Live data from Hacker News

In Firefox 24 and following, mark all versions of Java as unsafe

bugzilla.mozilla.org

41–50 of 184 posts

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#41
post #26
post #25

Earlier quoted context omitted.

I doubt it. Apart from the odd algorithm demonstration I haven't found a need to enable Java in my browser for the past 10 years.

Sure, and I haven't used Internet Explorer in years. That doesn't mean that suddenly disabling Internet Explorer is going to have no effect even if I (and probably most of us here on HN) would not even notice. A lot of corporates and financial applications require Java.

So you think perpetuating the use of Java in the browser is a reasonable response to the security risks it presents to those corporates?

This action by Mozilla raises awareness of the fact that Java security updates are too slow and too opaque and it's time to change to something else.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#43
I'm using Firefox in Ubuntu with Java to connect to a Juniper Networks VPN. When I upgraded to Ubuntu 13.10 a couple of days ago, the VPN launcher stopped working. I think Firefox 24 came along with the upgrade (that's the version running now).

I upgraded to the latest Java r45 and it still didn't work. Then I noticed a blinking red thing in the address bar where the security lock icon goes. I clicked that and it gave me an option to enable Java for the VPN connection site permanently.

Seemed easy enough to fix. I only had to click that icon once, and it's been working smoothly since.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#44
post #34

I'm all for this being blocked by default, and the same goes for all plugins. But it certainly bothers me when they make it impossible to override their security constraints. Put in an about:config setting to allow Java, and it's fine. All the heavy-handedness is going to do is force Firefox out of corporate IT environments where many internal websites rely on Java.

This. Firefox is all about customization for me. Can you use about:config to turn this off? (I don't even use Java or Flash)

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#45

I'm using Firefox in Ubuntu with Java to connect to a Juniper Networks VPN. When I upgraded to Ubuntu 13.10 a couple of days ago, the VPN launcher stopped working. I think Firefox 24 came along with the upgrade (that's the version running now). I upgraded to the latest Java r45 and it still didn't work. Then I noticed a blinking red thing in the address bar where the security lock icon goes. I clicked that and it gav…

You might also want to take a look at https://github.com/madscientist/msjnc. I found it a lot better than Juniper's manager for linux.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#46
post #6

This will have a pretty bad effect on Firefox's market-share if it goes live. That said, it's a solution for the current problem and should really be applied to all plugins - I'm not sure why java is singled out here, many of the other browser plugins are just as bad. Java has likely the most widely publicized security vulnerabilities, yet I can guarantee you that many many 0-days are traded daily for practically eve…

Why? Java applets are extremely rare these days.

If you're 20-something doing "the startup game" you probably don't see it on the next cool site demos.

If you support the company where most of the users just know to click and login, and one day they just can't, you aren't going to like it, to quote one of the post from the bugzilla:

"I haven't been able to get VPN-ed in for days, until I figured I could still use the Juniper SSL VPN from Internet Explorer. I find it amazing the casualness with which a small group of developers just shut off an entire set of functionality with no regard for its size, utility... You just broke millions of peoples software, and then you complain about this being a bug list, and you can simply do this, or simply do that."

It doesn't help that "advanced users" would know, ordinary users after the automatic update can't do what they were able to do.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#47

Wow, this is really irresponsible behavior, I would've expected something better from Mozilla.. Until now they've first offered an alternative (e.g. pdf.js) before trying to move away from a tech. Marking a current version as unsafe, even when there are no known exploits is simply ridiculous. I'd love to see the reaction of Mozilla if Microsoft decided to mark all Firefox releases as unsafe, and give a big security w…

Well, when you download the .exe file in IE, you do get a warning that it might be unsafe from Windows. And you need to verify that you want to install it. The way to verify that the installer is legit, verifying the checksum, is not done by Windows, and must be done manually. Users don't do that, and flagging everything as unsafe is a good way of notifying the user that they must be careful.

> flagging everything as unsafe is a good way of notifying the user that they must be careful

Crying wolf all the time is a 100% guaranteed way of making sure nobody will ever care.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#48
post #41
post #26

Earlier quoted context omitted.

Sure, and I haven't used Internet Explorer in years. That doesn't mean that suddenly disabling Internet Explorer is going to have no effect even if I (and probably most of us here on HN) would not even notice. A lot of corporates and financial applications require Java.

So you think perpetuating the use of Java in the browser is a reasonable response to the security risks it presents to those corporates? This action by Mozilla raises awareness of the fact that Java security updates are too slow and too opaque and it's time to change to something else.

I'd personally say the same about Flash and any other browser plugin - they should all be disabled. The amount of money traded on the black market for 0 days for all of these plugins is staggering.

That said, users of these plugins are not just going to stop using these services. They need these services to make bank payments or trade their shares. Getting hacked is a smaller worry than being unable to use those services. That just means they will swap to a different browser. The web becomes no safer, and only Firefox loses market share.

If you get hacked and someone steals from your bank account, the bank will reimburse you and the police will (try) track down the hackers. Same way as if someone broke into a bank vault and stole the money. Being unable to sell off your shares because Firefox blocked your trading app means you are forced to switch browsers.

Basically it's a pointless display. Just show a warning if a website tries to use a plugin (any plugin, including flash - there are numerous undisclosed 0-days) and move on.

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#49

Earlier quoted context omitted.

Well, when you download the .exe file in IE, you do get a warning that it might be unsafe from Windows. And you need to verify that you want to install it. The way to verify that the installer is legit, verifying the checksum, is not done by Windows, and must be done manually. Users don't do that, and flagging everything as unsafe is a good way of notifying the user that they must be careful.

> flagging everything as unsafe is a good way of notifying the user that they must be careful Crying wolf all the time is a 100% guaranteed way of making sure nobody will ever care.

UAC? is that the window I always have to click 'Yes' on when I run a program? Yeah, could you disable that?

Re: In Firefox 24 and following, mark all versions of Java as unsafe

#50

Earlier quoted context omitted.

> This will have a pretty bad effect on Firefox's market-share if it goes live. It's already live. ff24 is the current stable.

Confirmed. It broke my SO's ability to do online banking yesterday and I was (as usual) called in as tech support. I just assumed Java was out of date (again) and was surprised to see it still blacklisted after updating to latest version. There's no part of the UI saying "We've permanently blocked all of Java by default". Even if you agree with the developer's ideological stance here (which you very well may not), th…

There should be a "plugin" icon in the address bar, showing you that java has been blocked (see https://news.ycombinator.com/item?id=6590650)

Pressing on that icon should allow you to run java once, or allow if forever for that site.

If the icon doesn't appear, I think you should file a bug on bugzilla.

Post reply on HN