SUBSCRIBE

Mozilla hot under the collar over Firefox spoofing

A report by Canadian researchersย that repressive regimes are spying on dissidents with network intrusion software that masquerades as the Firefox browser has prompted Mozilla to fire off a cease and desist letter to the U.K. maker of the software.

Early this week Citizen Lab, a research outfit at the University of Torontoโ€™s Munk Centre for International Studies, reported the remote interception program FinFisher developed by British-based Gamma International was being used some governments to conduct online surveillance on anti-government activists and dissidents.
FinFisherโ€™s global foorprint. (Blue- none, Red โ€“ new sighting, Yellow โ€“ prior sighting)
ย 

โ€œWe had identified instances where FinSpy makes use of Mozillaโ€™s trademark and code,โ€ according to report by Citizen Lab researchers Morgan Marquis-Boire, Bill Marczak, Claudio Guarnieri and John Scott-Railton titled For Their Eyes Only: The Commercialization of Digital Spying. โ€œThe latest Malay-language sample masquerades as Mozilla Firefox in both file properties and in manifest.โ€

RELATED CONTENT

Whoโ€™s using my spyware on Toronto servers?
5 nations, 5 firms named as โ€˜enemies of the Internetโ€™

FinSpy is a component in FinFisher.

The report said FinFisher command and control servers were recently found in Hungary, Turkey, Romania, Panama, Lithuania, Macedonia, South Africa, Pakistan, Nigeria, Bulgaria and Austria. Taking previous Citizen Lab research this places the total number of countries where FinFisher command and control centres have been located to 36.

โ€œWe cannot abide a software company using our name to disguise software surveillance toll that can be โ€“ and in several cases actually have been โ€“ used by Gammaโ€™s customers to violate citizensโ€™ human rights and online privacy,โ€ according to Alex Fowler, the lead of Mozillaโ€™s privacy and public policy group. โ€œWeโ€™ve sent Gamma a cease and desist letter today demanding that these illegal practices stop immediately.โ€

In a blog post yesterday, Fowler also assured browser users that Firefox itself is not affected by the spyware.

โ€œIt is important to note that the spyware does not affect Firefox itself, either during the installation process or when it is operating covertly on a personโ€™s computer or mobile device,โ€ Fowler said. โ€œGammaโ€™s software is entirely separate, and only uses our brand and trademark to lie and mislead as one of its methods of avoiding detection and deletion.โ€

Citizen Lab said Gammaโ€™s surveillance tools were used in a spyware attack in Bahrain aimed at pro-democracy activists as well as the upcoming general elections in Malaysia.

โ€œEach sample demonstrates the exact same pattern of falsely designating spyware as originating from Mozilla,โ€ said Fowler. โ€œGammaโ€™s brochures and promotional video tout one of the essential features of its surveillance software is that it can be covertly deployed on the personโ€™s system and remain undetected.โ€

The Citizen Lab researchers also lamented the lack of controls on how such technologies are exported.

There is extremely limited candor from companies about the nature and scope of the due-diligence performed when sales are contemplated,โ€ according to the Citizen Lab report. โ€œIn what has been referred to as a โ€œpermissiveโ€ standard,ย  companies have sometimes stated that they will only sell to states that are not on official blacklists established by the European Union or the United States.โ€

However, companies have been โ€œopaqueโ€ about what actions are being taken about cases in countries such as Morocoo, Bahrain, and the United Arab Emirates where there are cases of the technologies being abused, the report said .

Improving the State of Affairs With Analytics Sponsor: SAS
Improving the State of Affairs With Analytics
Download this case study-rich white paper to learn why data management and analytics are so crucial in the public sector, and how to put it to work in your organization.
Register Now


Tech Jobs

Categories