefox
Search
Tracking
()
RESOLVED
WORKSFORME
Tracking | Status | |
---|---|---|
firefox43 | --- | affected |
People
(Reporter: florian, Unassigned)
References
Details
(Whiteboard: [hijacking][fxsearch])
The current way search plugins can be changed using the distribution/ feature is too easy to hijack, we need to design something better that will require the engines to be signed (or somehow verified). This shouldn't negatively affect performance.
Comment 1•9 years ago
|
||
putting low priority - but need to start with BD early and move up once impact/discussions have been had. shell put on agenda for bi-weekly discussion.
Rank: 40
Flags: needinfo?(sescalante)
Priority: -- → P4
Comment 2•8 years ago
|
||
I've gone through the data, and we have very low cases of search engine hijacking via the distribution/searchplugins directory. Access to that directory requires admin access and once the user has given that, anything in Firefox can be modified (including replacing omni.ja).
Comment 3•8 years ago
|
||
Hi Florian, Based on what Mike looked at - do we want to resolve this won't fix or just put as a P4.
Flags: needinfo?(sescalante) → needinfo?(florian)
Reporter | ||
Comment 4•8 years ago
|
||
(In reply to :shell escalante from comment #3) > Hi Florian, Based on what Mike looked at - do we want to resolve this won't > fix or just put as a P4. Shell, the next step here is Mike and me discussing this in person in London. P4 is fine for now.
Flags: needinfo?(florian)
Comment 5•4 years ago
|
||
Following on from the search configuration modernisation effort, we have now moved distribution handling into the central configuration, and the associated engines are shipped as app-provided engines.
As a result, we've also removed the old distribution loading functionality from the search service.
Status: NEW → RESOLVED
Closed: 4 years ago
Resolution: --- → WORKSFORME
You need to log in
before you can comment on or make changes to this bug.
Description
•