Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

141–150 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#141
post #114

This will be more great publicity for Norwegian government-owned consultancy Evry, which has built the BankID Java Applet which is used for authentication of each and every online consumer money transaction performed in the country. However, it is about time - I've heard online banking developers talk crap both about BankID and the underlying online banking infrastructure in the country, and security holes due to Jav…

There are still a couple banks in Norway where you can get by without BankID.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#142
post #136

Earlier quoted context omitted.

Adapt or die. An unfortunate comment, because some of the devices I had in mind when writing those last few posts are in fact medical equipment. If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken. Delays and increased suffering for patients are all but certain consequences until the IT staff have chance to fix things agai…

> If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken. Would that be a failure of Firefox (or other browser vendors) or a failure of hospital IT staff to manage the medical devices / desktops / network effectively?

That's a fair question. However, I don't think some people posting in this discussion would like the equally fair answer.

Logically, if Firefox is not going to support long term stability and compatibility -- and clearly it doesn't in the case we're discussing -- then the only possible conclusion is that Firefox can't be part of an effectively managed IT infrastructure for these kinds of organisations. That means the correct course of action for those responsible for that infrastructure is to plan to remove any dependencies on Firefox as quickly as possible and to replace it with something more stable, which presumably means IE in this context.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#143
post #118

Earlier quoted context omitted.

You have to stop and think for a moment, though - it's kind of cool that the Firefox development team can basically say "Norwegian authorities - you need to ditch your $100 million outdated software solution because it is unsafe, and we are going to announce this to all your users".

Not so cool if you're a Norwegian taxpayer, one suspects.

As a Norwegian taxpayer, I disagree :-) I don't know a single Norwegian who actually enjoys having to update Java again (and anyone who's turned on the news in the last 3 years here has heard of Java security holes).

(And if this really is just a click-to-play type inconvenience, well, that's a hell of a lot less than the hoops that users are used to going through in order to get into their BankID banks here.)

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#144

Earlier quoted context omitted.

Some of those clients' security involves (among other things) firewalled private networks, biometric access controls overseen by armed guards, and a requirement to provide complete systems free of charge for several months of testing and auditing before any new software roll-out is approved. There is no such thing as easy and painless upgrades in that kind of environment, and that is by design. You don't exactly want…

These are the exact opposite of the kinds of places you would expect an untested Firefox update to show up. You are being inconsistent. Is it a tightly-controlled environment or not?

The environment in which these devices exist and the environment in which the machines used to access them exist are not necessarily the same. Obviously they will be connected in some way, but it is perfectly rational to want to apply security updates to staff computers that might encounter software or data from external sources but which might also be used to access in-house systems that are tightly controlled.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#145

Earlier quoted context omitted.

edit: here I should replace firefox and mozilla with oracle That's quite a stretch. I have a user who uses frequently one specific website and for no apparent reason Firefox decides to tell him it's now dangerous to use with fearful and technological terms (vulnerabilities, plug-in, risk, etc.). If Mozilla decides its users are dumb and should not be trusted to allow Java applet to be run then they should not warn th…

The warnings are 8-14 and 5-8 words respectively, and state the case concisely. The word "risk" appears nowhere, and is a common English word anyway, and "vulnerable" and its derivatives are also common English words. How would you rephrase the warning in fewer than 8 words that would have helped your stepfather understand the problem and how to deal with it?

"Java is disabled in Firefox. [More Info]()"

http://support.mozilla.org/en-US/kb/how-to-enable-java-if-it...

edit: formatting.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#146

Earlier quoted context omitted.

edit: here I should replace firefox and mozilla with oracle That's quite a stretch. I have a user who uses frequently one specific website and for no apparent reason Firefox decides to tell him it's now dangerous to use with fearful and technological terms (vulnerabilities, plug-in, risk, etc.). If Mozilla decides its users are dumb and should not be trusted to allow Java applet to be run then they should not warn th…

The warnings are 8-14 and 5-8 words respectively, and state the case concisely. The word "risk" appears nowhere, and is a common English word anyway, and "vulnerable" and its derivatives are also common English words. How would you rephrase the warning in fewer than 8 words that would have helped your stepfather understand the problem and how to deal with it?

Somehow I have the feeling we aren't talking about the same warning.

It's french but I doubt the translation process would made the word count explode from 14 words to this: https://dl.dropboxusercontent.com/u/202857/java.png

(and yes, it popped up on an up-to-date firefox with up-to-date java)

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#147

Earlier quoted context omitted.

The warnings are 8-14 and 5-8 words respectively, and state the case concisely. The word "risk" appears nowhere, and is a common English word anyway, and "vulnerable" and its derivatives are also common English words. How would you rephrase the warning in fewer than 8 words that would have helped your stepfather understand the problem and how to deal with it?

Somehow I have the feeling we aren't talking about the same warning. It's french but I doubt the translation process would made the word count explode from 14 words to this: https://dl.dropboxusercontent.com/u/202857/java.png (and yes, it popped up on an up-to-date firefox with up-to-date java)

Congratulations, you've just lambasted Mozilla for a Java message. Java pops up that same message for applets in all browsers. Go talk to Oracle, it has absolutely nothing to do with Mozilla or Firefox.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#148

Earlier quoted context omitted.

> You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1] Allow me to disagree and to tell you what happened last weekend: Last Sunday I had a call from my stepfather who "couldn't run the website to order agro food" anymore. This website runs a Java applet to manage agro food orders on-line and the code isn't signed (it's a…

Java actually installs malware (the Ask toolbar) unless you are careful enough to deselect it during the installation/update process.

Heh. I guess that makes me a malware writer as I worked on the Ask Toolbar for Firefox when I worked at Ask.com.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#149
post #110

Earlier quoted context omitted.

> You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1] Allow me to disagree and to tell you what happened last weekend: Last Sunday I had a call from my stepfather who "couldn't run the website to order agro food" anymore. This website runs a Java applet to manage agro food orders on-line and the code isn't signed (it's a…

Interesting point. How would you rephrase the warning?

I had a look at the mozilla website and the english phrasing seems okay to me. I think the french is too verbose (and it adds nuances that are confusing like "some versions of the plugin is disabled", "trusted sites": does it mean sites that are guaranteed to be trusted because of a certificate or sthg or sites I trust because I know who coded it or it's so universally known (eg: google) that I should trust it anyway ?) even ignoring the fact french is de facto more verbose than english.

Anyway, this is the warning my user was given : https://dl.dropboxusercontent.com/u/202857/java.png

Unmovable window, can't close firefox without first actioning something in it, one checkbox+one butotn to allow "something scary" to run (something that wasn't scary yesterday). This is what prompted my user to google the warning.

Post reply on HN