Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

171–180 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#171
post #114

This will be more great publicity for Norwegian government-owned consultancy Evry, which has built the BankID Java Applet which is used for authentication of each and every online consumer money transaction performed in the country. However, it is about time - I've heard online banking developers talk crap both about BankID and the underlying online banking infrastructure in the country, and security holes due to Jav…

" government-owned " is misleading, it's not used for " every online consumer money transaction performed ", and, if I understand it correctly, it's just one extra click ..

Evry, the consultancy which developed and runs BankID, is largely owned by the public (The Postal Service: 40%, Telenor: 30%, of which the latter is 53% state-owned: http://www.purehelp.no/company/owner_network/evryasa/9343824...). BankID is in fact used to sign all(#) internet banking transactions by regular, private end users of online banking services.

The problem isn't the extra click - two factor authentication with a one-time pad is an excellent extra security measure. The problem is that the implementation sucks and is riddled with security holes, prompting you to update Java every other time you log into your online bank account. This in addition to incredibly slow loading and also outright crashes if you are using a non-standard (i.e. not latest version of IE) browser. It is a giant, steaming pile of crappy software. We can't switch to a Javascript version fast enough.

(#) Except for those customers who have not yet been pushed into BankID, which is the selected standard for online banking. And obviously not for intra-bank and similar transactions.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#172

Earlier quoted context omitted.

Yes, Mozilla has been pretty clear on this. If you want more stability, you need the ESR release, and if that's not enough, you're out of luck. Mainline Firefox is simply not intended for use within organizations that demand the kind of stability you want. You need to evaluate the ESR release, and/or find a different browser entirely. IE may indeed be the best option if you only support Windows clients. Though Micros…

Mainline Firefox is simply not intended for use within organizations that demand the kind of stability you want. I'm not sure who mainline Firefox is intended for any more. That's part of the problem, I think. It seems like Mozilla are chasing Google to the exclusion of almost anything else, and the main goal for both of them seems to be ticking boxes to say they have more bleeding edge features, even though hardly a…

Your mistake is in conflating Java with the browser. The two are unrelated. Neither is really built with the other in mind, their development is not integrated or synchronized in any way, and the paradigms are just generally incompatible. And now, one poses a clear and present danger to the security of the other.

If you had a Java application, you would not have a problem. If you had a web application, you would not have a problem. If you had a C or C++ application built against either native Windows APIs or a mature cross-platform toolkit, you would not have a problem.

Instead, you rely on browsers continuing to put their users at risk by automatically running code in a constantly-leaking sandbox managed by a company that doesn't give a shit.

Understand this: Java is a hole in the defenses of modern web browsers. It is behind. Way behind. And it will remain so forever. It and its owner are not up to the task of dealing with the modern web.

So yes, you're going to be fighting a constant battle so long as you insist on relying on what everybody already knew was crap in the mid-90s.

Or you could just tell your users to click the magic button.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#173
post #113

Does anyone want to write a user-friendly walk-through to help normal users get Java running? I may have the time to assist, though I'm doubtful I could do the whole thing. ScreenLeap has a good start: http://www.screenleap.com/troubleshooting-java The advice they give varies based on the detected browser and OS (as it must) but it's somewhat out of date, and isn't intended for a general audience. The applets on my e…

Could you consider contributing this to http://support.mozilla.org ?

I don't have much hope - the pile-on against applets has been unrelenting for months now - but I will give this a shot. It's not obvious to me which part of the site you mean yet, though.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#174
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

Java is singled out because it is "too big to fail".

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#175
post #152

Earlier quoted context omitted.

> Delays and increased suffering for patients are all but certain consequences If the product you are building is not future proof it is your problem not Mozilla's. Dont blame Mozilla for your poor technology choices. Applets will eventually stop working, and you'll be responsible if your product fails , not Mozilla. Dont blame anybody else but you. You broke the medical staff instruments by choosing or maintaining a…

If the product you are building is not future proof it is your problem not Mozilla's. Nothing is future-proof if the people controlling the platforms move the goalposts. We have standards and value backward compatibility for a reason: it's because violating those standards and breaking that compatibility hurts. And it's going to become Mozilla's problem if they continue down this path, because Firefox will cease to b…

TLDR it's your problem , not Mozilla's. You can still tell your clients to uee another browser, heck they had to install java on their machines for your solution to work... they should not had too, but smart people always make poor technology choices.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#176
post #136

Earlier quoted context omitted.

> If Java-based UIs are no longer readily available to clinical staff the way they were last week, then effectively their instruments just got broken. Would that be a failure of Firefox (or other browser vendors) or a failure of hospital IT staff to manage the medical devices / desktops / network effectively?

I really hope you aren't one of the same people who say IE6 and IE7 have to die, and so web developers are right to try to force their users to use modern browsers. I work with the NHS in the UK; quite a few of the medical professionals are forced to use IE6 or IE7 because the hospital IT staff are managing their medical devices / desktops / network effectively, just as you say. When Firefox makes a decision like thi…

My immediate point was that it's not as if Firefox is all of the sudden automatically updating itself on the hospital computers and people start dying because Java applets won't run. If that happened, I would blame the IT staff for allowing such a critical component to update itself without any sort of evaluation.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#177
post #67
post #17

Earlier quoted context omitted.

Depends on where you are in the world. Java is required for online banking in Norway, while it's mostly unused in Sweden, the neighbouring country. Both use Java for online verification to government sites.

> Both use Java for online verification to government sites. Do they? I thought Sweden used the online bank identity system for verification (bankid), which is either a standalone downloadable application, a smartcard image, or an mobile app. Not sure how an Firefox policy would effect this even if some parts of the bankid uses Java.

Bankid is based on java iirc.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#178
post #175

Earlier quoted context omitted.

If the product you are building is not future proof it is your problem not Mozilla's. Nothing is future-proof if the people controlling the platforms move the goalposts. We have standards and value backward compatibility for a reason: it's because violating those standards and breaking that compatibility hurts. And it's going to become Mozilla's problem if they continue down this path, because Firefox will cease to b…

TLDR it's your problem , not Mozilla's. You can still tell your clients to uee another browser, heck they had to install java on their machines for your solution to work... they should not had too, but smart people always make poor technology choices.

You can still tell your clients to uee another browser

Actually, we've been doing that for quite some time on one of the major projects I work on that uses Java applets, for exactly this reason. We usually recommend a recent version of IE, and as a general policy we don't offer any sort of guaranteed support for Firefox or Chrome. Of course we still test on those other browsers routinely and we'll help customers who have problems if we can, but no-one is getting any money back if they break later because of the kinds of changes we're talking about.

The worrying thing for Mozilla should be how many businesses are essentially telling us that they agree and they're moving or already planning to move back to IE as their corporate standard. It's certainly not always because of Java, but choices like rapid update cycles, lack of long-term support, and willingness to drop useful functionality do seem to be generating an increasing amount of hostility from institutional users.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#180

Earlier quoted context omitted.

Still, many users [ http://geeksbynature.dk/2013/03/28/plugins-usage-distributio... ] have only Flash, Java and Windows Media plugins installed, maybe also Reader and Office. With Mozilla's efforts to replace Reader with pdf.js and Flash with Shumway (or HTML5), Java is a reasonable next target.

Their PDF replacement is far from good - buggy and unusable. We have to show PDF documents to our customers directly in browser, so we need good UX, and it was disappointing to see how it works in FF compared to other browsers with Reader and how much effort do we need to fix it. I'm not surprised they screwed up with Java too.

Since I replaced Adobe Reader with SumatraPDF on my Windows machine I found this to be a really good feature and it works for the most PDFs. In recent Firefox version I did not have any problems viewing PDFs. Although they need to make it more responsive, especially on larger documents. But Adobe Reader wasn't really fast to begin with, so it's not that big of a deal.
Post reply on HN