Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

21–30 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#21
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

Still, many users [http://geeksbynature.dk/2013/03/28/plugins-usage-distributio...] have only Flash, Java and Windows Media plugins installed, maybe also Reader and Office. With Mozilla's efforts to replace Reader with pdf.js and Flash with Shumway (or HTML5), Java is a reasonable next target.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#22
post #13

Earlier quoted context omitted.

> This will have a pretty bad effect on Firefox's market-share if it goes live. It's already live. ff24 is the current stable.

Oh interesting - hard to keep track of which version Firefox is up to these days. They should really swap to a system like Ubuntu's - using the date for the version number. It was released over a month ago too. Has it had any effect on Firefox's market-share? Especially in enterprise? It's a pretty decent test bed for understanding how users react to these kinds of changes. If they just accept them and adapt when for…

That would (and probably does, with Ubuntu) annoy people who don't use the Gregorian calendar.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#23
post #13

Earlier quoted context omitted.

> This will have a pretty bad effect on Firefox's market-share if it goes live. It's already live. ff24 is the current stable.

Oh interesting - hard to keep track of which version Firefox is up to these days. They should really swap to a system like Ubuntu's - using the date for the version number. It was released over a month ago too. Has it had any effect on Firefox's market-share? Especially in enterprise? It's a pretty decent test bed for understanding how users react to these kinds of changes. If they just accept them and adapt when for…

> It was released over a month ago too. Has it had any effect on Firefox's market-share?

No, the change went live Friday: https://bugzilla.mozilla.org/show_bug.cgi?id=914690#c20

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#24
post #17
post #9

Earlier quoted context omitted.

Will it? I've been browsing without Java for years, and I can only remember problems with one site (some hilarious throwback from the late 90s). For general browsing, I doubt anyone will notice a difference. Maybe for corporate use, but isn't that mostly IE anyway?

Depends on where you are in the world. Java is required for online banking in Norway, while it's mostly unused in Sweden, the neighbouring country. Both use Java for online verification to government sites.

and they should definitely stop doing that. for me seeing Java on the client side is a sign of bad development.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#25
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

I doubt it. Apart from the odd algorithm demonstration I haven't found a need to enable Java in my browser for the past 10 years.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#26
post #25
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

I doubt it. Apart from the odd algorithm demonstration I haven't found a need to enable Java in my browser for the past 10 years.

Sure, and I haven't used Internet Explorer in years. That doesn't mean that suddenly disabling Internet Explorer is going to have no effect even if I (and probably most of us here on HN) would not even notice.

A lot of corporates and financial applications require Java.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#27
post #13

Earlier quoted context omitted.

Oh interesting - hard to keep track of which version Firefox is up to these days. They should really swap to a system like Ubuntu's - using the date for the version number. It was released over a month ago too. Has it had any effect on Firefox's market-share? Especially in enterprise? It's a pretty decent test bed for understanding how users react to these kinds of changes. If they just accept them and adapt when for…

That would (and probably does, with Ubuntu) annoy people who don't use the Gregorian calendar.

out of curiosity, who isn't on Gregorian calendar for everyday usage nowadays? The only thing I can think of is that for official documents Japan uses the emperor-year, but the months stay the same

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#28
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

> This will have a pretty bad effect on Firefox's market-share if it goes live. It's already live. ff24 is the current stable.

Confirmed. It broke my SO's ability to do online banking yesterday and I was (as usual) called in as tech support.

I just assumed Java was out of date (again) and was surprised to see it still blacklisted after updating to latest version.

There's no part of the UI saying "We've permanently blocked all of Java by default". Even if you agree with the developer's ideological stance here (which you very well may not), the UX part of the job is completely botched.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#29
Wow, this is really irresponsible behavior, I would've expected something better from Mozilla.. Until now they've first offered an alternative (e.g. pdf.js) before trying to move away from a tech.

Marking a current version as unsafe, even when there are no known exploits is simply ridiculous. I'd love to see the reaction of Mozilla if Microsoft decided to mark all Firefox releases as unsafe, and give a big security warning whenever you installed FF.

Especially if the UI for unblocking it in FF is as obtuse as the discussion implies..

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#30
post #17

Earlier quoted context omitted.

Depends on where you are in the world. Java is required for online banking in Norway, while it's mostly unused in Sweden, the neighbouring country. Both use Java for online verification to government sites.

and they should definitely stop doing that. for me seeing Java on the client side is a sign of bad development.

They will. It was announced earlier this year that the Norwegian banks will move over to a HTML5/js authentication. The government identification has been the same as the banks, so that too will disappear.
Post reply on HN