This will be more great publicity for Norwegian government-owned consultancy Evry, which has built the BankID Java Applet which is used for authentication of each and every online consumer money transaction performed in the country. However, it is about time - I've heard online banking developers talk crap both about BankID and the underlying online banking infrastructure in the country, and security holes due to Jav…
In Firefox 24 and following, mark all versions of Java as unsafe
141–150 of 184 posts
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#142Earlier quoted context omitted.
Adapt or die. An unfortunate comment, because some of the devices I had in mind when writing those last few posts are in fact medical equipment. If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken. Delays and increased suffering for patients are all but certain consequences until the IT staff have chance to fix things agai…
> If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken. Would that be a failure of Firefox (or other browser vendors) or a failure of hospital IT staff to manage the medical devices / desktops / network effectively?
Logically, if Firefox is not going to support long term stability and compatibility -- and clearly it doesn't in the case we're discussing -- then the only possible conclusion is that Firefox can't be part of an effectively managed IT infrastructure for these kinds of organisations. That means the correct course of action for those responsible for that infrastructure is to plan to remove any dependencies on Firefox as quickly as possible and to replace it with something more stable, which presumably means IE in this context.
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#143Earlier quoted context omitted.
You have to stop and think for a moment, though - it's kind of cool that the Firefox development team can basically say "Norwegian authorities - you need to ditch your $100 million outdated software solution because it is unsafe, and we are going to announce this to all your users".
Not so cool if you're a Norwegian taxpayer, one suspects.
(And if this really is just a click-to-play type inconvenience, well, that's a hell of a lot less than the hoops that users are used to going through in order to get into their BankID banks here.)
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#144Earlier quoted context omitted.
Some of those clients' security involves (among other things) firewalled private networks, biometric access controls overseen by armed guards, and a requirement to provide complete systems free of charge for several months of testing and auditing before any new software roll-out is approved. There is no such thing as easy and painless upgrades in that kind of environment, and that is by design. You don't exactly want…
These are the exact opposite of the kinds of places you would expect an untested Firefox update to show up. You are being inconsistent. Is it a tightly-controlled environment or not?
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#145Earlier quoted context omitted.
edit: here I should replace firefox and mozilla with oracle That's quite a stretch. I have a user who uses frequently one specific website and for no apparent reason Firefox decides to tell him it's now dangerous to use with fearful and technological terms (vulnerabilities, plug-in, risk, etc.). If Mozilla decides its users are dumb and should not be trusted to allow Java applet to be run then they should not warn th…
The warnings are 8-14 and 5-8 words respectively, and state the case concisely. The word "risk" appears nowhere, and is a common English word anyway, and "vulnerable" and its derivatives are also common English words. How would you rephrase the warning in fewer than 8 words that would have helped your stepfather understand the problem and how to deal with it?
http://support.mozilla.org/en-US/kb/how-to-enable-java-if-it...
edit: formatting.
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#146Earlier quoted context omitted.
edit: here I should replace firefox and mozilla with oracle That's quite a stretch. I have a user who uses frequently one specific website and for no apparent reason Firefox decides to tell him it's now dangerous to use with fearful and technological terms (vulnerabilities, plug-in, risk, etc.). If Mozilla decides its users are dumb and should not be trusted to allow Java applet to be run then they should not warn th…
The warnings are 8-14 and 5-8 words respectively, and state the case concisely. The word "risk" appears nowhere, and is a common English word anyway, and "vulnerable" and its derivatives are also common English words. How would you rephrase the warning in fewer than 8 words that would have helped your stepfather understand the problem and how to deal with it?
It's french but I doubt the translation process would made the word count explode from 14 words to this: https://dl.dropboxusercontent.com/u/202857/java.png
(and yes, it popped up on an up-to-date firefox with up-to-date java)
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#147Earlier quoted context omitted.
The warnings are 8-14 and 5-8 words respectively, and state the case concisely. The word "risk" appears nowhere, and is a common English word anyway, and "vulnerable" and its derivatives are also common English words. How would you rephrase the warning in fewer than 8 words that would have helped your stepfather understand the problem and how to deal with it?
Somehow I have the feeling we aren't talking about the same warning. It's french but I doubt the translation process would made the word count explode from 14 words to this: https://dl.dropboxusercontent.com/u/202857/java.png (and yes, it popped up on an up-to-date firefox with up-to-date java)
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#148Earlier quoted context omitted.
> You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1] Allow me to disagree and to tell you what happened last weekend: Last Sunday I had a call from my stepfather who "couldn't run the website to order agro food" anymore. This website runs a Java applet to manage agro food orders on-line and the code isn't signed (it's a…
Java actually installs malware (the Ask toolbar) unless you are careful enough to deselect it during the installation/update process.
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#149Earlier quoted context omitted.
> You can still easily run Java applets in Firefox 24 and beyond, you just need to click the red lego block in the upper left corner and allow it. [1] Allow me to disagree and to tell you what happened last weekend: Last Sunday I had a call from my stepfather who "couldn't run the website to order agro food" anymore. This website runs a Java applet to manage agro food orders on-line and the code isn't signed (it's a…
Interesting point. How would you rephrase the warning?
Anyway, this is the warning my user was given : https://dl.dropboxusercontent.com/u/202857/java.png
Unmovable window, can't close firefox without first actioning something in it, one checkbox+one butotn to allow "something scary" to run (something that wasn't scary yesterday). This is what prompted my user to google the warning.
Re: In Firefox 24 and following, mark all versions of Java as unsafe
#150I hope there will be an about:config override for this. It seems like any time one of these browser authors does something "for security", it ends up being a perpetual pain in my ass and the ass of the users I support.