Mozilla Monitor



Newsletter

  1. Mozilla Monitor Reviews

Subscribe to our Threatpost Today newsletter

Mozilla is a global non-profit dedicated to putting you in control of your online experience and shaping the future of the web for the public good. Visit us at foundation.mozilla.org. Most content available under a Creative Commons license. Firefox Monitor is a free service provided by Mozilla, which is the same company that created the Firefox browser. Will Firefox Monitor protect me from data breaches? No one — not even Firefox — can prevent data breaches from happening. We can alert you about breaches that affect you. My query is about the Mozilla product called Firefox Monitor, which monitors sites for data breaches, and informs whether my email address has been impacted. Emails come from breach-alerts@mozilla.com and have been very useful apart from this last one. Find out if you’ve been part of a data breach with Firefox Monitor. Sign up for alerts about future breaches and get tips to keep your accounts safe. Mozilla::Monitor is a bare wrapper around PRMonitor.Please see IntroductiontoNSPR for a high-level summary of its semantics. Methods Enter Enter the monitor. Exit Exit the monitor. Wait nsresult Wait( in PRIntervalTime interval = PRINTERVALNOTIMEOUT ).

Join thousands of people who receive the latest breaking cybersecurity news every day.

The administrator of your personal data will be Threatpost, Inc., 500 Unicorn Park, Woburn, MA 01801. Detailed information on the processing of personal data can be found in the privacy policy. In addition, you will find them in the message confirming the subscription to the newsletter.

Infosec Insider Post

Infosec Insider content is written by a trusted community of Threatpost cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.

Sponsored Content

Sponsored Content is paid for by an advertiser. Sponsored content is written and edited by members of our sponsor community. This content creates an opportunity for a sponsor to provide insight and commentary from their point-of-view directly to the Threatpost audience. The Threatpost editorial team does not participate in the writing or editing of Sponsored Content.

Firefox Monitor, a breach notification website launched by Mozilla in September, can now deliver alerts from inside the Firefox browser.

Once the service goes live in the coming weeks, Firefox users running version 62 and later will see an icon appear in the address bar when they visit a known breached website.

Clicking on this will reveal details of the specific breach supplied through Firefox’s integration with the Have I Been Pwned (HIBP) website, which Naked Security covered in September.

This will read something like:

More than x number of email accounts from example.domain were compromised in 2018. Check Firefox Monitor to see if yours is at risk.

Notice the alert won’t tell Firefox users that their personal account has been breached, only that they should check for themselves, offering them a link to do this.

The first time Firefox users see a breach alert for any website, it will relate to those added to the HIBP database in the preceding 12 months (the actual breach may have happened years earlier of course).

From there on, to avoid alert fatigue, the cut-off will be websites added within the preceding two months.

It will also be possible to turn alerts off completely by hitting ‘never show Firefox Monitor alerts’ on the notification drop-down box.

One giant leap for breach notification

Mozilla

Firefox has recently become a bit of a security and privacy control centre, incorporating more anti-tracking and security controls than any other popular rival browser.

In theory, breach alerts could become redundant because affected users would already know about the issue after being asked by a compromised site to reset their passwords. However, not all breaches lead to universal password reset with some websites limiting this to a subset of users it thinks have been affected.

With Firefox Monitor, all Firefox users visiting that website would see an alert for a breach they may and may not already know about.

On balance, this is a good thing. Resetting passwords on a breached website is a good precaution to take, just in case its extent has been underestimated.

It’s been asserted that alerts might frighten users away from a website, but the disclosure may serve to improve security practices among both site owners and users.

Arguably, the problem with browser breach alerts is that they give people general warnings about websites rather than more useful ones relating to their own accounts.

Cagily, Mozilla hints that personalised breach alerts might be on the list for future development:

Over the longer term, we want to work with our users, partners, and all service operators to develop a more sophisticated alert policy. We will base such a policy on stronger signals of individual user risk, and website mitigations.

Mozilla Monitor Reviews

It’s a complex undertaking to aim for on several levels (not least privacy) but one Mozilla seems determined to press on with.