Live data from Hacker News

Firefox 36.0 released

mozilla.org

21–30 of 256 posts

Re: Firefox 36.0 released

#21
> No longer accept insecure RC4 ciphers whenever possible

What do they mean with "whenever possible"? If there is a downgrade attack ongoing, will it be possible to avoid RC4?

Re: Firefox 36.0 released

#22

Yay! Time for another firefox rant. I love the idea of firefox and I used to love it a lot. But not now. I keep trying it and always go back to chrome. It crashes. A lot. Like, at least once a day I have to ctrl+alt+del and restart it on my laptop. It freezes and the window stops responding, it doesn't even paint. In the inspector, the DOM breadcrumb area scrolls and moves around. It's like the blink tag, only worse.…

Your bugs are probably in extensions and not Firefox proper. Try starting in "safe mode" by just holding the Shift key while FF is launching. If it's still a problem, try asking in #firefox on irc.mozilla.org. They're great at helping users troubleshoot, and they'll help you file a bug report if it comes to that.

Re: Firefox 36.0 released

#23
post #10

Earlier quoted context omitted.

Adding multi-process to a large project that was not designed for multi-process is an astronomical amount of work. And Firefox's approach has advantages over Chrome's, so they're not simply playing catch-up.

Understood, but I'm speaking from the viewpoint of a user, here. It's a massive annoyance for a crashed tab to annihilate the other 49. (And the session restore being activated is generally grounds for a smoke break, because your system will be tied up for a while...)

Since 38a (previous nightly) electrolysis e10s is enable by defualt IIRC. That's the main reason I favor Firefox instead of Chromium these days, since I'd love to provide them with automatic user feedback as much as possible. Multithreading isolates from crashes half the time, but some times everything will go down. Also there seem to be concurrent issues and threading overhead, for mundane page loading can become very very sluggish.

Re: Firefox 36.0 released

#24

While it's nice to see the progress being made here, it's a little bit.. what's the word here? Strange? Disheartening? Annoying? Infuriating? ..to see long-standing issues being ignored or back-burnered in the march to add all the new features. Duplicate SSL certs still cause sites to be unviewable without stupid and security-breaking workarounds that are not necessary in other browsers, for nearly 7 years now[1], ma…

For the curious, the duplicate SSL cert issue is in regards to some buggy routers and wireless printers with broken firmware. They send out invalid SSL certificates. Firefox doesn't have a way to provide an exception to allow access when security is compromised in this way but the user doesn't care and wants to access it anyway.

The only reason tabs generally misbehave is if Flash crashes. Firefox separates Flash out to a separate process so it won't crash the browser, even the tab the crashed Flash plugin is in. It just takes it a few more seconds than I'd like to realize the crash. (You can adjust the timing yourself, though). I haven't had a non-Flash-related Firefox issue in a very long time.

Re: Firefox 36.0 released

#25
post #10

While it's nice to see the progress being made here, it's a little bit.. what's the word here? Strange? Disheartening? Annoying? Infuriating? ..to see long-standing issues being ignored or back-burnered in the march to add all the new features. Duplicate SSL certs still cause sites to be unviewable without stupid and security-breaking workarounds that are not necessary in other browsers, for nearly 7 years now[1], ma…

Adding multi-process to a large project that was not designed for multi-process is an astronomical amount of work. And Firefox's approach has advantages over Chrome's, so they're not simply playing catch-up.

Even Internet Explorer has been multi-process since IE8. All other browsers do it, except Firefox.

Re: Firefox 36.0 released

#26

Earlier quoted context omitted.

It's just that chrome devtools are really, really well made in many dimensions. But keep in mind that Mozilla has been catching up a lot (impressive knowing the budget difference) both in devtools and under the hood (memory usage).

Don't forget about FireBug which is pretty awesome.

I heard it was an unmaintanable mess, that's why Mozilla added in-house devtools. I liked FireBug UX more, but I like that Firefox has metalevel coding/debugging capabilities out of the box (the smalltalk fan speaking).

Re: Firefox 36.0 released

#27
post #17

Earlier quoted context omitted.

Yeah, the full HTTP/2 support was a pleasant surprise! Wonder if Google's (and other prominent ones) web properties have switched over to HTTP/2 from SPDY yet.

Using FirefoxDevEdition with SPDY indicator shows me Google, Youtube and Twitter over HTTP/2.

[deleted]

Re: Firefox 36.0 released

#28
post #10

Earlier quoted context omitted.

Adding multi-process to a large project that was not designed for multi-process is an astronomical amount of work. And Firefox's approach has advantages over Chrome's, so they're not simply playing catch-up.

Understood, but I'm speaking from the viewpoint of a user, here. It's a massive annoyance for a crashed tab to annihilate the other 49. (And the session restore being activated is generally grounds for a smoke break, because your system will be tied up for a while...)

Session restore in Firefox has been lazy for a long time now (the tab only loads when you activate it). It doesn't take longer than loading a single page.

How often do tabs crash for you? That's the real issue if you ask me. I'm on Nightly (with Electrolysis!) and the last crash was over 2 months ago.

Re: Firefox 36.0 released

#29

While it's nice to see the progress being made here, it's a little bit.. what's the word here? Strange? Disheartening? Annoying? Infuriating? ..to see long-standing issues being ignored or back-burnered in the march to add all the new features. Duplicate SSL certs still cause sites to be unviewable without stupid and security-breaking workarounds that are not necessary in other browsers, for nearly 7 years now[1], ma…

For the curious, the duplicate SSL cert issue is in regards to some buggy routers and wireless printers with broken firmware. They send out invalid SSL certificates. Firefox doesn't have a way to provide an exception to allow access when security is compromised in this way but the user doesn't care and wants to access it anyway. The only reason tabs generally misbehave is if Flash crashes. Firefox separates Flash out…

No, the certs are otherwise valid, but the problem is that once Firefox has seen a cert for a given address, if another address presents an identical cert, the second address cannot be browsed to without shutting down the browser and deleting the entire cert store.

Other offenders off the top of my head: BMC interface on Intel boards, HP iLO for blade management, F5 load balancers.

Yeah, they shouldn't be doing that, but the only thing being asked for here is a bleeding override button.

Re: Firefox 36.0 released

#30
post #15

Earlier quoted context omitted.

But the issue isn't ignored or back-burnered.

That was more directed at the F-ING SSL issue, but still, end of 2015 to have a feature that's considered standard nowadays and introduced 7 years ago? How much of the work that went into deprecating certs and removing obscure command line flags and setting up HTTP/2 (which isn't even really used by anyone yet) could have went into electrolysis?

SPDY indicator[1] tells me that HTTP/2 is active on all Google properties, including YouTube. That's a nice chunk of the web right there.

I agree with you on older bugs just lingering around. This is a serious issue for many open source projects. JWZ was complaining about it years ago[2]. My favourite example is the problem of putting the tabs at the bottom of the window in gnome-terminal[3], which has been reported over 12 ago, has a patch available posted in the bugzilla, and it's still not fixed.

[1] https://addons.mozilla.org/en-US/firefox/addon/spdy-indicato...

[2] http://www.jwz.org/doc/cadt.html

[3] https://bugzilla.gnome.org/show_bug.cgi?id=75420

Post reply on HN