Mozilla suspends Firefox Send service due to malicious activity

Mozilla has temporarily suspended the file sharing service Firefox Send due to its involvement in the distribution of malware and complaints about the lack of funds to send abuse notifications about inappropriate use of the service (only a general feedback form was present). The work is planned to be restored after the implementation of the possibility of sending complaints about the placement of malicious or problematic content, as well as establishing a service for prompt response to such messages. It is also planned to disable the ability to send files anonymously - when placing a file in the service, it will become mandatory to register an account through the Firefox Account service.

Recall that Firefox Send allowed you to upload a file to the storage on Mozilla servers, up to 1 GB in size in anonymous mode and 2.5 GB when creating a registered account. On the browser side, the file was encrypted and transferred to the server in encrypted form. After downloading the file, the user was provided with a link that was generated on the client side and included an identifier and a decryption key. Using the provided link, the recipient could download the file and decrypt it on their side. The sender had the opportunity to determine the number of downloads, after which the file was deleted from the Mozilla repository, as well as the lifetime of the file (from one hour to 7 days).

Recently, Firefox Send has been in demand by cybercriminals as channel for dissemination malware, storage of components used in various attacks, and transfer data intercepted as a result of malware or compromised user systems. The popularity of the service among attackers was facilitated by Firefox Send's support for data encryption and password protection, as well as the ability to auto-delete a file after a certain number of downloads or expiration of the lifetime, which made it difficult to investigate malicious activity and allowed bypassing attack detection systems. In addition, links to the send.firefox.com domain in emails were generally considered trustworthy and were not blocked by antispam filters.

Mozilla suspends Firefox Send service due to malicious activity

Source: opennet.ru

Add a comment