Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

31–40 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#31
post #17

Earlier quoted context omitted.

Depends on where you are in the world. Java is required for online banking in Norway, while it's mostly unused in Sweden, the neighbouring country. Both use Java for online verification to government sites.

and they should definitely stop doing that. for me seeing Java on the client side is a sign of bad development.

Seeing browser-developers ignore the real world and just go ahead with their agendas unconcerned about how it affects the actual users of their browser is also a sign of bad development.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#32
post #27

Earlier quoted context omitted.

That would (and probably does, with Ubuntu) annoy people who don't use the Gregorian calendar.

out of curiosity, who isn't on Gregorian calendar for everyday usage nowadays? The only thing I can think of is that for official documents Japan uses the emperor-year, but the months stay the same

Thailand isn't AFAIR. Look at the Thai Railways website ( http://www.railway.co.th/home/default.asp?lenguage=Eng ), you can book tickets until 21/12/2556 )

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#33
post #9
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

Will it? I've been browsing without Java for years, and I can only remember problems with one site (some hilarious throwback from the late 90s). For general browsing, I doubt anyone will notice a difference. Maybe for corporate use, but isn't that mostly IE anyway?

I believe apps like Google hangouts use Java/Need Java enabled.

I think the commenter shiloh.enriquez on that Mozilla thread had a decent point in that many users just want the thing to work, won't necessarily understand or have the patience to understand and will move from FF to Chrome or IE.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#34
I'm all for this being blocked by default, and the same goes for all plugins. But it certainly bothers me when they make it impossible to override their security constraints. Put in an about:config setting to allow Java, and it's fine.

All the heavy-handedness is going to do is force Firefox out of corporate IT environments where many internal websites rely on Java.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#35

Wow, this is really irresponsible behavior, I would've expected something better from Mozilla.. Until now they've first offered an alternative (e.g. pdf.js) before trying to move away from a tech. Marking a current version as unsafe, even when there are no known exploits is simply ridiculous. I'd love to see the reaction of Mozilla if Microsoft decided to mark all Firefox releases as unsafe, and give a big security w…

Well, when you download the .exe file in IE, you do get a warning that it might be unsafe from Windows. And you need to verify that you want to install it.

The way to verify that the installer is legit, verifying the checksum, is not done by Windows, and must be done manually. Users don't do that, and flagging everything as unsafe is a good way of notifying the user that they must be careful.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#36
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

Still, many users [ http://geeksbynature.dk/2013/03/28/plugins-usage-distributio... ] have only Flash, Java and Windows Media plugins installed, maybe also Reader and Office. With Mozilla's efforts to replace Reader with pdf.js and Flash with Shumway (or HTML5), Java is a reasonable next target.

Except it's not getting replaced, it's getting blocked and disabled. While lots of code deployed still depends on it.

I hate Java applets as much as the next guy, but lets not ignore that there's a real world out there.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#37
post #9

Earlier quoted context omitted.

Will it? I've been browsing without Java for years, and I can only remember problems with one site (some hilarious throwback from the late 90s). For general browsing, I doubt anyone will notice a difference. Maybe for corporate use, but isn't that mostly IE anyway?

I believe apps like Google hangouts use Java/Need Java enabled. I think the commenter shiloh.enriquez on that Mozilla thread had a decent point in that many users just want the thing to work, won't necessarily understand or have the patience to understand and will move from FF to Chrome or IE.

Google Hangouts is a plugin of its own, it does not use or depend on Java.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#39
post #2

Great news, I'm always paranoid about java plugin. Now I can relax a little bit.

You were able to disable java in your browser with one click also before ...in my opinion, this move from FF is a very bad one. Now what we should use if we need more then HTML5? A) -> Silverlight ...FF promote a closed technology against the somehow open Java?? B) -> Flash ...which is on a downhill now? C) -> Java ...users need to be IT experts to enable it One thing I would like to see: MS should ban FF because it…

Change is to disable java by default. User can enable it for one page but can't enable it globally for every page. I like that because it close to things like flashblock.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#40
post #2

Great news, I'm always paranoid about java plugin. Now I can relax a little bit.

You were able to disable java in your browser with one click also before ...in my opinion, this move from FF is a very bad one. Now what we should use if we need more then HTML5? A) -> Silverlight ...FF promote a closed technology against the somehow open Java?? B) -> Flash ...which is on a downhill now? C) -> Java ...users need to be IT experts to enable it One thing I would like to see: MS should ban FF because it…

> One thing I would like to see: MS should ban FF because it is insecure :)

Any follow-up on that? FF is, to my belief at least, one of the more secure browsers.

Post reply on HN