Mozilla adds all recent versions of Java to its Firefox add-on blocklist
thenextweb.com
thenextweb.com
This advice feels very rash to me. This vulnerability (and most Java vulnerabilities in its class) affects ONLY the Java browser plugin. Many users won't know if they need Java on their computer, and common services like GotoMeeting and others use it transparently. Telling them to uninstall it will cause support headaches for companies that have coached the user through Java installation in the past and now suddenly it's gone. The result will be that after wasted time on everybody's part, they'll end up reinstalling Java and will be vulnerable all over again.
It would be much better to include proper instructions for how to disable it (or set it in click-to-play mode) in the browser than telling people to uninstall it carte blanche.
You can only disable, rename, delete or block (in the browser configuration) after installation. As of Java 7 Update 10 (12 Nov 2012), there is also a Java Windows Control Panel option to control the security configuration of browser plugin, including preventing it running. I do not know if changes to these settings still apply if further updates or other Java versions are installed.
However, all of these actions are non-trivial for typical users and besides Java is unlikely to be used on the desktop for most users.
I don't expect the browser to police the internet - it's not its job.
I'm actually gaining respect for IE these days - it doesn't pull shit like this and we have more control over it in a corporate environment.
An analogy, if my butler allows you into my home and he notices you opening the door to criminals, then he's going to demand that you leave. If he doesn't, I'm going to fire him. (Disclosure: I don't have a butler.)
Protecting users from getting compromised is part of the browser's job. Security on the internet is important.
The popup is necessary because many plugin elements are too small for a usable "click to play" message and button. Some websites use Flash content without any visible UI (elements that are just 1x1 or 0x0 pixels). For example, Gmail uses Flash for attachment uploading and audio chat. GitHub uses Flash for copying repo URLs to the user's clipboard.
Why not make it easier than going into about:config, then? In Chrome it's available in the settings.
> The popup is necessary because many plugin elements are too small...
How about a whitelist then, so that the main Flash applets on YouTube and other prominent sites with large, easy to locate Flash applets have a non-popup click-to-enable dialog (as is used by extensions like Flashblock)? That would cover 90% of use cases.
Also, how about an option to have click-to-play settings controlled on a per-plugin basis? I wanted click-to-play enabled for Java, but now I'm getting the same crap for Flash when I already have an extension (Flashblock) for that.
And even otherwise the popup doesn't have to protrude over the browser window. It could just be something in the chrome.
It can be annoying to remember to do it, the first few times you may curse the site for being broken before you realize what's going on.
I believe a per-plugin setting is planned.
I like your suggestion for a basic whitelist for popular websites like YouTube and Facebook.
How to enable: http://howto.cnet.com/8301-11310_39-57536917-285/enable-clic...
To enable all blocked plugins on page click the "lego" icon in the address bar. Plugins on demand can be enabled/disabled per-site in the site preferences (F12->Edit Site preferences) under the content tab.
And sometimes that's all it takes to cripple adoption of a platform.
I wouldn't be sorry to see it go.
Banks are feeling pressured already, with agressive customers telling them off on facebook when they try to tone this down. And I can't see Mozilla blocking BankID helping them any further.