27 ms·
It's worrying to me that they imply ESR is less secure; isn't the whole point that it gets security fixes applied to it? Less churn should make it more secure.
by technomancy 10y ago
It's worrying to me that they imply ESR is less secure; isn't the whole point that it gets security fixes applied to it? Less churn should make it more secure.
- tedmiston 10y ago> Maintenance of each ESR, through point releases, is limited to high-risk/high-impact security vulnerabilities and in rare cases may also include off-schedule releases that address live security vulnerabilities. Backports of any functional enhancements and/or stability fixes are not in scope. https://www.mozilla.org/en-US/firefox/organizations/faq/ https://www.mozilla.org/en-US/firefox/organizations/faq/
- technomancy 10y agoDamn; I assumed since it was shipped in Debian Stable it had all the same guarantees as the rest of the distro, but I guess the browser codebases tend to be such security disasters that they can't necessarily keep up.
- mgbmtl 10y agoProjects release new versions of software not just for new features, but (one would hope) constant improvements to the underlying architecture. Firefox in particular has been evolving quickly, with many of under-the-hood improvements that may not fix "high-risk" security issues, but constantly improve security directly or indirectly (e10s?). You can't expect maintainers of an ESR to backport all those things. There's always a risk in adopting the latest version of a program, but there's also a risk with keeping the old, less actively maintained version. I get burned all the time with Debian Stable, running into bugs fixed in the latest version but not backported. (nonetheless, I do prefer Debian Stable to most other solutions) A project I'm involved in even has an automatic "toxic code" warning for PRs on known functions/classes that need to be refactored, and where monkey-patching will likely cause other security issues one way or another.
- rictic 10y agoSpeculating but some new features are security features, like support for additional CSP directives, cipher suites, that sort of thing.
- yuhong 10y agoAn example is "Slaughterhouse" (see https://bugzilla.mozilla.org/show_bug.cgi?id=929539 https://bugzilla.mozilla.org/show_bug.cgi?id=929539 and http://bholley.net/blog/2016/the-right-fix.html http://bholley.net/blog/2016/the-right-fix.html). This is not the only incident where Mozilla people have suggested hiding bugs until an old ESR goes end of life BTW.