this post was submitted on 05 Feb 2024
-1 points (33.3% liked)

Firefox

17899 readers
46 users here now

A place to discuss the news and latest developments on the open-source browser Firefox

founded 4 years ago
MODERATORS
top 12 comments
sorted by: hot top controversial new old
[–] [email protected] 0 points 9 months ago (1 children)

As an IT Engineer this concept frankly terrified me and feels like your opening yourself up to a potential zero click attack - such as https://threatpost.com/apple-mail-zero-click-security-vulnerability/165238/

So my initial answer is an emphatic "please do not the ZIP". It could be as mundane as a ZIP bomb, or it could explain a vulnerability in the operating system or automatic extraction program. Having a human required to open the ZIP prior to its expansion reduces its attack surface area somewhat (but not eliminates it) because it allows the human to go "huh this ZIP looks funny" if something is off, rather than just dispatching an automated task.

With that out of the way - what's your use case with this? There has to be a specific reason your interested in saving a few clips here on one highly specific archive format, but not others like the tar unix archive, 7z, or RAR.

[–] [email protected] 0 points 9 months ago (2 children)

I didn't read your response beyond the first sentence.

If Apple can do this, why can't we?

[–] [email protected] 0 points 9 months ago

Why bother even answering in the first place if you didn't give an F lol, the dude tried to help you out

[–] [email protected] 0 points 9 months ago

I do not have an answer for that. But if you only plan to read one part of my answer I would suggest reading the last sentence of my response instead of the first. Can't help you if you don't tell me what's wrong.

[–] [email protected] 0 points 9 months ago (2 children)

That sounds like a great idea until you download a zip bomb

[–] [email protected] 0 points 9 months ago (1 children)

Doesn't most software now recognize that now though?

[–] [email protected] 0 points 9 months ago (1 children)

ZIP bomb is definitely among the most mundane of issues you could cause yourself by automatically unzipping something.

[–] [email protected] 0 points 9 months ago

Yeah you could get it caught in the zipper.

[–] [email protected] 0 points 9 months ago

It's my understanding that this is the default behavior on Macs: https://old.reddit.com/r/firefox/comments/n5l4de/is_there_an_addon_that_unzips_a_zip_file/

If they can do it, why can't we?

[–] [email protected] 0 points 9 months ago

I think it needs to be done by the operating system, extensions nowadays don't have the permissions to do that.

When I was using MacOS it automatically extract zipped files and I hated it so much, you accidentally click on a link, it automatically saves in download and automatically unzip it, leading to too much trash in downloads...

[–] [email protected] 0 points 9 months ago

You could write a bash script using inotifywait to watch for new files in your download folder and extract them if they are archives.

[–] [email protected] 0 points 9 months ago

If this werent a firefox question id say wget url | tar -xvf