Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

91–100 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#91

A lot of the angry comments about this seem to be coming from uninformed people who haven't actually tried it - that or something about this change isn't actually rolled out. I just tried it in an up-to-date version of Firefox 24, along with Firefox Nightly. In both, with my existing old build of Java, I got a placeholder image like this: https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn... Clicking it too…

The applet loading without user action after the Java update sounds like you had already allowed it for that site before (or maybe you haven't got the blocklist update yet for some reason?).

What you are seeing on Firefox 26+ is all plugins except Flash becoming click-to-play by default: https://blog.mozilla.org/futurereleases/2013/09/24/plugin-ac...

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#92
post #41

Earlier quoted context omitted.

So you think perpetuating the use of Java in the browser is a reasonable response to the security risks it presents to those corporates? This action by Mozilla raises awareness of the fact that Java security updates are too slow and too opaque and it's time to change to something else.

This action by Mozilla raises awareness of the fact that Java security updates are too slow and too opaque and it's time to change to something else. It also raises awareness of the fact that you can't trust some of the big names in the browser industry not to break stuff every few weeks just because they don't like it and then push the changes on you whether you want them or not. Introducing restrictions so tight th…

If you need control over the version and features of the browser your employees use then disable automatic updating and use a management tool instead.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#93
post #50

Earlier quoted context omitted.

Confirmed. It broke my SO's ability to do online banking yesterday and I was (as usual) called in as tech support. I just assumed Java was out of date (again) and was surprised to see it still blacklisted after updating to latest version. There's no part of the UI saying "We've permanently blocked all of Java by default". Even if you agree with the developer's ideological stance here (which you very well may not), th…

There should be a "plugin" icon in the address bar, showing you that java has been blocked (see https://news.ycombinator.com/item?id=6590650 ) Pressing on that icon should allow you to run java once, or allow if forever for that site. If the icon doesn't appear, I think you should file a bug on bugzilla.

You know those big, yellow bars that browser and websites tends to come up with when they want to be 100% certain that the user notices something is up?

I've yet to see a single non-technical user even notice or react to its presence once. I see it instantly and can't understand why it doesn't alert or annoy them, but to them, it's just not there.

In light of that sort of behaviour, adding a subtle icon to the location bar is meaningless. Heck, adding anything to the location bar is meaningless if the intent is to communicate with the user; most users never look there.

So yeah. If that's Mozilla's stance, they will find out that nobody's going to notice. I certainly didn't see it. That is effectively dead code which they've written.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#94
post #46

Earlier quoted context omitted.

Why? Java applets are extremely rare these days.

If you're 20-something doing "the startup game" you probably don't see it on the next cool site demos. If you support the company where most of the users just know to click and login, and one day they just can't, you aren't going to like it, to quote one of the post from the bugzilla: "I haven't been able to get VPN-ed in for days, until I figured I could still use the Juniper SSL VPN from Internet Explorer. I find i…

This has to be balanced against the extreme risk of turning on java for every site out there.

A few users are inconvenienced. That few being the intersection of those who rely on java applets for something they care about (already a tiny fraction) and those who lack the knowledge to solve the problem on their own (an even smaller fraction). Even losing that fraction of users is unlikely to affect firefox's marketshare to any significant degree.

In the context of a company's IT department, they should be competent enough to know how to set default browser configurations and to provide walk-through documentation. If an IT department thinks that user convenience is a good enough excuse to expose the company's employees to some of the most serious and hard to prevent web-based exploits out there then I say fuck 'em. They have their priorities all wrong and if they want to continue to have their priorities all wrong then they are welcome to their own private hell.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#95
post #64

Earlier quoted context omitted.

Most of Java is open-source now. I wonder why the dependence on Oracle is so high. If Apache or a similar foundation would fork(+) and adopt it, it will benefit the Java eco-system tremendously. + Fork if legally required.

Apache did try to fork it with Harmony ( http://harmony.apache.org/ ), but Sun pulled every trick in the book to keep people from contributing and/or adopting it. Then again, the code is still extant, could be time to pull it out of the attic.

Indeed, but the situation has changed now. Sun, just before it got acquired by Oracle, had open sourced the last remaining puzzle: the Java compatibility test suite. Which allows anyone to run the test suite, claim and validate that their software is conformant with Java.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#96

A lot of the angry comments about this seem to be coming from uninformed people who haven't actually tried it - that or something about this change isn't actually rolled out. I just tried it in an up-to-date version of Firefox 24, along with Firefox Nightly. In both, with my existing old build of Java, I got a placeholder image like this: https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn... Clicking it too…

> In both, with my existing old build of Java, I got a placeholder image like this:

> https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn...

The problem is that this dialog box is outright lying. It will show that placeholder even with the latest version of Java installed.

Firefox is open source software. Open source software should be trustworthy. Software which lies to you is by definition not.

As things stand here, right now, it's Firefox which has a problem.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#97

A lot of the angry comments about this seem to be coming from uninformed people who haven't actually tried it - that or something about this change isn't actually rolled out. I just tried it in an up-to-date version of Firefox 24, along with Firefox Nightly. In both, with my existing old build of Java, I got a placeholder image like this: https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn... Clicking it too…

> In both, with my existing old build of Java, I got a placeholder image like this: > https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn... The problem is that this dialog box is outright lying . It will show that placeholder even with the latest version of Java installed. Firefox is open source software. Open source software should be trustworthy. Software which lies to you is by definition not. As things…

It will show a different placeholder with the latest Java (no update link & text): http://imgur.com/k94vEvB

Given Javas security history, this seems correct.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#98
post #70

Earlier quoted context omitted.

Are those actually users, or developers/testers who run test suits on their products and noticed a change?

They are actually users, and those users paid a very large amount of money for very expensive equipment that happens to use Java applets as part of its remote management interface.

Did any of that money go to Mozilla or any other organization seeking to advance and secure the internet for the vast majority of people who did not waste money on overpriced products from a company that doesn't want to take responsibility for its poor judgement and inflexibility?

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#99

A lot of the angry comments about this seem to be coming from uninformed people who haven't actually tried it - that or something about this change isn't actually rolled out. I just tried it in an up-to-date version of Firefox 24, along with Firefox Nightly. In both, with my existing old build of Java, I got a placeholder image like this: https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn... Clicking it too…

> In both, with my existing old build of Java, I got a placeholder image like this: > https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn... The problem is that this dialog box is outright lying . It will show that placeholder even with the latest version of Java installed. Firefox is open source software. Open source software should be trustworthy. Software which lies to you is by definition not. As things…

I just want to confirm 'gfritzsche' in you being wrong, and ranting about a lot of stuff that is just wrong. You should delete your comment.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#100

Earlier quoted context omitted.

> You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1] Allow me to disagree and to tell you what happened last weekend: Last Sunday I had a call from my stepfather who "couldn't run the website to order agro food" anymore. This website runs a Java applet to manage agro food orders on-line and the code isn't signed (it's a…

This is clearly a person who would have wound up with malware regardless. It's as if you blamed telephones for allowing a scammer to call a gullible mark from the Official Credit Card Office.

He wouldn't have ended up on treacherous paths if that warning had been more explicit about what was going on.

I agree he's not computer savy but I am not blaming Mozilla for his installing malware. I am blaming Mozilla for a confusing message about security. See https://news.ycombinator.com/item?id=6590686

Post reply on HN