<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic drive-by email theft vulnerability in Discussions</title>
    <link>https://connect.mozilla.org/t5/discussions/drive-by-email-theft-vulnerability/m-p/89193#M34469</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Yesterday after visiting sites for a solar panel and a battery home energy storage system (renogy, sportsmanswarehouse), clicking on&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the google&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ads for them, I immediately received spam emails from two sites I visited. I ***never*** entered this email anywhere; not in&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;any form, not in an&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"inquiry" or sales form; not in related sites, not in purchases, etc. It was stolen without any action on my part, except&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;visiting these sites through a&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;google ad, while I was logged into google calendar app.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This happened shortly after I transitioned from safari to firefox on my old mac (macOS10.15.7). This was my private google email. I&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cannot&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;definitively point the finger at firefox, but the timing ***strongly*** suggests this, related to some failing of firefox security that safari is not&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;vulnerable to. My guess is that my google login credential was in a cookie that firefox allowed the sites to access, but safari does not.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Mac no longer supports the safari on this mac, so I cannot use it for many sites, but firefox does.&amp;nbsp; So, if firefox can fix this vulnerability -GREAT.&amp;nbsp; I would be much obliged.&amp;nbsp; If it does not, this computer has to go into a landfill, for no reason other than planned obsolescence, which is a bummer.&lt;/P&gt;&lt;P&gt;To my knowledge, I had fairly strict security mode settings in firefox.&lt;/P&gt;&lt;P&gt;Deets:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;FIREFOX 136.0&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;macOS10.15.7&lt;/DIV&gt;&lt;DIV&gt;MacBook Pro (Retina, 13-inch, Early 2013)&lt;/DIV&gt;&lt;DIV&gt;spam emails from: renogy@safeopt.com,&amp;nbsp;sportsmanswarehouse@d.sportsmans.com&lt;/DIV&gt;</description>
    <pubDate>Thu, 06 Mar 2025 20:00:04 GMT</pubDate>
    <dc:creator>ThePirate</dc:creator>
    <dc:date>2025-03-06T20:00:04Z</dc:date>
    <item>
      <title>drive-by email theft vulnerability</title>
      <link>https://connect.mozilla.org/t5/discussions/drive-by-email-theft-vulnerability/m-p/89193#M34469</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Yesterday after visiting sites for a solar panel and a battery home energy storage system (renogy, sportsmanswarehouse), clicking on&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the google&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ads for them, I immediately received spam emails from two sites I visited. I ***never*** entered this email anywhere; not in&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;any form, not in an&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"inquiry" or sales form; not in related sites, not in purchases, etc. It was stolen without any action on my part, except&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;visiting these sites through a&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;google ad, while I was logged into google calendar app.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This happened shortly after I transitioned from safari to firefox on my old mac (macOS10.15.7). This was my private google email. I&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;cannot&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;definitively point the finger at firefox, but the timing ***strongly*** suggests this, related to some failing of firefox security that safari is not&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;vulnerable to. My guess is that my google login credential was in a cookie that firefox allowed the sites to access, but safari does not.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Mac no longer supports the safari on this mac, so I cannot use it for many sites, but firefox does.&amp;nbsp; So, if firefox can fix this vulnerability -GREAT.&amp;nbsp; I would be much obliged.&amp;nbsp; If it does not, this computer has to go into a landfill, for no reason other than planned obsolescence, which is a bummer.&lt;/P&gt;&lt;P&gt;To my knowledge, I had fairly strict security mode settings in firefox.&lt;/P&gt;&lt;P&gt;Deets:&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;FIREFOX 136.0&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;macOS10.15.7&lt;/DIV&gt;&lt;DIV&gt;MacBook Pro (Retina, 13-inch, Early 2013)&lt;/DIV&gt;&lt;DIV&gt;spam emails from: renogy@safeopt.com,&amp;nbsp;sportsmanswarehouse@d.sportsmans.com&lt;/DIV&gt;</description>
      <pubDate>Thu, 06 Mar 2025 20:00:04 GMT</pubDate>
      <guid>https://connect.mozilla.org/t5/discussions/drive-by-email-theft-vulnerability/m-p/89193#M34469</guid>
      <dc:creator>ThePirate</dc:creator>
      <dc:date>2025-03-06T20:00:04Z</dc:date>
    </item>
  </channel>
</rss>

