Live data from Hacker News

Firefox 39.0 released

mozilla.org

81–90 of 105 posts

Re: Firefox 39.0 released

#81
To those using FF, is there a way to get an "omnibar" similar to Safari?

For example, Safari usually suggests Wikipedia articles or other useful autocompletions. FF only autocompletes from domain names, bookmarks and history, it seems. It does have a separate search input in the toolbar, but even that one doesn't do what Safari does; all the suggested autocompletes are from Google, and additional search engines like Wikipedia or Amazon require that you click on their icon to search.

There's an extension called Omnibar, but it doesn't seem to provide suggestions from other than Google, bookmarks and history.

Re: Firefox 39.0 released

#82
post #61

Earlier quoted context omitted.

If i ever go to hell i know what my punishment will be - implement unicode

There is a Unicode character PERSON WITH BLOND HAIR, but no corresponding PERSON WITH BLACK HAIR. This is obviously discriminatory. We need new emoji modifiers for: blonde-hair, black-hair, brown-hair, red-hair etc.

That's actually covered in that article:

"As to hair color, dark hair tends to be more neutral, because people of every skin tone can have black (or very dark brown) hair—however, there is no requirement for any particular hair color. One exception is PERSON WITH BLOND HAIR, which needs to have blond hair regardless of skin tone."

Re: Firefox 39.0 released

#83

Earlier quoted context omitted.

> How so? If you're white, perhaps you see no problem with making everyone's skin white. > But the billions of people who aren't white might have a problem with it. I'm not white, and I have a problem with "skin tone" emoji. Previously, skin tones for emoji were left up to the font creator. In practice, this meant that they were usually lime green, neon blue, or Simpsons yellow, all of which are cartoonish enough not…

> Beyond that, the skin tones used are incredibly reductive. Human skin tones are not as simple as 6 different shades of brown. Yes, they are a bit more complicated. But 6 choices that correspond to a widely-used system (Fitzpatrick) is far better than none.

> correspond to a widely-used system (Fitzpatrick)

The fact that a system is widely used when classifying the impact of UV light on melanoma does not imply that it has relevance in another.

> 6 choices is far better than none.

Actually, no, sometimes the "solution" is worse than the problem. It's quite regressive to bake an outdated conception of the color theory of race into a standard that aims to "educate and engage academic and scientific communities, and the general public" (the stated mission of the Unicode Consortium).

As one of the "billions of people who aren't white" that you refer to in your original comment, I find this approach more problematic than the existing status quo (leaving it up to the font creators).

Re: Firefox 39.0 released

#84
post #35

Earlier quoted context omitted.

YES. Force them to upgrade their weak sites!

Which unfortunately costs time and money. Whilst yes, they should be up to date and secure, banks are pretty big businesses and require more time. One day they'll catch up.

Banks, of all businesses, should be concerned about online security, for real protection and for appearance of caring for their customers' peace of mind. Mozilla telegraphs these browser changes months in advance.

Re: Firefox 39.0 released

#85
post #35

Earlier quoted context omitted.

YES. Force them to upgrade their weak sites!

Which unfortunately costs time and money. Whilst yes, they should be up to date and secure, banks are pretty big businesses and require more time. One day they'll catch up.

After the CVE score for BEAST and RC4 got adjusted and the RFC 7465 was introduced I've seen some payment systems update their system quite quickly (in a matter of days), and if they didn't they'd probably fail their next PCI audit: https://news.ycombinator.com/item?id=9198889

Perhaps it helps if you write your payment site operator/bank private emails asking them to allow other ciphers beside RC4, mine looked like this (actual site name removed):

  According to Qualys SSL Labs the site **** [2] only supports the RC4 cipher, 
  and thus is not RFC 7465 compliant [3], and Google Chrome qualifies the site as 
  "Your connection to **** is encrypted with obsolete cryptography."

  The site **** is even worse [4], it uses only 768-bit DH key exchange in some 
  situations (instead of 2048).

  There is an online tool [5] that you can use to generate/compare 
  configuration for popular web-servers, using the intermediate level is 
  recommended [6].

  For your information I sent a similar email last year to **** and they have 
  fixed their problems, and get a nice 'A' grade from SSLLabs now.

  Apparently this use of RC4 all comes down due to a mistake in NIST's 
  classification of the severity of the BEAST vulnerability [7], but both Google 
  Chrome[7] and Mozilla Firefox[8] are trying to avoid the use of RC4 completely, 
  and mitigating the BEAST vulnerability is no excuse for not providing good 
  ciphers (in addition to RC4 if you must) when my browser supports TLS 1.2 with 
  AES-GCM which is NOT vulnerable to the BEAST attack.

  I suggest you to include the Qualys SSL Labs test when testing sites for 
  PCI-DSS compliance, they are usually quite good at reporting the latest TLS 
  vulnerabilities for a server.

  [1] http://www.visaeurope.com/media/images/pci%20dss%20validated%20web%20listing%20march%202015-73-18412.pdf
  [2] https://www.ssllabs.com/ssltest/analyze.html?d=****
 This server accepts the RC4 cipher, which is weak. Grade capped to B.
 Certificate uses a weak signature. When renewing, ensure you upgrade to SHA2.
  [3] https://tools.ietf.org/html/rfc7465
  [4] https://www.ssllabs.com/ssltest/analyze.html?d=****
 This server supports insecure Diffie-Hellman (DH) key exchange parameters. Grade set to F.
 Certificate uses a weak signature. When renewing, ensure you upgrade to SHA2.
 The server supports only older protocols, but not the current best TLS 1.2. Grade capped to B.
 This server accepts the RC4 cipher, which is weak. Grade capped to B.
  [5] https://mozilla.github.io/server-side-tls/ssl-config-generator/
  [6] https://wiki.mozilla.org/Security/Server_Side_TLS
  [7] https://code.google.com/p/chromium/issues/detail?id=375342#c30
  [8] https://bugzilla.mozilla.org/show_bug.cgi?id=1088915
  [9] https://www.ssllabs.com/ssltest/analyze.html?d=****

Re: Firefox 39.0 released

#86
post #48

And yet there are still issues on my Sandy Bridge system with display corruption even with the latest Intel drivers. Also has anyone else noticed that Firefox is no longer keeping the page state when navigating back? For example on Reddit go to the comments section, minimize a few comments then navigate to a link then go back and none of the minimized comments remain minimized, in Firefox prior to 38 things worked co…

Yes I have noticed the exact same thing on Reddit lately. My guess it's because they started sending "Cache-Control: no-cache" which prevents Firefox to cache the page for the back button.

https://bugzilla.mozilla.org/show_bug.cgi?id=567365

Re: Firefox 39.0 released

#87
post #16

Earlier quoted context omitted.

Same here. But I'll keep using Firefox because I cant stand what Chrome is doing with my cpu/memory/privacy and I want to keep Safari (the less 'usable' browser) for work related stuff and Firefox for personal ones, on another desktop space.

Two firefox profiles? One for work and one for personal? Type "man firefox" into your terminal and you will see the relevant options and can set up aliases and shortcuts appropriate for your separated browsing needs.

There are some Firefox add-ons that let you run multiple profiles in separate windows.

Re: Firefox 39.0 released

#88

Earlier quoted context omitted.

Two firefox profiles? One for work and one for personal? Type "man firefox" into your terminal and you will see the relevant options and can set up aliases and shortcuts appropriate for your separated browsing needs.

There are some Firefox add-ons that let you run multiple profiles in separate windows.

Firefox does this out of the box without any addons.

Re: Firefox 39.0 released

#89
post #8

Surprised by the inclusion of "CSS Scroll Snap Points": https://developer.mozilla.org/en-US/docs/Web/CSS/scroll-snap... It basically allows to do scroll hijacking [1] without any JavaScript, just like this: http://blog.gospodarets.com/demos/scroll-snap-full-screen/ [1]: http://trentwalton.com/2013/10/23/scroll-hijacking/

this is in Safari 9 as well. https://developer.apple.com/library/prerelease/mac/releaseno...

Re: Firefox 39.0 released

#90

To those using FF, is there a way to get an "omnibar" similar to Safari? For example, Safari usually suggests Wikipedia articles or other useful autocompletions. FF only autocompletes from domain names, bookmarks and history, it seems. It does have a separate search input in the toolbar, but even that one doesn't do what Safari does; all the suggested autocompletes are from Google, and additional search engines like…

I really do miss typing part of a domain name (often YouTube), hitting tab, and doing an on site search.

But I'll put up with whatever to support Mozilla. Their work on Firefox and Rust is some of the most important going on.

Post reply on HN