Firefox 88.0
mozilla.org
mozilla.org
The amount of complexity that one can put into a PDF is both surprising and a tad frightening.
Adobe had to update reader back in like... 2008?... to prompt before loading external resources. Because companies were embedding Google Analytics into PDFs.
Wow! This is daft. Thank the FLOSS gods for things like Pi-Hole because I never realised this. And if I hadn't blocked Google Analytics there, this would have been a sad state of affairs.
Can't edit my comment any more, but I realise this is quite dismissive of the work the real maintainers have put in. So I'll thank them instead!
[0] https://www.cs.odu.edu/~zeil/cs390/latest/Public/turing-comp...
Though I'm not entirely convinced they haven't accidentally added Turing completeness back in at some point.
I mean you don't really need all that much to write a basic lisp interpreter.
The PDF layout language isn't Turing complete on its own.
Basically, it was a PDF full of scripting and options and such, that let you:
* Choose which content you wanted to use (i.e. content from which sources) * Choose which rules you wanted to use (in case you wanted to use optional rules) * Choose your class, race, and background, and handle them appropriately * Level up your character, prompting you to choose spells, feats, abilities, etc. from every option available to you based on your current character options * Manage your inventory * Import and export your character data * Import and export source data
It was pretty insane. Granted, it was also insanely slow (presumably due to limitations of what data you can store in a PDF and how), but for a bunch of tech-savvy newbies to 5th edition D&D, it was vastly better than the other options and helped us discover a lot of character features that we'd missed when overwhelmed at first.
I still wish they'd put it into literally anything more performant, like an electron app or something. Yes, it was that bad.
It isn't expensive, it is just something to be aware of.
On the flip side, are there any examples of PDF JS being actually useful and not a vector for tracking/exploits?
This issue makes it seem that Components.utils.Sandbox is used when included in firefox, which would be the browser's own JS engine (but confined to a sandbox), and quickjs in other settings (say a website). https://github.com/mozilla/pdf.js/issues/12487
But I can't find Components.utils.Sandbox being referenced in the code on github. So maybe they decided to use quickjs for all use cases? The issue with quickjs is that it's written in C which is an unsafe language. wasm has bad binary security [0] so exploits are easier to create given some memory safety violation. The environment that calls the wasm is extremely privileged compared to random websites, so if a wasm exploit could convince the environment to do something, it would be major trouble.
[0]: https://www.usenix.org/conference/usenixsecurity20/presentat...
{ "policies": { "PDFjs": { "Enabled": false }, "DisableBuiltinPDFViewer": true } }
See:
https://support.mozilla.org/en-US/kb/managing-policies-linux...
I looked at the source code briefly and it's on the order of 10K lines of Javascript.
Just add a couple of lines of js for DOOM in the browser, now in js in a pdf in a browser!
off-topic, but fwiw: the pocorgtfo16.pdf[1] is a polyglot that is valid PDF, a ZIP archive, and a Bash script that runs a Python webserver which hosts Kaitai Struct’s WebIDE which, allows you to view the file’s own annotated bytes.
I thought they always required JS to be enabled. I have JS disabled by default in uBlock Origin, and the inbuilt Firefox PDF viewer doesn't work unless I whitelist and enable JS temporarily for the page. Only then can I read my PDF.
This new feature means you can run JS embedded in PDF… in PDF.js.
Certainly nothing will go wrong here.
Zero websites automatically get JavaScript access from me, and many other savvy web users.
If PDFs are not subject to these same controls in Firefox, then this could be a security and privacy vulnerability.
Even if this weren't true, it would still be false that "all websites already use JavaScript".
Does the JS run in a true sandbox? Inside, outside, or beside the usual browser sandbox? Are network requests allowed? Filesystem access? Are granular permissions required/available?
I want to block JS in PDFs, by default, like I do in web pages.
I'd also be happy to hear that the JS runtime in PDFs is run in a tight document sandbox, operates only on a highly constrained DOM-equivalent, and has zero network or filesystem access. Seems reasonable.
Odd, this is the only place I accessed it from. Not a big deal as it's still on the context menu and also can be added as a tool bar item but I am curious the rationalization behind this change. That seemed like a great place to have it to me.
But I think the whole "page actions" button is too hidden. I think screenshot belongs there, and the issue is that most people don't know without being told that "page actions" is something that even exists.
It's great btw to take screenshot of loooong web pages smoothly.
I'm a daily Firefox user for quite a while now... thanks for telling me this exists! Never really looked into what those 3 dots were.
(That being said, I always right click to trigger the screenshot option from the context menu.)
For efficiency Key combo > toolbar > command palette. I just hate to be forced into #3 because #2 doesn't exist. (not to mention that the developers make crazy arguments in the forums about why they refuse to impliment it... but that's all off topic)
I think it has to do with iframes.
You can shift+right click normally too, even when a page doesn't block right click.
Edit: this might be a small opportunity for some of the native FTP apps to jump in and handle the links. Click an FTP link in the browser and launch my FTP client with the details passed through.
...why. Obviously it's easy to add it to the overflow bar, but it was handy having it there. Especially on pages that block right-clicking (including for good reasons, like games).
Note that, in Firefox, you can always get to the context menu using shift-right click.
God I hate it when sites do that. There's a service that I pay for which disables right click, spams copyright notice modals every single time I try to copy any text and replaces the text I copied with useless copyright messages. It's so incredibly obnoxious it makes me want to scrape their content off their website out of pure spite.
???
Edit: Also great to see how they brush over existing users who have pinned the screenshot action to the toolbar, which is something you can do with all page actions (who knew?!).
We had discussed it before as a possibility, but I just confirmed with Romain that it's out of scope.
For reference, ~15k users have screenshots pinned to the URL bar and engaged with it within a 1 month period.
So apparently 15k people did know and now have to manually fix the regression, assuming they know how to do it. I still find it creepy that they gather data this specific, and of course users who disable "telemetry" mean nothing to them, they don't exist.
I'd be super happy if gathering such specific data by any application meant to the developers "15k users are using this feature, there is no way we can break their workflow" instead of "there's only 15k users out of [x], that's just 0.x%, we can ignore them".
I personally have never cared—there is nothing that can be learned about me (aside from being a power user, which I don't care about being public knowledge) from technical features I use. I absolutely block everything personal using uBlock Origin + Privacy Badger + FF's built in stuff, but I definitely see the value in tracking feature use.
This is a super nice little QoL improvement, but I'd love to be able to configure this to be even longer (optimally by domain, but I'd love a global setting too).
[0] https://phabricator.services.mozilla.com/rMOZILLACENTRAL1513...
Glad that they're still looking after Linux users.
[0] https://www.linuxadictos.com/en/firefox-88-will-activate-the...
edit: I gotta say, why the fuck would someone downvote this comment?
Firefox is using 55% of my CPU, whilst Safari is using 3%.
As someone who used Firefox exclusively back in the day (and mozilla before that), I will continue to try tests like this every time a new Firefox is released. Maybe, someday, the energy contrast will be less dramatically in Safari's favour, and I'll switch back to Firefox.
Firefox 88 (no extensions, private mode):
CPU% 55 (avg) 61 (peak)
GPU% 65 (avg) 77 (peak)
Safari (no extensions):
CPU% 33 (avg) 40 (peak)
GPU% 33 (avg) 40 (peak) <- same numbers for both CPU and GPU in safari.
Chrome: ~20% Safari: ~35% Firefox: ~45%
I'm looking to move to Safari by default. I just need to get over some UI differences. It drives me nuts that Firefox doesn't use the native context menus (I use "Look Up" constantly) and Text Shortcuts don't work. There's a bug for this filed literally 20 years ago.
Each browser has different trade offs and those may not change over time. I'm glad Safari fits your needs.
⌘-^-D the keyboard shortcut also works.
Firefox has had some bugs around this.
https://superuser.com/questions/1138014/how-to-use-three-fin...
Chrome ~2.5% https://streamable.com/flb8rh
Firefox ~3.5% https://streamable.com/dkrp0w
- Chrome 5-8%
- Firefox 6-7%
But note for others: you need to be logged out of GitHub to see the animation. Or open GitHub in a private window.
And this apparently happens quite a lot [no security patches in between versions]: https://www.mozilla.org/en-US/security/known-vulnerabilities...
Not that I much care - FF4Lyfe here!
Personally I would prefer to keep things as simple as possible, but unlike the maintainers of those projects, when it comes to making releases, I'm not perfect.
https://groups.google.com/forum/feed/mozilla.announce/msgs/r...
... which has been awesome, but I note I didn't get an item for this new version - looks like as of a couple weeks ago they have moved to a new mailing list system so this feed is gone.
The new Google Group is https://groups.google.com/a/mozilla.org/g/announce but after a few minutes of guessing I haven't figured out how to get an RSS view.
- have bookmarks/history stay on the page you open it on (and no other)
- have bookmarks and history occupy a full page, instead of shoveled into a GUI element, dialog style
- option to collapse tabs into a page (tab)
- make the "tabs window" (the downward arrow after +) a tab, so the tabs can be sorted, searched in, or copied from, as html, to a file (I now get a rather useless list of 100 tabs)
- have navigation to all of these pages, along with recent Downloads and options like Help and New Private Tab, right from the New Tab page, and leave the hamburger menu for page specific actions.
And more. But even without Firefox is a great browser.
I strongly prefer it to the apparent alternative, which seems to be an HTML-native interface in a tab. In fact I think doing that to preferences (about:preferences) was a step in the wrong direction. Not only is the result rather ugly (IMHO), I'm constantly losing my preferences tab among my other tabs, whereas a separate window with a native UI has a single instance (more appropriate for preferences) and doesn't get commingled with web pages.
These are accessible at:
- chrome://browser/content/places/places.xhtml
- chrome://browser/content/places/historySidebar.xhtml
- chrome://browser/content/places/bookmarksSidebar.xhtml
Not sure why they're not shown as tabs by default like the rest of Firefox's menus.
Ctrl+Shift+O and Ctrl+Shift+H respectively.
They also need some tab grouping thing like Chrome, which ironically they pioneered but abandoned.
I would hate that very much because I don't see the necessity for a whole page.
If you go to about:performance, you can double-click on a Tab entry, and it will jump you to that tab.
edit: I'm surprised people like them:
https://mk0ghacksnety2pjrgh8.kinstacdn.com/wp-content/upload...
Did they really revert the megabar? I can't find anything about that with searches. (I fixed it to look exactly like the old design with usercss, so I can't easily check myself.)
As a side note, anyone using TreeStyleTab is probably immune from Mozilla's awful tab style revamp, as the tabs in TST are styled using CSS by the extension.
Collections seemingly reinvent the wheel but limit the number of bookmarks, and force me to swipe left to view them.
And it would be great if selecting url bar would also allow me to choose one of my collections. Now I have to open a new empty tab first.
Edit: basically what a sibling comment wrote I see
That's the first item listed under Features, yet I wouldn't classify that as a feature! That's a vulnerability waiting for an exploit.
Every streaming video call I do through Firefox turns my MBP into a toaster.
According to Apple's Energy usage tool, Firefox bloats up to 70, while Safari is around 4 for the same Zoom call. Oof.
I really want to love Firefox, but it destroys my battery life. Faster than 1% per minute while on a streaming video call.
It's weird that a new profile was created in the first place.
As far as I can tell I still can't play breakout in a PDF in Firefox though (and I think that's for the better)
[0] https://rawgit.com/osnr/horrifying-pdf-experiments/master/br...
not sure why at this point.
And you still have to manually configure Firefox to use the native full-screen-api so you can use the macOS menubar to chance your volume. Horrible, just horrible ...
But I'm currently on Firefox Nightly and pretty happy about the recent UX/UI changes.
I really want to like Firefox and I want there to be viable alternatives to Chrome but when playing video back at 360p (not joking) grinds my 1.5 year old Macbook Pro to a halt on a popular website... I just can't use it.
I don't know if this is a video codec issue, a CSS/JS issue that Twitch manages to trigger or what but it's a problem.
[1]: https://bugzilla.mozilla.org/show_bug.cgi?id=1403823
[2]: https://www.reddit.com/r/firefox/comments/917hyv/twitch_in_f...
1. Why don't users have to do that with Chrome?
2. While it does help, the video-without-chat CPU+GPU usage is still higher than Chrome's CPU+GPU usage for video-with-chat.
If that also applies to Youtube or other services and has been open for 4+ years then... yeah, big problem.
What were they thinking? It’ll just get disabled in a few months because it makes for one awesome vector attack.
While we have a automatic deployment pipeline for our own projects, lots of our customers that host externally still use good old FTP.
I don't think FTP is ever going to fully die. It is still a typical way to deploy your files when using a shared web hosting that does not offer SSH.
Just be aware that any FTP upload capability offered is likely a serious pain for the admins on the other side. Even if they finally get it configured well enough to mostly forget about, they'll have to dive back in every time they upgrade any infrastructure along the path to it. It's much easier to just pass a TCP port though, which is what scp/sftp (the SSH variant, not the misnamed ftp/s variants some clients used to advertise as it) is much easier, and if you use rsync, includes easy recovery.
That is true only for active mode FTP. Firefox (and many other clients) already used passive mode FTP by default, which passes through NATs and firewalls just fine without need for special help.
This is what the ip_conntrack_ftp and ip_nat_ftp Linux kernel modules are, a way to make iptables more FTP aware by supplementing iptables at the kernel level.
This is also what OpenBSD's ftp-proxy utility is for, a way to deal with this without resorting to privileged specialty packet processing code, and a way to bypass not being able to see into encrypted traffic.
The fact that these workarounds exist is a testament to how hard FTP has been to deal with in the modern era of the web.
Surely those abominations are almost dead now though, in the age of the low-overhead VMs?
Wordpress is still a huge part of the Web and is running fine on shared hosting. And yes it can be an appropriate and cost effective choice for smaller sites even in 2021.
Also adding to that, the one time I did migrate a project from shared hosting to a dockerized VM solution was when the hoster was not supporting the needed PHP version anymore. Meaning hopelessly too old to ever update.
python -m http.server [port]
This will share the current directory using HTTP on port 80 by default unless you provide an alternative with [port].
Print in firefox is totally broken. The change to Chromium was the last nail in the coffin for printing. The new web does not care.
I don’t think that Firefox uses code from Chromium for printing, does it? I believe that the print interface merely resembles that of Chromium.
On more and more pages I encounter issues like the printer only printing out the cookie warning window, or just the left navigation bar, etc. and none of the actual page content that I wanted to print. Or content goes up to the first in-line advertisement and then cuts of there with just blank pages coming out of the printer after that. Or weird pagination issues where there's text on page 1 and text on page 2, but there's a bunch of text missing in between that is otherwise visible fine on the screen.
I'm talking about web pages that don't specifically have a "print" button on them. If it looks like the page is using a fancy layout I typically now just do a screenshot and print the resulting .png.
Macbook Air M1
On Linux hardware accel is still iffy, on macOS they implemented support for CoreAnimation one or two years ago, and still looks out of place with the rest of the OS.
Not for me on desktop with a pretty well specced machine, Firefox still runs better on Linux than Windows and I constantly boot into the other during one day.
Might be my underpowered 10900K or $1500 GPU.
Firefox on Windows does.
The Mozilla mission 2005:
"Established in July, 2003, with start-up support from America Online's Netscape division, the Mozilla Foundation exists to provide organizational, legal, and financial support for the Mozilla open-source software project."
The Mozilla mission 2021:
"Our mission is to ensure the Internet is a global public resource, open and accessible to all. An Internet that truly puts people first, where individuals can shape their own experience and are empowered, safe and independent."
This shift has manifested itself in different ways which broadly align with American left politics. The homepage and blog are speckled with articles promoting diversity initiatives, endorsing BLM, calling for systemic change, endorsing net neutrality, and fighting misinformation.
Mozilla is also one of the organizations at the forefront of sanitizing language it deems problematic in any way:
* Removing "meritocracy" from the governance docs - https://blog.mozilla.org/careers/words-matter-moving-beyond-...
* Changing "master password" to "primary password" - https://support.mozilla.org/en-US/kb/primary-password-replac...
* Removing "crazy" from the codebase - https://bugzilla.mozilla.org/show_bug.cgi?id=1675987
* Removing words deemed as reference to mental illness - https://bugzilla.mozilla.org/show_bug.cgi?id=1675986
Some like this sort of thing and see it as positive, to other it's alienating.