Live data from Hacker News

Firefox 66.0.4 is out, fixes disabled add-ons

ftp.mozilla.org

331–340 of 392 posts

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#331

Earlier quoted context omitted.

I haven't Switched yet but I fired up my Vivaldi install and have been impressed. A lot of little annoyances that I got used to with the new extension restrictions aren't there because the functionality is built in (like mouse gestures and tabs on left). I first started using Firefox as my default when I unzipped a version of Phoenix off a CD which came with a computer magazine.

I installed Vivaldi, and moved shortly back to Firefox. The two things that did it: 1. I accidentally saved the wrong password to a site. When I went to fix it, it said I needed to login to my Google account to change my stored password. Wait, wat?! You are sending my passwords to Google, unencrypted, without telling me?! Thai is not acceptable, aside from - What else are you sending? 1b. I see that it saves non pass…

Vivaldi doesn't save passwords using Google. Did you perhaps click on a help link that sent you to a Google support page for Chrome?

I see that if you click the password icon the address bar and click the "Manage passwords" button it opens the default password settings page inherited from Chromium (vivaldi://settings/passwords) which includes a link to a support page for Google Chrome (https://support.google.com/chrome/?p=settings_password), but not all the information on that page is applicable to Vivaldi. In particular, Vivaldi doesn't use Google but rather its own account system for browser sync (which is optional, same as Firefox and Chrome).

That appears to be a bug, since that legacy Chromium password settings page isn't Vivaldi's normal password settings page (vivaldi://settings/privacy/). But it doesn't seem malicious.

Incidentally, the built-in password manager in Vivaldi (as well as in Chrome and other browsers based on Chromium) doesn't let you manually edit an existing password, whether or not you use an account to sync them. You can only update an entry by signing into a site with a new password and confirming the password change if the browser detects it, or deleting the old entry and saving a new one. A limitation compared to Firefox's password manager, though I do appreciate the native ability to generate random passwords in Chromium-based browsers. I hope Firefox and Chrome copy each other in those regards.

I haven't experienced any crashes with Vivaldi, though I don't use it as much as other browsers such as Firefox so perhaps I've just been luckier.

Vivaldi's background seems clear enough: https://en.wikipedia.org/wiki/Vivaldi_(web_browser)

It was founded by Norwegian developers who left the original Opera (either due to switch from the old Opera browser to the new interface, or because the company was sold to Chinese investors). I do wish they were more open with the source code, but anyone who was comfortable with using the original Opera back in the day should be okay with Vivaldi. More so than the current Opera, I think, which I still see many people using due to brand recognition I assume.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#332

Earlier quoted context omitted.

Why on earth are you running such a massively outdated browser? You should at least switch to pale moon, basilisk, or another maintained browser. God knows how many vulnerabilities in the wild there are in 56.

Is security the new motor powering the upgrade treadmill? God knows how many vulnerabilities there are in the massively outdated Windows 7, why don't you upgrade to Windows 10...

Win7 gets security updates until somewhere in 2020. After that point, anyone still using 7 will be better off upgrading to 8/8.1/10.

Firefox 56 is not an ESR. It does not get security patches. From a quick look, there are public CVEs[0] that allow for ROP code execution almost effortlessly.

Security was always one of the big reasons behind keeping browsers up to date (the other reason being propagating new standard faster).

Besides, I wasn’t suggesting updating to latest firefox. I specifically mentioned pale moon and basilisk because they support old style extensions, while hopefully keeping up with the security fixes and other improvements to the engine going in mainline.

[0] https://www.cvedetails.com/vulnerability-list/vendor_id-452/...

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#333
post #308

Earlier quoted context omitted.

I'm a privacy conscious person so I disabled all spyware that Firefox included. But I went to check, studies was enabled, probably because it was included and enabled by default in the last years and I didn't notice. So how long until Firefox adds something else to have remote code execution rights on my machine?

Studies do send telemetry which is not quite the same as being spyware. You can actually check what is sent, though there's no option to more finely disable studies requiring, say, cursor, keyboard or tab name monitoring. I haven't seen any such studies though. The "remote code execution" thing is already there, it is called JavaScript. Almost every browser has it. Add-ons use it all the time. As for browser code its…

>Studies do send telemetry which is not quite the same as being spyware.

How is software whose sole purpose is to send my information to a third party not spyware?

>The "remote code execution" thing is already there, it is called JavaScript. Almost every browser has it. Add-ons use it all the time.

JS on any webpage can't do whatever it wants, since it's restrained to the webpage itself. otoh I'm sure this "studies" thing can change my browser configuration (including my certificates, making me vulnerable to MITM) and probably even execute any command with my current user privileges.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#334

Earlier quoted context omitted.

Chromium is definitely worse. While these deserve an explanation, you should not wait to move. Chrome is spyware that does web browsing. It's parent company also shows ads, all the time. Chrome's auto update not only allows them to silently update or change your browser, it allows them to silently install other software on your computer. Firefox is a browser. It can auto-update in a way that may be questionable, but…

Chromium is not Chrome. It does not have auto-update. Surprisingly this gives more control by default than with Firefox.

I find it very disturbing that the very dangerous issue with Chrome and its family is not discussed here, which is the erosion of web standards.

tl;dr : Choosing anything based on Chromium is giving the death sentence to the Web "democracy"

Moving to a Chromium based browser is letting more and more market share to a browser engine whose roadmap is fully determined by Google. The issue trackers of Chromium or Android projects clearly shows how much Google values its users'feedback about their most wanted features : Not At All. These days it seems they are starting to feel the same about open standards... At first with WHATWG getting in the yard of W3C they tried to get more influence on the redaction of standards, now they don't even bother since they can force anything they want in a "de facto standard" as they are doing with AMP.

The next step is to obliterate any standardized feature they don't like. It can seems to be a frivolous issue but they are doing this right now to SVG-in-OpenType, a standard that is currently implemented in all major browsers except Chromium family (yes even Edge see https://www.colorfonts.wtf/#section4 but the switch to Chromium will probably end it). Here is what Google responds to the numerous people aking them to implement it : https://bugs.chromium.org/p/chromium/issues/detail?id=306078... Apparently a feature even the -probably small- team of Edge developers managed to implement is too complicated for Google chrome engineers ?!? This will get more and more frequent as long they have more than 80% of browser marketshares.

So if you switch to ANY Chromium based browser, even if it's for privacy reasons, PLEASE keep in mind that you are working for the destruction of the web "democracy".

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#335

Good move, congrats on surviving the second armag-add-on finally BUT I won't be moving from chromium until Firefox (or Mozilla) explains: - why am I opted-in to a Studies program in Firefox's default state? (With no explicit information about what it is) - what does app.normandy.enabled switch do and why is its default value is True and doesn't change to false when I explicitly state I don't want to be in the Studies…

Chromium is definitely worse. While these deserve an explanation, you should not wait to move. Chrome is spyware that does web browsing. It's parent company also shows ads, all the time. Chrome's auto update not only allows them to silently update or change your browser, it allows them to silently install other software on your computer. Firefox is a browser. It can auto-update in a way that may be questionable, but…

Google still pay for Firefox; about $2 per user. So, Chrome and Firefox are funded by the same people. In fact Google upped the money they're paying despite FF's falling users share, what are they getting for their money - I doubt they're giving it out of charity.

It's like price differentiation, I feel. FF is for people who want to avoid Google, but Google are paying to get privacy-infringement lite. Who knows what else besides being default search provider, and getting every search you type in through search suggestions, they're getting for their money?

>cranky devs looking over their shoulder to call them out years later because Mr. Robot may have been able to show them an ad //

Way to underplay things. Do Chrome change their UI (ie chrome) to ad advertising? Do they force add-ons on people that are unremovable in order to advertise a product? And then update, re-placing the advert into users chrome who've removed it? Do they blank out users home-screen settings in order to add advertising? (I think they did do that one?)

Chrome may be spyware, but default so is FF. And Mozilla have shown they're more than happy to mess around with their users browsers for advertising/promotions.

Aside: how is Chromium worse? Waterfox is looking like a good option.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#336
post #333

Earlier quoted context omitted.

Studies do send telemetry which is not quite the same as being spyware. You can actually check what is sent, though there's no option to more finely disable studies requiring, say, cursor, keyboard or tab name monitoring. I haven't seen any such studies though. The "remote code execution" thing is already there, it is called JavaScript. Almost every browser has it. Add-ons use it all the time. As for browser code its…

>Studies do send telemetry which is not quite the same as being spyware. How is software whose sole purpose is to send my information to a third party not spyware? >The "remote code execution" thing is already there, it is called JavaScript. Almost every browser has it. Add-ons use it all the time. JS on any webpage can't do whatever it wants, since it's restrained to the webpage itself. otoh I'm sure this "studies"…

They cannot, the studies use JS available to the browser though with internal APIs available. It is potent, but not quite as much as to allow running arbitrary executables outside the browser or usually bypass file system level protection. It can read and write files the user can access. (Which may or may not include /dev on *nix.) It can also exploit your OpenGL driver.

The difference between spyware and telemetry is intent - use of data - and anonymization measures.

If you don't trust the company making the browser with user studies (and their toggle), you probably shouldn't use their build - and you can disable study code completely on compile time.

If Mozilla decided to be evil like a certain Alphabet company, there is nothing to stop them but forking and writing another web browser.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#337

Earlier quoted context omitted.

Chromium is not Chrome. It does not have auto-update. Surprisingly this gives more control by default than with Firefox.

But Chromium still has most, if not all, the Google integration. There are forks that try to strip Google from it, but it is a mistake to assume that Chromium is somehow better than Chrome.

Firefox by default sends all your searches to Google, and uses Google search suggestions (so sends all typed in text to Google).

What other integrations, specifically please, does Chromium have with Google?

Aside: do Google serve the Firefox Newtab adverts, perhaps that "feature" was added for the extra money Firefox are getting from Google?

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#338

Earlier quoted context omitted.

Why on earth are you running such a massively outdated browser? You should at least switch to pale moon, basilisk, or another maintained browser. God knows how many vulnerabilities in the wild there are in 56.

Web devs might want to use older versions to test their site in them.

Considering that firefox gets upwards 70% of the users onto the latest version within 4 weeks or so of a new release, I don't see the point, doubt chrome is an issue for this as well, only reason I can see to support ancient browsers is if you have intranet web apps that only function is IE6-IE10 and you need to be able to run it there as well

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#339

Good move, congrats on surviving the second armag-add-on finally BUT I won't be moving from chromium until Firefox (or Mozilla) explains: - why am I opted-in to a Studies program in Firefox's default state? (With no explicit information about what it is) - what does app.normandy.enabled switch do and why is its default value is True and doesn't change to false when I explicitly state I don't want to be in the Studies…

Consider running Icecat. It's most convenient to use it by installing a fully libre distribution such as Parabola or Guix System. Distributions which respect the FSDG don't just exclude proprietary software, but actually take software like Firefox which is 99% libre, and chucks out the last 1% of junk, improving many defaults. You're unlikely to have ethical qualms with such an Icecat.

https://www.gnu.org/software/gnuzilla/ You can see how it's made here: https://git.savannah.gnu.org/cgit/gnuzilla.git/tree/makeicec...

Note that it looks like it disables sync, but that should still work, and you can add whatever addons you like.

Re: Firefox 66.0.4 is out, fixes disabled add-ons

#340
post #129

Earlier quoted context omitted.

I've seen people expecting such a switch since... Firefox 6 or so? I wouldn't hold my breath.

Edge's switch to Chromium was a bit surprising, even if it makes complete sense to do so on both the browser and OS level. At this point, I'm not sure if Mozilla's involvement with the Chromium project would be such a bad thing. In regards to web standards and freedom, having Google, Microsoft and Mozilla having their hand in that pot doesn't seem a lot different from each maintaining their own.

It would be a terrible loss to us all if Mozilla made Firefox chromium based, since it would mean Google basically controls the internet via Chromium

EDIT: also Mozilla putting more and more rust code into Firefox is great for memory safety which is something that is a cause of many security issues these days

Post reply on HN