Mozilla says a new Firefox security bug is under active attack
techcrunch.com
techcrunch.com
I assume some research into IonJIT will be done to see where it was introduced but by the sounds of what it does it could have been long ago.
Their "what's new" link in the beta's About window doesn't track with the beta release cycle. There's no revision listed, so I think the notes are for 73.0b1 still? At any rate, there's no mention of any security fixes.
https://www.mozilla.org/en-US/firefox/73.0beta/releasenotes/
Their developer edition "What's new" page seems more about marketing upcoming changes before they land in the mainline release than anything else.
I'd like to assume they're always on top of getting the same fixes into developer versions at the same time, but since they don't actually tell us anywhere I always feel like I have to check.
I did find these changes in 72 which look related to the bug:
https://hg.mozilla.org/releases/mozilla-release/rev/8260da04...
And poking at one of those referenced files in the beta channel looks like it has the same changes:
https://hg.mozilla.org/releases/mozilla-beta/file/tip/js/src...
So I think we're good on beta channel?
Isn't this the same company that was just being roasted for having spyware installed in Samsung phones?
Alternately, who knows whether they found this exploit a while back and only went public once they discovered someone else was using it?
With some effort javascript from known sites could be fingerprinted and vetted.
An unexpected change could trigger a warning and blocking.
But with WASM we are really in trouble.
Settings -> check 'I am an advanced user'. You should now be able to block 1st party, third party and inline JS from executing and save on a per-site basis. Hope this helps someone!
The phrasing may unfortunately mislead the less technical readers of their audience.
JavaScript always runs “on the host computer”, this should be described as a sandbox escape.
Simplifying terms and using approximations so that the uninitiated can understand is not lying, it's good communication. We can't use jargon all the time.
But they carefully qualified it with "outside of the browser [meaning sandbox]" and you left that out of your quote.
Also, while I have you, please stop using HN for ideological battle—you've been doing a lot of that as well, and it destroys what this site is for (https://news.ycombinator.com/newsguidelines.html), regardless of which ideology you favor or disfavor.
Also, can you please not systematically delete comments? Deletion is for things that shouldn't have been posted in the first place. Deleting more than half of what you post is not an intended use of the threads.