In Firefox 24 and following, mark all versions of Java as unsafe
bugzilla.mozilla.org
bugzilla.mozilla.org
In both, with my existing old build of Java, I got a placeholder image like this:
https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn...
Clicking it took me to the update page. Exactly what you want. There was an option in the top-left corner to forcibly load it, which is fine - updating is the right move.
Once I updated and uninstalled the old JRE, in Firefox 24 the applet I was trying loaded silently without any confirmation. It was not blacklisted.
In Firefox Nightly, once Java is updated, I see this placeholder where the applet would have been:
https://dl.dropboxusercontent.com/u/1643240/activate_java.pn...
Clicking the placeholder opens a prompt asking if I want to allow the plugin once or allow it always on this site. Very straightforward.
Other than the fact that modern Java 7 is not blocked by default in Firefox 24 for me (maybe they didn't roll that out yet?), everything works fine here, and I don't see any catastrophic UI mistakes, developer/enterprise-hostile design, or attempts at destroying the web.
What you are seeing on Firefox 26+ is all plugins except Flash becoming click-to-play by default: https://blog.mozilla.org/futurereleases/2013/09/24/plugin-ac...
I know it's to protect the users from themselves but if you're going to warn on all versions make it easier to allow the applet to run.
> https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn...
The problem is that this dialog box is outright lying. It will show that placeholder even with the latest version of Java installed.
Firefox is open source software. Open source software should be trustworthy. Software which lies to you is by definition not.
As things stand here, right now, it's Firefox which has a problem.
As a dedicated Firefox-user who dislikes the direction Chrome is taking, I still say Firefox has a problem here. This is something real users are experiencing.
I believe this as a whole will have a very negative impact on Firefox's perception in the java-heavier regions of the internet.
And damage done is hard to repair. Mozilla should think carefully and very quickly about what they just have done.
Edit: My bank's facebook page is already filling up with customers saying they can't log in. When the bank's reply is "Dont use Firefox. Firefox is broken" and the customer indeed can log in with other browsers, what chance do you think there is for the user going back to Firefox?
Mozilla needs to get 24.1 java-enabled-edition out there now, until it gets its UI/UX story straight.
Edit 2: Down-vote as you like. If you don't think this will affect Firefox's perception, you are a tad more optimistic than I am.
Given Javas security history, this seems correct.
You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1]
It's much less strict than in Chrome (on OS X), where Java doesn't run at all anymore.
[1] https://support.mozilla.org/en-US/kb/how-to-enable-java-if-i...
Allow me to disagree and to tell you what happened last weekend:
Last Sunday I had a call from my stepfather who "couldn't run the website to order agro food" anymore. This website runs a Java applet to manage agro food orders on-line and the code isn't signed (it's a small structure).
He tried to understand what was going on with the warning before clicking "ok/yes/run". He googled the warning and unfortunately ended up installing malwares from ads running on some PC help website/forums that promised to fix "2 just found vulnerabilities": he thought that was related since the warning actually preventing him from accessing his "working-fine-yesterday" website seemed to be about security and vulnerabilities in the plug-in.
He then tried to update Java but canceled it at the end of the process because the window with the Java propaganda ("it powers 3 billions of applications, your car, your website, etc.") looked too much like the one with malwares from before and those didn't fix the problem (not being able to access his website).
When I finally could go to his house to fix it I realized what had happened.
It is definitely not user-friendly. It was working before and in his eyes Mozilla made it not working anymore.
edit: typo and grammar
Funny, but he didn't installed the Ask toolbar :). I did when uninstalling/reinstalling Java and clicking a little bit too fast :). Hopefully it's not as tedious to remove as a trojan.
It tricks people to installing it, reports your search activity (maybe other data? I can't find details, not installing it myself), and takes major, unnecessary steps to make it hard to uninstall it. Sounds like malware to me.
Most common search suggestions for Cydoor (well known adware): http://i.imgur.com/iXqJdzU.png
Most common search suggestions for Ask Toolbar: http://i.imgur.com/HziYjkZ.png
Looks pretty similar to me.
After reviewing the facts by discussing them with nknighthb it appears the warning message that prompted me to blame Mozilla for a confusing warning message was due to Oracle and their Java warning pop-up. https://dl.dropboxusercontent.com/u/202857/java.png
My apologies :], I am a little bit ashamed for not spotting it sooner.
This is honestly what makes the Firefox warnings even more damaging than they already are.
If a brave user decides to click past the "DO NOT ENTER" sign on the Firefox warning, they are immediately presented with another worrying warning, popped up by the Java plugin. What kind of fool says "yes, please go ahead and do this dangerous thing" when two separate pieces of software have already told them not to? Not most, unfortunately.
At least I can make the Java plugin warning dialog be relatively calm by signing my JARs. The Firefox one is completely beyond my control.
I'd like to know if the Firefox developers have details on exploits that bypass the Java plugin dialogs. If they do, I'd like to know as well. If they don't, that means they're duplicating a security feature that's already in the plugin... what's the good of that? It just confuses and frightens the users of valid, secure Java applets.
I agree he's not computer savy but I am not blaming Mozilla for his installing malware. I am blaming Mozilla for a confusing message about security. See https://news.ycombinator.com/item?id=6590686
You have a user who has not been trained to not install random software, is fooled by extremely common ads, and who does not have the basic judgement necessary to not flail about when presented with something they don't understand but to consult someone who will understand.
This is a recipe for the exact scenario you described, but is in no way dependent on Firefox's Java messages. Any message appearing on their screen that they don't understand can be the trigger, including scammy ads encountered by millions of people in routine daily browsing.
[1] https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn...
[3] 1 & 2 taken from this thread: https://news.ycombinator.com/item?id=6590877
That's quite a stretch.
I have a user who uses frequently one specific website and for no apparent reason Firefox decides to tell him it's now dangerous to use with fearful and technological terms (vulnerabilities, plug-in, risk, etc.).
If Mozilla decides its users are dumb and should not be trusted to allow Java applet to be run then they should not warn them with techno-cryptic messages they know their users can't understand (because if Mozilla thought they could then Mozilla would know users could make the difference between a good and a bad applet and that warning wouldn't be needed).
A shorter and less scarier note would have been a better message for everyone.
How would you rephrase the warning in fewer than 8 words that would have helped your stepfather understand the problem and how to deal with it?
It's french but I doubt the translation process would made the word count explode from 14 words to this: https://dl.dropboxusercontent.com/u/202857/java.png
(and yes, it popped up on an up-to-date firefox with up-to-date java)
Maybe I got caught by the fact I had never seen that pop-up before and Firefox just seemed to have been updated the day before.
While we are on the topic: that makes a lot of clicking to get an applet running for the first time.
http://support.mozilla.org/en-US/kb/how-to-enable-java-if-it...
edit: formatting.
The appropriate training is nothing less than years of experience working with computers or being in the IT business. Why do we believe that this ought to be standard knowledge for users? It seems to me that we're placing too much burden on the user to make good judgements in the face of insufficient application and operating system trustworthiness.
We absolutely place too much burden on end-users -- one reason the iPad is such a hit -- but "don't believe everything you read on the Internet" and "ask me before you try to fix something you don't really understand" is not a heavy burden. If it were, we'd have a lot more mechanics and a lot fewer operable cars on the road.
Anyway, this is the warning my user was given : https://dl.dropboxusercontent.com/u/202857/java.png
Unmovable window, can't close firefox without first actioning something in it, one checkbox+one butotn to allow "something scary" to run (something that wasn't scary yesterday). This is what prompted my user to google the warning.
I've had multiple calls in the past week from Java users who didn't know that and just thought the page in question had stopped working. Your idea of "easily" and theirs are very different.
It's much less strict than in Chrome, where Java doesn't run at all anymore.
I've spent much of this morning testing applets in Chrome. In fact, I've got one running right now, and I just confirmed that Chrome is up-to-date. Perhaps you've misunderstood something?
Still, it's a much easier thing for normal users to figure out than how to update Java (which they must do quite regularly to get Java to run at all).
I did a little Googling and it turns out that Java still runs in Chrome on Windows, it's just banned on OS X.
Unfortunately, the applets I work on at the moment run on embedded web servers in network-enabled devices. You can't just roll out a quick update to this software every time Mozilla or Oracle break things.
You're not helping your case at all.
Accept responsibility for supporting your customers, and stop lashing out at others for not doing it for you.
Mozilla is taking the only responsible course to protect the vast majority of their users. It's been a long time coming, and absolutely no one should be surprised that it finally arrived. If anything, I'm surprised it took this for the first major browser to do it.
More will follow. Adapt or die.
An unfortunate comment, because some of the devices I had in mind when writing those last few posts are in fact medical equipment.
If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken. Delays and increased suffering for patients are all but certain consequences until the IT staff have chance to fix things again.
Fortunately, the software running on equipment that could actually cause death as a direct result of failure is written to much higher standards and shouldn't depend on this kind of technology in the first place.
If the product you are building is not future proof it is your problem not Mozilla's.
Dont blame Mozilla for your poor technology choices. Applets will eventually stop working, and you'll be responsible if your product fails , not Mozilla.
Dont blame anybody else but you. You broke the medical staff instruments by choosing or maintaining a dead technology thus putting patient lives in danger. Do you think they'll sue you ? or Mozilla if there is an accident? You are responsible.
Nothing is future-proof if the people controlling the platforms move the goalposts. We have standards and value backward compatibility for a reason: it's because violating those standards and breaking that compatibility hurts. And it's going to become Mozilla's problem if they continue down this path, because Firefox will cease to be a viable browser choice for a significant proportion of their potential market.
Dont blame Mozilla for your poor technology choices. Applets will eventually stop working
I don't know why you're writing as if I personally broke these medical devices. I've never personally worked on any of those projects, I'm just familiar with them and citing them as examples of why this sort of change is damaging.
In any case, people really should get off the "Java applets is a dead technology" bandwagon. Viable replacements using HTML/CSS/JS are very recent developments, and people have been developing web-based user interfaces for all kinds of devices for decades. Of course they're not all going to throw out all that work and rewrite everything from scratch. There's nothing wrong with it, and contrary to your claim, there is no reason those applets must eventually stop working. They'll work just fine as long as browsers run Java applets, which they've been doing just fine for many years.
Obviously applets will stop working if browser makers deliberately drop support for them even though it's been available for a very long time. However, that's like saying obviously CSS3 is no use for anything because it's not all W3C standardised in stone yet so you're stupid if you use it today because it might all be different at some arbitrary point in the future that no-one can predict. You can shoot down any technology, no matter how modern and trendy, with such a generic argument, but it doesn't demonstrate anything particularly helpful to do so.
You broke the medical staff instruments by choosing or maintaining a dead technology thus putting patient lives in danger.
No, I didn't, but if the serious software I work on were medical in nature, you could literally bet your life that I wouldn't be letting either Java or Firefox anywhere near it and would be using an entirely different level of engineering practice to build it, as I do for certain projects in other fields where reliability is essential.
However, while we build the literally life-or-death systems that way, chances are the word processor, KVM, and, yes, web browser that organisations doing vital work use for day-to-day activities are not developed to the same standards. Breaking them still hurts, if only in efficiency (which can obviously still be harmful in a medical context). Unless you're claiming that all software that runs in any medical facility must be developed to the same standards as control software for high-risk, safety-critical systems, again, your argument is so generic that it doesn't really prove anything interesting.
Actually, we've been doing that for quite some time on one of the major projects I work on that uses Java applets, for exactly this reason. We usually recommend a recent version of IE, and as a general policy we don't offer any sort of guaranteed support for Firefox or Chrome. Of course we still test on those other browsers routinely and we'll help customers who have problems if we can, but no-one is getting any money back if they break later because of the kinds of changes we're talking about.
The worrying thing for Mozilla should be how many businesses are essentially telling us that they agree and they're moving or already planning to move back to IE as their corporate standard. It's certainly not always because of Java, but choices like rapid update cycles, lack of long-term support, and willingness to drop useful functionality do seem to be generating an increasing amount of hostility from institutional users.
You're probably aware that in many, if not almost all commercial EULAs, you'll find an all-caps passage like this one I just pulled out of Apple's OS X license document:
> E. YOU FURTHER ACKNOWLEDGE THAT THE APPLE SOFTWARE AND SERVICES ARE NOT INTENDED OR SUITABLE FOR USE IN SITUATIONS OR ENVIRONMENTS WHERE THE FAILURE OR TIME DELAYS OF, OR ERRORS OR INACCURACIES IN THE CONTENT, DATA OR INFORMATION PROVIDED BY, THE APPLE SOFTWARE OR SERVICES COULD LEAD TO DEATH, PERSONAL INJURY, OR SEVERE PHYSICAL OR ENVIRONMENTAL DAMAGE, INCLUDING WITHOUT LIMITATION THE OPERATION OF NUCLEAR FACILITIES, AIRCRAFT NAVIGATION OR COMMUNICATION SYSTEMS, AIR TRAFFIC CONTROL, LIFE SUPPORT OR WEAPONS SYSTEMS.
It's stated clearly and at length because absolutely no one writing general-purpose software wants to bear this responsibility. FOSS no less than commercial, but FOSS is generally a less-attractive lawsuit target.
Trying to foist this responsibility onto Mozilla is just evil. They didn't ask for it. They didn't offer their software as a solution to medical IT's woes. But you want to blame them for obvious misuse of their software causing harm to patients.
If I were to die of an aneurysm tomorrow, would it be your fault for not being a competent neurosurgeon and healing me? No. Nor should it be Mozilla's fault that it does not produce a medical device, but a piece of software someone has decided to misuse as one.
Would that be a failure of Firefox (or other browser vendors) or a failure of hospital IT staff to manage the medical devices / desktops / network effectively?
Logically, if Firefox is not going to support long term stability and compatibility -- and clearly it doesn't in the case we're discussing -- then the only possible conclusion is that Firefox can't be part of an effectively managed IT infrastructure for these kinds of organisations. That means the correct course of action for those responsible for that infrastructure is to plan to remove any dependencies on Firefox as quickly as possible and to replace it with something more stable, which presumably means IE in this context.
You need to evaluate the ESR release, and/or find a different browser entirely. IE may indeed be the best option if you only support Windows clients. Though Microsoft hasn't exactly been shy about forcing IE along more quickly of late, either.
I'm not sure who mainline Firefox is intended for any more. That's part of the problem, I think.
It seems like Mozilla are chasing Google to the exclusion of almost anything else, and the main goal for both of them seems to be ticking boxes to say they have more bleeding edge features, even though hardly any real projects can actually use most of those features because they aren't stable and portable enough yet. Meanwhile, users get interfaces that subtly shift around every few days, developers are fighting a constant battle just to stand still, and as we've been discussing, organisations can't manage large-scale deployments robustly at all any more.
If you had a Java application, you would not have a problem. If you had a web application, you would not have a problem. If you had a C or C++ application built against either native Windows APIs or a mature cross-platform toolkit, you would not have a problem.
Instead, you rely on browsers continuing to put their users at risk by automatically running code in a constantly-leaking sandbox managed by a company that doesn't give a shit.
Understand this: Java is a hole in the defenses of modern web browsers. It is behind. Way behind. And it will remain so forever. It and its owner are not up to the task of dealing with the modern web.
So yes, you're going to be fighting a constant battle so long as you insist on relying on what everybody already knew was crap in the mid-90s.
Or you could just tell your users to click the magic button.
I work with the NHS in the UK; quite a few of the medical professionals are forced to use IE6 or IE7 because the hospital IT staff are managing their medical devices / desktops / network effectively, just as you say.
When Firefox makes a decision like this, what they apparently did not seem to consider is that they are drawing a cutoff line which has serious costs to some of their users. I didn't see any discussion of this whatsoever in the issue thread.
Imagine a relatively forward-thinking hospital that has been able to allow their staff to use fairly-recent versions of Firefox (once new versions have been vetted by IT). Changes like this may force them to stop deploying new versions completely, until some time possibly a decade from now when they're finally able to replace the Java-based UI.
That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically every single other browser plugin as well.
Maybe for corporate use, but isn't that mostly IE anyway?
Exhibit A: healthcare.gov
(And if this really is just a click-to-play type inconvenience, well, that's a hell of a lot less than the hoops that users are used to going through in order to get into their BankID banks here.)
Do they? I thought Sweden used the online bank identity system for verification (bankid), which is either a standalone downloadable application, a smartcard image, or an mobile app. Not sure how an Firefox policy would effect this even if some parts of the bankid uses Java.
I think the commenter shiloh.enriquez on that Mozilla thread had a decent point in that many users just want the thing to work, won't necessarily understand or have the patience to understand and will move from FF to Chrome or IE.
It's already live. ff24 is the current stable.
I just assumed Java was out of date (again) and was surprised to see it still blacklisted after updating to latest version.
There's no part of the UI saying "We've permanently blocked all of Java by default". Even if you agree with the developer's ideological stance here (which you very well may not), the UX part of the job is completely botched.
Pressing on that icon should allow you to run java once, or allow if forever for that site.
If the icon doesn't appear, I think you should file a bug on bugzilla.
I've yet to see a single non-technical user even notice or react to its presence once. I see it instantly and can't understand why it doesn't alert or annoy them, but to them, it's just not there.
In light of that sort of behaviour, adding a subtle icon to the location bar is meaningless. Heck, adding anything to the location bar is meaningless if the intent is to communicate with the user; most users never look there.
So yeah. If that's Mozilla's stance, they will find out that nobody's going to notice. I certainly didn't see it. That is effectively dead code which they've written.
It was released over a month ago too. Has it had any effect on Firefox's market-share? Especially in enterprise? It's a pretty decent test bed for understanding how users react to these kinds of changes. If they just accept them and adapt when forced it shows that we can be more proactive in moving users to better yet incompatible software?
No, the change went live Friday: https://bugzilla.mozilla.org/show_bug.cgi?id=914690#c20
The Reader "replacement" PDF viewer in Firefox is limited and buggy compared to the real thing. We also found it literally unusable for our purposes when it launched, and we routinely disable it on new installations where we still use Firefox at all (which is basically only test machines for web developers now anyway, because of exactly the recent attitude from Mozilla illustrated by this discussion).
I have avoided Reader for years by using Safari, and later Chrome, which each have their own built in PDF renderers. I'm glad that Firefox has caught up, it's one of the things that has kept me from using Firefox. I read a lot of PDFs, and loading the big, slow, clunky Reader plugin, or downloading the PDF, is a non-starter.
I hate Java applets as much as the next guy, but lets not ignore that there's a real world out there.
+ Fork if legally required.
A lot of corporates and financial applications require Java.
This action by Mozilla raises awareness of the fact that Java security updates are too slow and too opaque and it's time to change to something else.
That said, users of these plugins are not just going to stop using these services. They need these services to make bank payments or trade their shares. Getting hacked is a smaller worry than being unable to use those services. That just means they will swap to a different browser. The web becomes no safer, and only Firefox loses market share.
If you get hacked and someone steals from your bank account, the bank will reimburse you and the police will (try) track down the hackers. Same way as if someone broke into a bank vault and stole the money. Being unable to sell off your shares because Firefox blocked your trading app means you are forced to switch browsers.
Basically it's a pointless display. Just show a warning if a website tries to use a plugin (any plugin, including flash - there are numerous undisclosed 0-days) and move on.
It also raises awareness of the fact that you can't trust some of the big names in the browser industry not to break stuff every few weeks just because they don't like it and then push the changes on you whether you want them or not.
Introducing restrictions so tight that you can't actually do your useful work any more isn't security, it's just broken.
That sounds like a long time if you're reading this in Firefox on your home PC, but if you're responsible for a large corporate network with thousands of users and a hundred critical intranet applications to keep working, many of which have a measurable dollar amount attached for every hour of downtime, different rules apply.
There is a reason so many large organisations stuck with IE6 for so long: having tried and tested, stable software is far more valuable in that kind of environment than having the latest shiny features that none of the in-house applications you're actually providing the computers/browsers to use need anyway.
If you support the company where most of the users just know to click and login, and one day they just can't, you aren't going to like it, to quote one of the post from the bugzilla:
"I haven't been able to get VPN-ed in for days, until I figured I could still use the Juniper SSL VPN from Internet Explorer. I find it amazing the casualness with which a small group of developers just shut off an entire set of functionality with no regard for its size, utility... You just broke millions of peoples software, and then you complain about this being a bug list, and you can simply do this, or simply do that."
It doesn't help that "advanced users" would know, ordinary users after the automatic update can't do what they were able to do.
A few users are inconvenienced. That few being the intersection of those who rely on java applets for something they care about (already a tiny fraction) and those who lack the knowledge to solve the problem on their own (an even smaller fraction). Even losing that fraction of users is unlikely to affect firefox's marketshare to any significant degree.
In the context of a company's IT department, they should be competent enough to know how to set default browser configurations and to provide walk-through documentation. If an IT department thinks that user convenience is a good enough excuse to expose the company's employees to some of the most serious and hard to prevent web-based exploits out there then I say fuck 'em. They have their priorities all wrong and if they want to continue to have their priorities all wrong then they are welcome to their own private hell.
Yes, but unfortunately when they do occur they tend to be rather important; Eurocontrol's air-traffic flow management site, for example. If you need to file or change a flight-plan...
I upgraded to the latest Java r45 and it still didn't work. Then I noticed a blinking red thing in the address bar where the security lock icon goes. I clicked that and it gave me an option to enable Java for the VPN connection site permanently.
Seemed easy enough to fix. I only had to click that icon once, and it's been working smoothly since.
> A number of people have written me to ask about multi-key logins. I don't have any knowledge of or experience with these and my (very limited) investigation of the Network Connect service doesn't show how to do this from the command line. If someone can describe what the expected interface to the ncsvc program is for these situations I'll try to add support for it.
http://mad-scientist.us/juniper.html
At least that sounds like two-factor authentication he's talking about ("multi-key logins"). If it supported that I would definitely use it.
https://support.mozilla.org/en-US/kb/how-to-enable-java-if-i...
ScreenLeap has a good start: http://www.screenleap.com/troubleshooting-java
The advice they give varies based on the detected browser and OS (as it must) but it's somewhat out of date, and isn't intended for a general audience.
The applets on my educational site are signed JARs (a wasted expense, it seems), and they are explicitly run within the sandbox, but every few months it gets harder and harder for students and their parents to get Java to run.
And now in Firefox my interactive components have just become scary-looking blocks of DO-NOT-ENTER signs and warnings that are totally unwarranted for my site. If you work up the courage to click through the browser's warnings, then of course you get round 2, the warnings that the plugin itself pops up.
I dearly wish to see some of the details on the evil that's being done with Java applets, and if all of these aggressive measures are actually doing anything to stop real risks, or if the main effect is to kill sites like mine.
These do not seem to be actions based on data anymore.
https://mail.mozilla.org/pipermail/firefox-dev/2013-October/...
However, it is about time - I've heard online banking developers talk crap both about BankID and the underlying online banking infrastructure in the country, and security holes due to Java exploits are rampant. The banks have paid the bill for this until now, but it causes massive inconvenience for...every Norwegian who uses an online banking service. (Every adult Norwegian, more or less).
The problem isn't the extra click - two factor authentication with a one-time pad is an excellent extra security measure. The problem is that the implementation sucks and is riddled with security holes, prompting you to update Java every other time you log into your online bank account. This in addition to incredibly slow loading and also outright crashes if you are using a non-standard (i.e. not latest version of IE) browser. It is a giant, steaming pile of crappy software. We can't switch to a Javascript version fast enough.
(#) Except for those customers who have not yet been pushed into BankID, which is the selected standard for online banking. And obviously not for intra-bank and similar transactions.
- How can the Mozilla team can think they can get away with this ? This behavior is all but neutral from firefox!
- So I have to drop my software that I programmed in 7 years ? I went 4 days ago in the developper forum to discuss about this :
--------------------------------- Me: "A red no entry sign" is too radical for recent java player I think. My users give me a phone call to tell me "No way I will accept to install your software with this red warning"... Even the people who know me, tell me they got so scared they have really hesitated to accept java. Now I do understand at a time when java had urgent security issue this scary red-message was necessary. But I really wish that Firefox checks the java version installed ... and give a less-scary-warning-sign or a "go !" if the user has a recent java version (like the latest on java 1.7 update 30).
Benjamin Smedberg (chef of this idiot change): "We fundamentally disagree about the risks of the Java plugin. We believe the Java plugin is unsafe, and we want to present that to our users".
-- Is there a boss at Mozilla ? someone who cares about developpers. And yea Benjamin, you know, java is open source by the way. Fuck you idiot ! Thierry
Somehow, as a thank you, he decided to insult us.
sigh
But, given Flash's similar reputation (not to mention it being prone to crash), why not mark Flash as unsafe as well?
Now what we should use if we need more then HTML5? A) -> Silverlight ...FF promote a closed technology against the somehow open Java?? B) -> Flash ...which is on a downhill now? C) -> Java ...users need to be IT experts to enable it
One thing I would like to see: MS should ban FF because it is insecure :)
Any follow-up on that? FF is, to my belief at least, one of the more secure browsers.
So, for the moment, we have not taken the decision to disable Flash.
http://blog.chromium.org/2013/09/saying-goodbye-to-our-old-f...
Marking a current version as unsafe, even when there are no known exploits is simply ridiculous. I'd love to see the reaction of Mozilla if Microsoft decided to mark all Firefox releases as unsafe, and give a big security warning whenever you installed FF.
Especially if the UI for unblocking it in FF is as obtuse as the discussion implies..
The way to verify that the installer is legit, verifying the checksum, is not done by Windows, and must be done manually. Users don't do that, and flagging everything as unsafe is a good way of notifying the user that they must be careful.
Crying wolf all the time is a 100% guaranteed way of making sure nobody will ever care.
When I write Windows-software, I only signal that the process requires UAC elevation for the things which actually does so. It's possible. In fact it's rather easy.
I almost never encounter software which requires UAC elevation, just like most things in Linux doesn't require me to go full sudo.
At the moment, as Oracle refuses to fix security bugs timely, Java is permanently unsafe. Please be pissed off at Oracle for not protecting their users, not at Mozilla for doing it for them.
You want to program stuffs in the browser ? use javascript and html5 apis.
You want to do socket stuffs in the browser? use a proxy server.
But dont expose your users to exploits by making them install Java.
You want to build future proof solutions ? stop using applets because you cant learn javascript.
[1] about 25 FPS with random hiccups on my Core i7 Quad @ 2.4-3.5 GHz and proprietary NVidia drivers and Google Chrome
[2] https://semitwist.com/articles/article/view/quake-shows-java...
[3] about 100x slower than old Berkeley Spice (early 90s technology), despite much less accurate models and using similar algorithms (sparse LU decomposition + Newton Raphson)
All the heavy-handedness is going to do is force Firefox out of corporate IT environments where many internal websites rely on Java.
I hope there will be an about:config override for this. It seems like any time one of these browser authors does something "for security", it ends up being a perpetual pain in my ass and the ass of the users I support.
- How can the Mozilla team can think they can get away with this ? This behavior is all but neutral from firefox ?
- So I have to drop my software that I programmed in 7 years ? Benjamin Smedberg (the guy at mozilla who made this shit) is an extremist. I went 4 days ago in the developper forum to discuss about this :
--------------------------------- Me: "A red no entry sign" is too radical for recent java player I think. My users give me a phone call to tell me "No way I will accept to install your software with this red warning"... Even the people who know me, tell me they got so scared they have really hesitated to accept java. Now I do understand at a time when java had urgent security issue this scary red-message was necessary. But I really wish that Firefox checks the java version installed ... and give a less-scary-warning-sign or a "go !" if the user has a recent java version (like the latest on java 1.7 update 30).
Benjamin Smedberg: "We fundamentally disagree about the risks of the Java plugin. We believe the Java plugin is unsafe, and we want to present that to our users".
-- Is there a boss at Mozilla ? someone who cares about developpers. And yea Benjamin, you know, java is open source by the way. Fuck you idiot ! Thierry