Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

11–20 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#11
post #2

Great news, I'm always paranoid about java plugin. Now I can relax a little bit.

You were able to disable java in your browser with one click also before ...in my opinion, this move from FF is a very bad one.

Now what we should use if we need more then HTML5? A) -> Silverlight ...FF promote a closed technology against the somehow open Java?? B) -> Flash ...which is on a downhill now? C) -> Java ...users need to be IT experts to enable it

One thing I would like to see: MS should ban FF because it is insecure :)

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#13
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

> This will have a pretty bad effect on Firefox's market-share if it goes live. It's already live. ff24 is the current stable.

Oh interesting - hard to keep track of which version Firefox is up to these days. They should really swap to a system like Ubuntu's - using the date for the version number.

It was released over a month ago too. Has it had any effect on Firefox's market-share? Especially in enterprise? It's a pretty decent test bed for understanding how users react to these kinds of changes. If they just accept them and adapt when forced it shows that we can be more proactive in moving users to better yet incompatible software?

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#14

I'm trying to find a summary of why this was done. This is a pretty high impact change!!!

Java vulnerabilities are a huge source of drive-by exploits in the browser. I wouldn't recommend anyone leave java on by default.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#15
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

Why? Java applets are extremely rare these days.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#16
The sooner Java moves away from Oracle, the better for everyone. That being said, there is rarely a need to run Java from a browser, aside from the odd game.

But, given Flash's similar reputation (not to mention it being prone to crash), why not mark Flash as unsafe as well?

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#17
post #9
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

Will it? I've been browsing without Java for years, and I can only remember problems with one site (some hilarious throwback from the late 90s). For general browsing, I doubt anyone will notice a difference. Maybe for corporate use, but isn't that mostly IE anyway?

Depends on where you are in the world. Java is required for online banking in Norway, while it's mostly unused in Sweden, the neighbouring country. Both use Java for online verification to government sites.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#18

Did they also disable Flash? (well I don't have the plugin installed anyway, so I wouldn't know)

No. Mozilla's plan for flash is to replace it with a javascript flash runtime, shumway.js, in the same way they discouraged adobe's acrobat plugin by bundling pdf.js. But shumway's not finished yet.

See: https://lwn.net/Articles/569496/

Post reply on HN