I say it every time that people say "Firefox is great now!". Just look at the Bugzilla, and tell me that among the thousands of reports (many of which have gone untriaged for around a decade!) there aren't at least a handful of serious issues like this. One, among many, of the reasons I use Chromium is that I see reports taken absolutely seriously, especially any report with any potential security outcome. Even seemi…
Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
11–20 of 82 posts
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#12Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#13Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#14Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.
Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.
The impact on amount of traffic and load speed is considerable IMO and well worth the pain at start.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#15Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.
Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#16it seems it can be fixed in 11 minutes. mozilla just don't give a f&ck.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#17Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.
Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#18Earlier quoted context omitted.
I assume the idea is that on the page visible behind the dialog are instructions to call some number, or open the download, or approve the extension the site wants to install.
Having spent a couple of years working for tech support for a large retail chain, I can confirm that this happens much more often than you might think. Non-technical users are floored the browser locking up, especially if the site starts to do something alarming like play an audio file telling them their computer is infected. If they were lucky and brought it to me in that state, I'd teach them about their task manag…
https://www.youtube.com/channel/UCm22FAXZMw1BaWeFszZxUKw/vid...
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#19Earlier quoted context omitted.
Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.
Yet another reason to do it -- so that bug reports about websites not working without Javascript are taken seriously, and fixed.
I've registered my fair share of complaints about javascript problems, nobody does anything ever. Except once when I complained a bug triggered epilepsy, that got their attention real quick.
Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix
#20Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.