Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

81–90 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#81

Earlier quoted context omitted.

Their PDF replacement is far from good - buggy and unusable. We have to show PDF documents to our customers directly in browser, so we need good UX, and it was disappointing to see how it works in FF compared to other browsers with Reader and how much effort do we need to fix it. I'm not surprised they screwed up with Java too.

It's disappointing that comments like the parent are getting downvoted here. Objective, factual observations should be encouraged, not censored. The Reader "replacement" PDF viewer in Firefox is limited and buggy compared to the real thing. We also found it literally unusable for our purposes when it launched, and we routinely disable it on new installations where we still use Firefox at all (which is basically only…

It's an early version, and for many uses it's more stable and less intrusive than Reader.

I have avoided Reader for years by using Safari, and later Chrome, which each have their own built in PDF renderers. I'm glad that Firefox has caught up, it's one of the things that has kept me from using Firefox. I read a lot of PDFs, and loading the big, slow, clunky Reader plugin, or downloading the PDF, is a non-starter.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#84
post #46

Earlier quoted context omitted.

Why? Java applets are extremely rare these days.

If you're 20-something doing "the startup game" you probably don't see it on the next cool site demos. If you support the company where most of the users just know to click and login, and one day they just can't, you aren't going to like it, to quote one of the post from the bugzilla: "I haven't been able to get VPN-ed in for days, until I figured I could still use the Juniper SSL VPN from Internet Explorer. I find i…

Well, the reality goes forward and the customers that doesn't know how to fix this will probably be mad at the vendor for good reasons. They still use old, crappy software and it'time for an update since it will no longer work in modern browsers.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#85

Earlier quoted context omitted.

> You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1] Allow me to disagree and to tell you what happened last weekend: Last Sunday I had a call from my stepfather who "couldn't run the website to order agro food" anymore. This website runs a Java applet to manage agro food orders on-line and the code isn't signed (it's a…

Java actually installs malware (the Ask toolbar) unless you are careful enough to deselect it during the installation/update process.

There was a bunch of other crap: a lollipop promotion app, a trojan and internet explorer settings changed.

Funny, but he didn't installed the Ask toolbar :). I did when uninstalling/reinstalling Java and clicking a little bit too fast :). Hopefully it's not as tedious to remove as a trojan.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#86
A lot of the angry comments about this seem to be coming from uninformed people who haven't actually tried it - that or something about this change isn't actually rolled out. I just tried it in an up-to-date version of Firefox 24, along with Firefox Nightly.

In both, with my existing old build of Java, I got a placeholder image like this:

https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn...

Clicking it took me to the update page. Exactly what you want. There was an option in the top-left corner to forcibly load it, which is fine - updating is the right move.

Once I updated and uninstalled the old JRE, in Firefox 24 the applet I was trying loaded silently without any confirmation. It was not blacklisted.

In Firefox Nightly, once Java is updated, I see this placeholder where the applet would have been:

https://dl.dropboxusercontent.com/u/1643240/activate_java.pn...

Clicking the placeholder opens a prompt asking if I want to allow the plugin once or allow it always on this site. Very straightforward.

Other than the fact that modern Java 7 is not blocked by default in Firefox 24 for me (maybe they didn't roll that out yet?), everything works fine here, and I don't see any catastrophic UI mistakes, developer/enterprise-hostile design, or attempts at destroying the web.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#87
post #16

The sooner Java moves away from Oracle, the better for everyone. That being said, there is rarely a need to run Java from a browser, aside from the odd game. But, given Flash's similar reputation (not to mention it being prone to crash), why not mark Flash as unsafe as well?

Juniper VPN is evil, broken, uses Java, and extremely common. And that's just one example of a common Java plugin.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#88
post #46

Earlier quoted context omitted.

Why? Java applets are extremely rare these days.

If you're 20-something doing "the startup game" you probably don't see it on the next cool site demos. If you support the company where most of the users just know to click and login, and one day they just can't, you aren't going to like it, to quote one of the post from the bugzilla: "I haven't been able to get VPN-ed in for days, until I figured I could still use the Juniper SSL VPN from Internet Explorer. I find i…

I think they should have just made their click-to-play UI a bit more obvious and easy to understand. It would have stopped a lot of these complaints.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#89

A lot of the commenters here seem to misunderstand this change. You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1] It's much less strict than in Chrome (on OS X), where Java doesn't run at all anymore. [1] https://support.mozilla.org/en-US/kb/how-to-enable-java-if-i...

> You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1] Allow me to disagree and to tell you what happened last weekend: Last Sunday I had a call from my stepfather who "couldn't run the website to order agro food" anymore. This website runs a Java applet to manage agro food orders on-line and the code isn't signed (it's a…

This is clearly a person who would have wound up with malware regardless. It's as if you blamed telephones for allowing a scammer to call a gullible mark from the Official Credit Card Office.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#90
post #64
post #56

Earlier quoted context omitted.

The real world would be nicer if Oracle actually worked on fixing Java security issues. They have a bad history of pretending that security holes have been fixed and/or pretending that they do not exist, while exploits run rampant.

Most of Java is open-source now. I wonder why the dependence on Oracle is so high. If Apache or a similar foundation would fork(+) and adopt it, it will benefit the Java eco-system tremendously. + Fork if legally required.

Mozilla working on the web platform has more impact. The sites that still rely on a Java plugin were expecting binary compatibility and a big vendor's security support because that sounds cheapest long term, now that it doesn't happen, heads in the sand or a web port are a lot more likely than forking Java.
Post reply on HN