Saturday, September 29, 2007

gmail security warning

If you have Javascript enabled, simply visiting a malicious site can cause your Gmail to be forwarded to them permanently. Even if you're using Firefox.

The solution: the NoScript extension for Firefox. It's easy to use--just click the icon in the bottom-right corner when you want to enable Javascript on a trusted site, and it'll remember your preference. For aimless web browsing, most sites should work without Javascript.

Even after Google fixes this vulnerability, NoScript is crucial from a security standpoint--when you have Javascript enabled without restriction, any site you visit can send a request to any other site, and it'll look like it's coming from you. The only way for sites to prevent this attack is to use random form tokens or otherwise unpredictable requests. It's not invincible, but it's one of the more difficult vulnerabilities to lock out, so you'll continue seeing attacks like this. Noscript protects you from them--and it's easy to use. Should be a simple decision.

2 comments:

Unknown said...

Wow. That's kind of frightening.

Unknown said...

NoScript is a great security tool, but it takes some getting used to. I actually have it disabled right now because it gets to be a hassle, but you might have frightened me into re-enabling it.