Earlier quoted context omitted.
and they should definitely stop doing that. for me seeing Java on the client side is a sign of bad development.
Seeing browser-developers ignore the real world and just go ahead with their agendas unconcerned about how it affects the actual users of their browser is also a sign of bad development.
In Firefox 24 and following, mark all versions of Java as unsafe
51–60 of 184 posts
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#52Earlier quoted context omitted.
Depends on where you are in the world. Java is required for online banking in Norway, while it's mostly unused in Sweden, the neighbouring country. Both use Java for online verification to government sites.
and they should definitely stop doing that. for me seeing Java on the client side is a sign of bad development.
Exhibit A: healthcare.gov
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#53This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…
Still, many users [ http://geeksbynature.dk/2013/03/28/plugins-usage-distributio... ] have only Flash, Java and Windows Media plugins installed, maybe also Reader and Office. With Mozilla's efforts to replace Reader with pdf.js and Flash with Shumway (or HTML5), Java is a reasonable next target.
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#54Earlier quoted context omitted.
out of curiosity, who isn't on Gregorian calendar for everyday usage nowadays? The only thing I can think of is that for official documents Japan uses the emperor-year, but the months stay the same
Thailand isn't AFAIR. Look at the Thai Railways website ( http://www.railway.co.th/home/default.asp?lenguage=Eng ), you can book tickets until 21/12/2556 )
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#55Earlier quoted context omitted.
> flagging everything as unsafe is a good way of notifying the user that they must be careful Crying wolf all the time is a 100% guaranteed way of making sure nobody will ever care.
UAC? is that the window I always have to click 'Yes' on when I run a program? Yeah, could you disable that?
When I write Windows-software, I only signal that the process requires UAC elevation for the things which actually does so. It's possible. In fact it's rather easy.
I almost never encounter software which requires UAC elevation, just like most things in Linux doesn't require me to go full sudo.
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#56Earlier quoted context omitted.
Still, many users [ http://geeksbynature.dk/2013/03/28/plugins-usage-distributio... ] have only Flash, Java and Windows Media plugins installed, maybe also Reader and Office. With Mozilla's efforts to replace Reader with pdf.js and Flash with Shumway (or HTML5), Java is a reasonable next target.
Except it's not getting replaced, it's getting blocked and disabled. While lots of code deployed still depends on it. I hate Java applets as much as the next guy, but lets not ignore that there's a real world out there.
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#57I'm using Firefox in Ubuntu with Java to connect to a Juniper Networks VPN. When I upgraded to Ubuntu 13.10 a couple of days ago, the VPN launcher stopped working. I think Firefox 24 came along with the upgrade (that's the version running now). I upgraded to the latest Java r45 and it still didn't work. Then I noticed a blinking red thing in the address bar where the security lock icon goes. I clicked that and it gav…
You might also want to take a look at https://github.com/madscientist/msjnc . I found it a lot better than Juniper's manager for linux.
> A number of people have written me to ask about multi-key logins. I don't have any knowledge of or experience with these and my (very limited) investigation of the Network Connect service doesn't show how to do this from the command line. If someone can describe what the expected interface to the ncsvc program is for these situations I'll try to add support for it.
http://mad-scientist.us/juniper.html
At least that sounds like two-factor authentication he's talking about ("multi-key logins"). If it supported that I would definitely use it.
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#58You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1]
It's much less strict than in Chrome (on OS X), where Java doesn't run at all anymore.
[1] https://support.mozilla.org/en-US/kb/how-to-enable-java-if-i...
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#59Earlier quoted context omitted.
out of curiosity, who isn't on Gregorian calendar for everyday usage nowadays? The only thing I can think of is that for official documents Japan uses the emperor-year, but the months stay the same
Thailand isn't AFAIR. Look at the Thai Railways website ( http://www.railway.co.th/home/default.asp?lenguage=Eng ), you can book tickets until 21/12/2556 )
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#60I'm all for this being blocked by default, and the same goes for all plugins. But it certainly bothers me when they make it impossible to override their security constraints. Put in an about:config setting to allow Java, and it's fine. All the heavy-handedness is going to do is force Firefox out of corporate IT environments where many internal websites rely on Java.