Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

131–140 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#131

Earlier quoted context omitted.

We are supporting our users. The point is that in this case we shouldn't have to. The problem is an entirely artificial one of Mozilla's creation, and no support from anyone should ever have been necessary.

The problem is entirely of Oracle's and your own creation. Oracle is not adequately supporting their software, and you have failed to notice the signs over the past several years that browsers were headed in exactly this direction and adapt accordingly. Mozilla is taking the only responsible course to protect the vast majority of their users. It's been a long time coming, and absolutely no one should be surprised tha…

Adapt or die.

An unfortunate comment, because some of the devices I had in mind when writing those last few posts are in fact medical equipment.

If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken. Delays and increased suffering for patients are all but certain consequences until the IT staff have chance to fix things again.

Fortunately, the software running on equipment that could actually cause death as a direct result of failure is written to much higher standards and shouldn't depend on this kind of technology in the first place.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#132
post #118

Earlier quoted context omitted.

Seeing browser-developers ignore the real world and just go ahead with their agendas unconcerned about how it affects the actual users of their browser is also a sign of bad development.

You have to stop and think for a moment, though - it's kind of cool that the Firefox development team can basically say "Norwegian authorities - you need to ditch your $100 million outdated software solution because it is unsafe, and we are going to announce this to all your users".

Not so cool if you're a Norwegian taxpayer, one suspects.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#133

Earlier quoted context omitted.

Still, many users [ http://geeksbynature.dk/2013/03/28/plugins-usage-distributio... ] have only Flash, Java and Windows Media plugins installed, maybe also Reader and Office. With Mozilla's efforts to replace Reader with pdf.js and Flash with Shumway (or HTML5), Java is a reasonable next target.

Their PDF replacement is far from good - buggy and unusable. We have to show PDF documents to our customers directly in browser, so we need good UX, and it was disappointing to see how it works in FF compared to other browsers with Reader and how much effort do we need to fix it. I'm not surprised they screwed up with Java too.

It works great for me, better than Chrome PDF Viewer. Chrome's viewer lacks even the most basic features like table of contents, and it's integrated pretty poorly -- it doesn't show the title of pdf (so PDFs are impossible to search by title in history), and it doesn't remember last reading position.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#134
post #128

Earlier quoted context omitted.

Yeah, it's true that lot of the sites still using Java hasn't been updated with the correct instructions about how to enable it in FF 24 yet - and they should fix that as soon as possible of course. Unfortunately, the applets I work on at the moment run on embedded web servers in network-enabled devices. You can't just roll out a quick update to this software every time Mozilla or Oracle break things.

If you were deploying web servers on embedded devices without planning for easy and painless upgrades, joke's on you. That's terrible for your client's security.

Some of those clients' security involves (among other things) firewalled private networks, biometric access controls overseen by armed guards, and a requirement to provide complete systems free of charge for several months of testing and auditing before any new software roll-out is approved. There is no such thing as easy and painless upgrades in that kind of environment, and that is by design. You don't exactly want the patient records in your healthcare systems or the performance monitoring tools with access to all of the traffic on your telecoms infrastructure or the card processing systems at your bank to be accessible on the public WiFi, after all.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#135

Earlier quoted context omitted.

The problem is entirely of Oracle's and your own creation. Oracle is not adequately supporting their software, and you have failed to notice the signs over the past several years that browsers were headed in exactly this direction and adapt accordingly. Mozilla is taking the only responsible course to protect the vast majority of their users. It's been a long time coming, and absolutely no one should be surprised tha…

Adapt or die. An unfortunate comment, because some of the devices I had in mind when writing those last few posts are in fact medical equipment. If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken. Delays and increased suffering for patients are all but certain consequences until the IT staff have chance to fix things agai…

The sorry state of medical IT and medical device vendors is not Mozilla's fault. It is especially not Mozilla's fault if medical organizations and their vendors are rolling out updates they haven't tested themselves.

You're probably aware that in many, if not almost all commercial EULAs, you'll find an all-caps passage like this one I just pulled out of Apple's OS X license document:

> E. YOU FURTHER ACKNOWLEDGE THAT THE APPLE SOFTWARE AND SERVICES ARE NOT INTENDED OR SUITABLE FOR USE IN SITUATIONS OR ENVIRONMENTS WHERE THE FAILURE OR TIME DELAYS OF, OR ERRORS OR INACCURACIES IN THE CONTENT, DATA OR INFORMATION PROVIDED BY, THE APPLE SOFTWARE OR SERVICES COULD LEAD TO DEATH, PERSONAL INJURY, OR SEVERE PHYSICAL OR ENVIRONMENTAL DAMAGE, INCLUDING WITHOUT LIMITATION THE OPERATION OF NUCLEAR FACILITIES, AIRCRAFT NAVIGATION OR COMMUNICATION SYSTEMS, AIR TRAFFIC CONTROL, LIFE SUPPORT OR WEAPONS SYSTEMS.

It's stated clearly and at length because absolutely no one writing general-purpose software wants to bear this responsibility. FOSS no less than commercial, but FOSS is generally a less-attractive lawsuit target.

Trying to foist this responsibility onto Mozilla is just evil. They didn't ask for it. They didn't offer their software as a solution to medical IT's woes. But you want to blame them for obvious misuse of their software causing harm to patients.

If I were to die of an aneurysm tomorrow, would it be your fault for not being a competent neurosurgeon and healing me? No. Nor should it be Mozilla's fault that it does not produce a medical device, but a piece of software someone has decided to misuse as one.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#136

Earlier quoted context omitted.

The problem is entirely of Oracle's and your own creation. Oracle is not adequately supporting their software, and you have failed to notice the signs over the past several years that browsers were headed in exactly this direction and adapt accordingly. Mozilla is taking the only responsible course to protect the vast majority of their users. It's been a long time coming, and absolutely no one should be surprised tha…

Adapt or die. An unfortunate comment, because some of the devices I had in mind when writing those last few posts are in fact medical equipment. If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken. Delays and increased suffering for patients are all but certain consequences until the IT staff have chance to fix things agai…

> If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken.

Would that be a failure of Firefox (or other browser vendors) or a failure of hospital IT staff to manage the medical devices / desktops / network effectively?

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#137

Earlier quoted context omitted.

> You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1] Allow me to disagree and to tell you what happened last weekend: Last Sunday I had a call from my stepfather who "couldn't run the website to order agro food" anymore. This website runs a Java applet to manage agro food orders on-line and the code isn't signed (it's a…

Java actually installs malware (the Ask toolbar) unless you are careful enough to deselect it during the installation/update process.

Uh no. That is not "malware". Unwanted software yes but not malware.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#138

A lot of the angry comments about this seem to be coming from uninformed people who haven't actually tried it - that or something about this change isn't actually rolled out. I just tried it in an up-to-date version of Firefox 24, along with Firefox Nightly. In both, with my existing old build of Java, I got a placeholder image like this: https://dl.dropboxusercontent.com/u/1643240/outdated_java.pn... Clicking it too…

Allowing java to run is not very intuitive. I predict a lot of people believing It can't be run getting frustrated and using a different browser.

I know it's to protect the users from themselves but if you're going to warn on all versions make it easier to allow the applet to run.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#139
post #128

Earlier quoted context omitted.

If you were deploying web servers on embedded devices without planning for easy and painless upgrades, joke's on you. That's terrible for your client's security.

Some of those clients' security involves (among other things) firewalled private networks, biometric access controls overseen by armed guards, and a requirement to provide complete systems free of charge for several months of testing and auditing before any new software roll-out is approved. There is no such thing as easy and painless upgrades in that kind of environment, and that is by design. You don't exactly want…

These are the exact opposite of the kinds of places you would expect an untested Firefox update to show up. You are being inconsistent. Is it a tightly-controlled environment or not?

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#140
post #114

This will be more great publicity for Norwegian government-owned consultancy Evry, which has built the BankID Java Applet which is used for authentication of each and every online consumer money transaction performed in the country. However, it is about time - I've heard online banking developers talk crap both about BankID and the underlying online banking infrastructure in the country, and security holes due to Jav…

"government-owned" is misleading, it's not used for "every online consumer money transaction performed", and, if I understand it correctly, it's just one extra click ..
Post reply on HN