4 ms·
How is that responsible when v54 fixed several security problems? https://www.mozilla.org/en-US/security/advisories/mfsa2017-15/ https://www.mozilla.org/en-US/
by insertnickname 9y ago
How is that responsible when v54 fixed several security problems?
https://www.mozilla.org/en-US/security/advisories/mfsa2017-15/ https://www.mozilla.org/en-US/security/advisories/mfsa2017-1...
- norswap 9y agoMaybe because there's always the potential that a new version may contain an even bigger bombshell?
- bitJericho 9y agoBecause a problematic upgrade could harm or brick every user it rolls out to.
- insertnickname 9y agoBut is that a greater risk than millions running a known-vulnerable browser?
- bitJericho 9y agoNot a single one of those shows a vulnerability. Every one says the bug "could be" exploitable. All software has potential vulnerabilities. The trick is to roll out completely before they become actually vulnerable. That doesn't mean you have to roll out dangerously quickly.
- lizzard 9y agoThere are times when we update users as fast as possible, but that's fairly rare and happens only when there's an exploit disclosed in public (or one definitely being used). So in addition to the security ratings used by Mozilla (defined here: https://wiki.mozilla.org/Security_Severity_Ratings https://wiki.mozilla.org/Security_Severity_Ratings) there are also "incidents" that result in a very fast release to all users (i.e. "chemspill").
- mccr8 9y agoPatches for many of these issues have been public already for a few weeks, so waiting another day or two won't cause much additional harm. The CVEs do not contain test cases.
- insertnickname 9y agoThat's a great point I hadn't considered.
- lizzard 9y agoWe have to weigh the potential risks against the potential benefits of a quick rollout and try to come to a balanced decision. If we see a problem from feedback from early installs, then we have a chance to quickly patch it and re-release, sometimes within one day. Staged rollout is fairly standard in the industry. (Speaking as a Firefox release manager)
- cesarb 9y agoIndeed, a botched rollout can lead to users disabling automated updates (see: Microsoft's GWX). Even if all you care about is security, you have to balance the risk of not patching quickly enough with the risk of the user disabling your ability to patch in the future.