Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Applications
    • Applications
    • Cybersecurity

    Mozilla Improves Web Browser Security in Firefox 66 Update

    Written by

    Sean Michael Kerner
    Published March 19, 2019
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Mozilla released the Firefox 66 update on March 19, providing users of the open-source web browser with new features that enhance user experience and improve security.

      Among Firefox 66’s new features is one that blocks websites from auto-playing sound, which can be an annoyance. Also, the search feature within the browser has been improved with enhanced capability to search across multiple open tabs on a user’s system. Additionally, security gets a boost in the new browser release with patches for multiple vulnerabilities and an expansion of the number of web content loading processes.

      “We are working to ensure Firefox users continue to experience best-in-class security and performance,” Eric Smyth, product manager of performance at Firefox, told eWEEK. “Doubling content processes from 4 to 8 will allow you to open more web pages more securely without significantly changing how much memory Firefox uses.”

      Smyth added that expanding the number of web content loading processes is part of Mozilla’s ongoing work to create a browser that is more secure and resilient to security threats. The new release follows Firefox 65, which was released on Jan. 29, integrating improved privacy controls into the web browser.

      With Firefox 66, Mozilla has also improved the way it shows security warnings in the browser to better help users understand risk. Among the warnings that have changes are SSL/TLS certificate error pages. Rather than simply identifying to a user that a given connection is not secure due to an SSL/TLS issue, the new warnings now state that a potential security risk is present and informs users of what steps they can take.

      WebAuthn Support

      Firefox 66 includes support for the new WebAuthn standard based on the FIDO2 protocols, which provide strong authentication capabilities without the need for a password. WebAuthn is an evolution of the FIDO Alliance standards for strong authentication that have been supported in Firefox for several years.

      “As of today, Firefox users on the Windows Insider Program’s fast ring can use any authentication mechanism supported by Windows for websites via Firefox,” J.C. Jon, cryptography engineering lead for Firefox at Mozilla, wrote in a blog post. “That includes face or fingerprint biometrics, and a wide range of external security keys via the CTAP2 protocol from FIDO2, as well as existing deployed CTAP1 FIDO U2F-style security keys.”

      Scroll Anchoring

      A common experience for many visiting a web page is having the content “jump” ahead as slow loading graphics and other media elements push content. In Firefox 66, Mozilla is integrating a web property for scroll anchoring that will provide for smoother scrolling and prevent content from jumping as new content is loaded on a given page.

      Scroll anchoring is achieved with the use of a new draft web specification from the W3C.

      “Changes in DOM elements above the visible region of a scrolling box can result in the page moving while the user is in the middle of consuming the content,” the draft scroll anchoring specification states. “This spec proposes a mechanism to mitigate this jarring user experience by keeping track of the position of an anchor node and adjusting the scroll offset accordingly.”

      Security Updates

      In Firefox 66, Mozilla is also providing 21 security patches for vulnerabilities. The timing of the new security updates comes just ahead of the annual Pwn2Own hacking competition, which gets underway on March 20, where Firefox is a target. At Pwn2Own, researchers are awarded cash prizes for disclosing new zero-day vulnerabilities in software.

      Five of the patched vulnerabilities in Firefox 66 are rated by Mozilla as having critical impact. Among the critical vulnerabilities are multiple use-after-free and memory safety issues (CVE-2019-9790 and CVE-2019-9788). Researcher Samuel Groß of Google Project Zero is credited by Mozilla with reporting an additional pair of critical issues (CVE-2019-9791 and CVE-2019-9792) within Firefox’s IonMonkey just-in-time (JIT) compiler.

      “The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout,” Mozilla warned in a security advisory. “This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash.”

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×