November 28, 2017 By Larry Loeb 2 min read

Cybersecurity education and security awareness have been important components of security for some time, but it’s never been easy to get companies to buy into the effort. One web browser is making an effort to change that.

Cybersecurity Education Takes Center Stage

Mozilla is working to integrate the data breach service Have I Been Pwned into Firefox’s user interface (UI). According to GitHub, Mozilla aims to use the service to alert users about data breaches and provide them with a bit of cybersecurity education.

Have I Been Pwned is a widely respected site run by Australian security researcher Troy Hunt. Its integration into a browser will alert users to data breaches that have led to credential leaks, potentially preventing Firefox users from falling prey to attacks.

Users will be automatically notified when they enter a site that has been recently breached. The browser will also offer a “Learn more” link when alerting users so that they can access additional information about data breaches within the Firefox UI. Those who are interested can then choose to join a service that will notify them about when they might be affected by future breaches, the information on GitHub explained.

Maintaining Data Security

According to Infosecurity Magazine, Hunt expressed some concerns about preserving data security during the process. “What I can say for sure is that no passwords will be involved here — I don’t store them nor do I provide any means of querying them, and I won’t be providing them to anyone else either,” he noted.

Mozilla is sensitive to these privacy issues. The company is working to determine who the custodian of this data will be and how it can offer functionality to users who opt out of subscribing to notifications. As noted by InfoSecurity Magazine, “While the project is still in infancy, the idea is to offer as much utility as possible while respecting the user’s privacy.”

It remains to be seen if Have I Been Pwned will make a big difference for Firefox users, but it’s a step in the right direction for a more secure future.

More from

New cybersecurity sheets from CISA and NSA: An overview

4 min read - The Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) have recently released new CSI (Cybersecurity Information) sheets aimed at providing information and guidelines to organizations on how to effectively secure their cloud environments.This new release includes a total of five CSI sheets, covering various aspects of cloud security such as threat mitigation, identity and access management, network security and more. Here's our overview of the new CSI sheets, what they address and the key takeaways from each.Implementing…

Threat intelligence to protect vulnerable communities

2 min read - Key members of civil society—including journalists, political activists and human rights advocates—have long been in the cyber crosshairs of well-resourced nation-state threat actors but have scarce resources to protect themselves from cyber threats. On May 14, 2024, the Cybersecurity and Infrastructure Security Agency (CISA) released a High-Risk Communities Protection (HRCP) report developed through the Joint Cyber Defense Collaborative that addresses the threat to these vulnerable groups, with findings contributed by the X-Force Threat Intelligence team.Cyber criminals seek stolen credentialsThe HRCP…

Overheard at RSA Conference 2024: Top trends cybersecurity experts are talking about

4 min read - At a brunch roundtable, one of the many informal events held during the RSA Conference 2024 (RSAC), the conversation turned to the most popular trends and themes at this year’s events. There was no disagreement in what people presenting sessions or companies on the Expo show floor were talking about: RSAC 2024 is all about artificial intelligence (or as one CISO said, “It’s not RSAC; it’s RSAI”). The chatter around AI shouldn’t have been a surprise to anyone who attended…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today