HomeSecurityMozilla Asks FBI to Reveal Firefox, Tor Browser Zero-Day

Mozilla Asks FBI to Reveal Firefox, Tor Browser Zero-Day

The Mozilla Foundation filed a motion in the U.S. District Court in Tacoma, Washington, yesterday, asking the judge to force the government to disclose a potential zero-day vulnerability in the Tor browser, which may also affect Firefox.

The motion was filed in the United States case against Jay Michaud, which is one of several child pornography possession indictments filed following the Playpen operation.

Mozilla Asks FBI to Reveal Firefox, Tor Browser Zero-Day
The Tor Browser zero-day could actually be a Firefox zero-day if the exploit affects some of the parts it borrowed from Mozilla's browser.

In late February and early March 2015, the FBI seized the Web server that ran the “Preteen Videos—Girls Hardcore” Dark Web Portal.

This website was a safe haven on the Dark Web, where criminals exchanged images of child pornography. The FBI conducted a Network Investigative Technique (NIT) on this server that helped identify and charge over 137 US citizens.

One of them is Jay Michaud, who fought the charges and asked the judge to force the FBI to disclose the technical details through which it tracked him down, so that its computer forensics experts could analyze their effectiveness.

The judge agreed with his request, and later court documents revealed that the FBI was in possession of a zero-day vulnerability (unpatched security bug) in the Tor browser.

The Tor Project built the Tor browser into Firefox ESR (Extended Release Support), and technically, the Tor Browser zero-day could actually be a Firefox zero-day if the exploit affects any of the parts it borrowed from Mozilla's browser.

The Foundation now argues that the FBI should have disclosed this security flaw to them first, allowed their engineers 14 days to fix it, and then disclosed it to Michaud's technical experts.

“Since the court ordered vulnerability disclosure, it should also follow the best practices for advance disclosure that are common in community security research,” Mozilla’s Denelle Dixon-Thayer wrote on the Foundation’s blog. “In this case, the judge should require the government to disclose the vulnerability to the affected tech companies first, so they can fix it quickly.”

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS