Live data from Hacker News

Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

zdnet.com

11–20 of 82 posts

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#11

I say it every time that people say "Firefox is great now!". Just look at the Bugzilla, and tell me that among the thousands of reports (many of which have gone untriaged for around a decade!) there aren't at least a handful of serious issues like this. One, among many, of the reasons I use Chromium is that I see reports taken absolutely seriously, especially any report with any potential security outcome. Even seemi…

I'd like Firefox to stop focusing on revamping the user interface every five minutes, that's all. Might be a start.

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#14

Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.

Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.

It's only a chore at the start? Once I give a site permissions I make sure to save them, so on next visit it just works.

The impact on amount of traffic and load speed is considerable IMO and well worth the pain at start.

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#15

Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.

Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.

I'm surprised there's no presets to subscribe (like AdBlock) for uMatrix.

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#17

Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.

Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.

Yet another reason to do it -- so that bug reports about websites not working without Javascript are taken seriously, and fixed.

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#18

Earlier quoted context omitted.

I assume the idea is that on the page visible behind the dialog are instructions to call some number, or open the download, or approve the extension the site wants to install.

Having spent a couple of years working for tech support for a large retail chain, I can confirm that this happens much more often than you might think. Non-technical users are floored the browser locking up, especially if the site starts to do something alarming like play an audio file telling them their computer is infected. If they were lucky and brought it to me in that state, I'd teach them about their task manag…

Some pretty good examples of different scammer scripts, of a wide variety, from a guy who has made a hobby out of trolling them:

https://www.youtube.com/channel/UCm22FAXZMw1BaWeFszZxUKw/vid...

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#19
post #17

Earlier quoted context omitted.

Not allowing JavaScript turns into a chore when you find out that websites break in non obvious ways. I do not want to manually enable/disable JavaScript when the browser is a means to an end for me.

Yet another reason to do it -- so that bug reports about websites not working without Javascript are taken seriously, and fixed.

ha! a typical response is "we thank you for taking the time to contact us and value your opinion. our website is best used with Google Chrome and javascript enabled. Do you have any other problem I can stonewall you about?"

I've registered my fair share of complaints about javascript problems, nobody does anything ever. Except once when I complained a bug triggered epilepsy, that got their attention real quick.

Re: Malicious sites abuse 11-year-old Firefox bug that Mozilla failed to fix

#20

Yet another reason to use an extension like uMatrix to disallow javascript by default, and only allow the absolute minimum that sites you trust need to function.

This dialog seems to operates off HTTP authentication, so disabling Javascript will probably not prevent it from appearing.
Post reply on HN