firefox logo
New features include a private browsing mode

Firefox 3.5 to be released today

Latest version set for UK availability at 5pm

Iain Thomson

Mozilla has confirmed that it will be making the final version of Firefox 3.5 available for download at around 5pm GMT today.

The new browser will include a number of advances, including geolocation software that can be used to provide information about local firms during searches. Other features include a private browsing mode that will not record which web sites have been visited and a speeded-up JavaScript engine dubbed TraceMonkey.

The latest version, which should be released in 70 languages, will also have improved stability and additional anti-malware features to protect users.

Demand for the new browser is expected to be heavy. The previous major release broke the world record for the most downloads in a single day after 8,002,530 people downloaded the code.

Earlier this month, Mozilla announced plans for a new service that will attempt to mitigate the effect of cross site scripting (XSS) attacks when using the Firefox browser.

Such attacks involve inserting malware into legitimate sites, which can be used to attack computers via the browser. The new Content Security Policy (CSP) system would defeat this by only accepting code from a cleared ‘white list’ of known web sites.

“One might ask if the vulnerable web sites are aware of their shortcomings in application security, why won't they address the root cause and fix their vulnerabilities?" explained the team on the CSP web page.

“Real world security, however, is usually provided in layers and Content Security Policy intends to be only one layer. Though the site may be free of vulnerabilities today, a new vulnerability may be introduced tomorrow which could remain fully mitigated by Content Security Policy until it is detected and fixed properly.”

The CSP system will demand that all JavaScript is loaded from an external file, and served from an explicitly approved host. This means that all inline script, javascript: URIs, and event-handling HTML attributes will be ignored.

“The bottom line is that it will be extremely difficult to mount a successful XSS attack against a site with CSP enabled,” said Brandon Sterne, security program manager for Firefox in the Mozilla security blog.

“All common vectors for script injection will no longer work and the bar for a successful attack is placed much, much higher.”

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Further reading

Firefox

Firefox 3.0.11 reaches 150 million downloads in 24 hours

Latest browser version proves popular

Firefox

Mozilla outlines upcoming Firefox 3.5 features

Feedback pouring in from 800,000 beta testers

Top 10 industry-changing applications

Spectacular products that changed the way we work

Mozilla fires up Jetpack for Firefox developers

API will let developers create add-ons using HTML, CSS and JavaScript

Related white papers

Related jobs

Most watched

ViewSonic ViewPad 7

ViewSonic ViewPad 7 video

Hands on with 7in tablet that features phone capability and Android 2.2

Samsung Galaxy Tab

Samsung Galaxy Tab video

We get a demo of the upcoming Android tablet from the IFA show floor

Analysis and Reports

Storage-as-a-Service: Best efforts or best practice?
IDG research: IT professionals understand the fundamentals of managing and protecting data, but do not apply best practices

The seven security myths of Microsoft Windows 7
It is essential to separate myth from reality about the built-in security of Microsoft’s latest offering

Poll

VMworld 2010 poll

VMworld 2010 poll

How advanced is your firm's cloud computing strategy?

View poll results

White paper library

Attachmate

Smartstream

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you thousands of white papers, case studies and analyst reports.

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Google logo

Google sketch could signal shift in search systems

Company plans major announcement Wednesday

HP

HP files legal complaint over Hurd move

Company seeks injunction citing trade secret concerns

Fujitsu Lifebook T730

Fujitsu Lifebook T730 video review

Laptop/tablet hybrid comes with Windows 7 and touchscreen interface

Druva

Druva offers remote backup for business laptops

InSync 4.0 backs up laptops to the datacentre over the...

Primary Navigation