Backdoor in FireFox in Kali and Parrot OSes (and others)

No, but my perspective of them is still primarily limited to just this one Codeberg and the associated GitLab thread, so it may not necessarily reflect them as a whole.

Basically, the main point is that in order to use push notifications in Firefox, it is required to serve them from a server hosted by Google and operated by Mozilla. Here is the relevant article about the feature itself.

The most important quote is this one.

So assuming you want to know my perspective on the LibreWolf team’s stance on keeping this feature enabled, I think it is fine when viewed in the context of their mission to reduce browser fingerprinting. Their argument is that if you do not want your IP address to be stored by Mozilla for 90 days, you should use a VPN.

But, going back to this thread, the issue is that during initialization of Firefox for the first time, it connects to these Google-hosted Mozilla services without the user being informed of them. That should at least be changed so that such a feature is only opt-in, specifically when Web Push is enabled and actually utilized by the user during normal operation.

4 Likes