Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

121–130 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#121

Wow, this is really irresponsible behavior, I would've expected something better from Mozilla.. Until now they've first offered an alternative (e.g. pdf.js) before trying to move away from a tech. Marking a current version as unsafe, even when there are no known exploits is simply ridiculous. I'd love to see the reaction of Mozilla if Microsoft decided to mark all Firefox releases as unsafe, and give a big security w…

Have you read the linked page?

At the moment, as Oracle refuses to fix security bugs timely, Java is permanently unsafe. Please be pissed off at Oracle for not protecting their users, not at Mozilla for doing it for them.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#122

I have reported this big issue forme in the developper forum last week. All java version, even recent ones, ALL are considered, (not like flash...) as a "permanent unsecure virus" by Firefox. - How can the Mozilla team can think they can get away with this ? This behavior is all but neutral from firefox! - So I have to drop my software that I programmed in 7 years ? I went 4 days ago in the developper forum to discus…

This is HN, mind your language please.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#123

Earlier quoted context omitted.

> your obvious trolling You're not helping your case at all. Accept responsibility for supporting your customers, and stop lashing out at others for not doing it for you.

We are supporting our users. The point is that in this case we shouldn't have to. The problem is an entirely artificial one of Mozilla's creation, and no support from anyone should ever have been necessary.

The problem is entirely of Oracle's and your own creation. Oracle is not adequately supporting their software, and you have failed to notice the signs over the past several years that browsers were headed in exactly this direction and adapt accordingly.

Mozilla is taking the only responsible course to protect the vast majority of their users. It's been a long time coming, and absolutely no one should be surprised that it finally arrived. If anything, I'm surprised it took this for the first major browser to do it.

More will follow. Adapt or die.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#124

Earlier quoted context omitted.

He wouldn't have ended up on treacherous paths if that warning had been more explicit about what was going on. I agree he's not computer savy but I am not blaming Mozilla for his installing malware. I am blaming Mozilla for a confusing message about security. See https://news.ycombinator.com/item?id=6590686

There are thousands of "confusing" messages to be found on a typical computer. The messages Firefox presents for Java[1][2][3] aren't even competitive. You have a user who has not been trained to not install random software, is fooled by extremely common ads, and who does not have the basic judgement necessary to not flail about when presented with something they don't understand but to consult someone who will under…

edit: here I should replace firefox and mozilla with oracle

That's quite a stretch.

I have a user who uses frequently one specific website and for no apparent reason Firefox decides to tell him it's now dangerous to use with fearful and technological terms (vulnerabilities, plug-in, risk, etc.).

If Mozilla decides its users are dumb and should not be trusted to allow Java applet to be run then they should not warn them with techno-cryptic messages they know their users can't understand (because if Mozilla thought they could then Mozilla would know users could make the difference between a good and a bad applet and that warning wouldn't be needed).

A shorter and less scarier note would have been a better message for everyone.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#125
post #122

I have reported this big issue forme in the developper forum last week. All java version, even recent ones, ALL are considered, (not like flash...) as a "permanent unsecure virus" by Firefox. - How can the Mozilla team can think they can get away with this ? This behavior is all but neutral from firefox! - So I have to drop my software that I programmed in 7 years ? I went 4 days ago in the developper forum to discus…

This is HN, mind your language please.

It's a copy of one of the comments on the link. It should have been in quotes at a minimum.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#126
post #119

Earlier quoted context omitted.

There are thousands of "confusing" messages to be found on a typical computer. The messages Firefox presents for Java[1][2][3] aren't even competitive. You have a user who has not been trained to not install random software, is fooled by extremely common ads, and who does not have the basic judgement necessary to not flail about when presented with something they don't understand but to consult someone who will under…

While I agree with your opening sentiment, and I agree regarding OP's dad not having the appropriate training and judgement, I disagree with the conclusion that he should be the resolution to that problem. The appropriate training is nothing less than years of experience working with computers or being in the IT business. Why do we believe that this ought to be standard knowledge for users? It seems to me that we're…

The appropriate training has been given by me to the various family members I have to support. They started out just like his stepfather. It did not require them to have years of experience before they stopped trusting random websites, installing whatever came across their screen. It required me explaining the relevant concepts a few times. That was it.

We absolutely place too much burden on end-users -- one reason the iPad is such a hit -- but "don't believe everything you read on the Internet" and "ask me before you try to fix something you don't really understand" is not a heavy burden. If it were, we'd have a lot more mechanics and a lot fewer operable cars on the road.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#127
post #83

If Java is whole source of vulnerabilities, how it's working well in servers?

Most of the vulnerabilities in Java that effect browsers are not relevant when Java is used in other contexts, rather than embedded in a browser.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#128

Earlier quoted context omitted.

Yeah, it's true that lot of the sites still using Java hasn't been updated with the correct instructions about how to enable it in FF 24 yet - and they should fix that as soon as possible of course. Still, it's a much easier thing for normal users to figure out than how to update Java (which they must do quite regularly to get Java to run at all). I did a little Googling and it turns out that Java still runs in Chrom…

Yeah, it's true that lot of the sites still using Java hasn't been updated with the correct instructions about how to enable it in FF 24 yet - and they should fix that as soon as possible of course. Unfortunately, the applets I work on at the moment run on embedded web servers in network-enabled devices. You can't just roll out a quick update to this software every time Mozilla or Oracle break things.

If you were deploying web servers on embedded devices without planning for easy and painless upgrades, joke's on you. That's terrible for your client's security.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#129
post #95

Earlier quoted context omitted.

Apache did try to fork it with Harmony ( http://harmony.apache.org/ ), but Sun pulled every trick in the book to keep people from contributing and/or adopting it. Then again, the code is still extant, could be time to pull it out of the attic.

Indeed, but the situation has changed now. Sun, just before it got acquired by Oracle, had open sourced the last remaining puzzle: the Java compatibility test suite. Which allows anyone to run the test suite, claim and validate that their software is conformant with Java.

Not quite. You have to have your code "substantially based" upon OpenJDK, and be GPLed, in order to use their validation suite. So Harmony still would not be able to use their validation suite.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#130

Earlier quoted context omitted.

There are thousands of "confusing" messages to be found on a typical computer. The messages Firefox presents for Java[1][2][3] aren't even competitive. You have a user who has not been trained to not install random software, is fooled by extremely common ads, and who does not have the basic judgement necessary to not flail about when presented with something they don't understand but to consult someone who will under…

edit: here I should replace firefox and mozilla with oracle That's quite a stretch. I have a user who uses frequently one specific website and for no apparent reason Firefox decides to tell him it's now dangerous to use with fearful and technological terms (vulnerabilities, plug-in, risk, etc.). If Mozilla decides its users are dumb and should not be trusted to allow Java applet to be run then they should not warn th…

The warnings are 8-14 and 5-8 words respectively, and state the case concisely. The word "risk" appears nowhere, and is a common English word anyway, and "vulnerable" and its derivatives are also common English words.

How would you rephrase the warning in fewer than 8 words that would have helped your stepfather understand the problem and how to deal with it?

Post reply on HN