8 ms·
Is that sarcasm?
by terabytest 13y ago
Is that sarcasm?
- LukeShu 13y agoI don't think so. It's easy now to look at the headline and think "Oh, just another Firefox release, it happens what? once a month?". That's a good thing. Users are upgrading, the process is smooth; Mozilla's having a relatively easy time iterating. Remember when Firefox 3, 4, and 5 came out? Each time, it was a big deal. Many complained and groaned. The upgrade process was problematic for many users. Some users would still have problems upgrading for many releases after that. It's been a great year if they can push out numerous high-quality releases, and have the process be so smooth that when users hear of a new version, they think "meh".
- nfoz 13y agoI would much rather a long-term-stable product with fewer security vulnerabilities that didn't need frequent updates.
- orbitur 13y agoTo have that, we would need to be disconnected from the internet.
- nirvdrum 13y agoCheck out the Firefox ESR builds. They're supported for 1 year. Not super long-term, but better than 6 weeks: http://www.mozilla.org/en-US/firefox/organizations/all/ http://www.mozilla.org/en-US/firefox/organizations/all/
- gtaylor 13y agoOn the flipside, a frequently updated browser that is constantly improving is a bit of a moving target. Because of the ease for them to push out updates, vulnerabilities can be fixed and pushed out to the vast majority of users in short order. Malicious people may only get a few days/weeks to wreak havoc at a large scale, as the vast majority will have updated shortly after the problem is fixed. In Forefox's case, the frequent releases more have to do with rapid improvement and iteration than anything. Read the changelog and notice how it was largely a bunch of mid-moderate improvements. Some CSS goodies, some JS goodies, some security goodies.
- fabrice_d 13y agoNote that we don't wait 6 weeks to push security updates when there is any serious issue. We do "chemspill" releases in these cases to fix the problem as soon as possible (usually less than 2 days after it's reported).
- gtaylor 13y agoAnd I am thankful for this! You guys do great work.
- iambateman 13y agoIf you want a browser that is released once per year...be my guest: http://www.apple.com/safari/ http://www.apple.com/safari/
- nly 13y agoI think that's a false dichotomy. High profile targets like FF aren't going to survive without frequent updates, regardless of feature bumping releases. Personally I wouldn't want to have to go back to convincing people to upgrade between major releases again, and thus far Mozilla has kept FF pretty stable so I see no reason to worry.
- cpeterso 13y agoWhat browser do you use now? I recommend Firefox's Extended Support Release, which receives only security updates for twelve months
- yeukhon 13y agoFalse logic. Slow update does not mean you have secure version. You can get ESR if you want the so-called LTS version. Freqeunt update addresses multiple things quickly: (1) security vulnerability, (2) performance regression (3) new features For a software widely used like FF, it is important that they keep the software up-to-date, make the software as slim as possible, and make the software easy to use. If you want to do some "AB" testing, frequent testing is necessary. When was the last time you boot up Ubuntu LTS and think "oh I need to update?" Browser tends to move fast and break fast because browser is a complex software and because the tool people use to make web application are so flexible there are so many corner cases (which can be abused to use to make things work) it is hard to have a dead version. I look at the CentOS machine yesterday and I thought "god, where is the shiny webconsole that FF comes with?" CentOS apparently comes with old FF and I had to force to upgrade to 26.
- nfoz 13y ago> Slow update does not mean you have secure version. This was not my claim. When there are security vulnerabilities I'm happy for the updates to be as quick as possible and as frequent as necessary. The problem is: > (3) new features Adding new features has a high chance of new security flaws, when you're operating at the speed of firefox on such an error-prone technology stack. Different users want to meet this trade-off differently. I want fewer features, in fact I'm ok not to be bleeding-edge compatible with the latest poorly-designed HTML draft spec if it means a more secure browser. It's a question of how and where Mozilla (or other browser teams) organize their effort.
- yeukhon 13y agoYou have to take a couple things into account. 1. FF is a product, meaning if Chrome or Opera or Safari have some shiny features that a lot of developers enjoy to have, FF will very likely implement that feature. 2. Some new features are to replace the old one. For example, the original Firefox sync was pain in the ass and so there will be a new thing called Firefox Account. That's a new feature to user but it's easier to use and makes more sense to users. 3. Some new shiny features are there because of requests. People requested them and developers thought they were useful for users to have. That's inevitable. Unlike Windows, unless you cry to TechCrunch, MS won't care about your email because it's one of the 1000000 emails they receive every day. In reality, software can't stay in the way the old OS works. Granted, we take Android fun as they roll out new features. But we can't upgrade easily because the phone manufacture and/or the service provider does not provide the stock upgrade (at least this is how my shitty phone works). I know there are compatibility breakage and some UI decisions are really really bad. For instance, the latest nightly rolls out a different color scheme for web console which I find a huge problem for people with poor eye sight (me) or work long hours. The UI is changing to australis soon (maybe 29, maybe 30, don't remember, they haven't have a final decision yet). It is actually quite frustrating to work in the browser side. A line of change can impact millions of websites. Often time you have to make a complex patch to make simple adjustment. Regarding security vulnerability, I personally think they are minor compare to other more common, cheap threats. They are exploitable (and yes some are critical and severe) but when was the last time you find yourself exploited because of browser? It was probably you downloading an infected file. I know this is kind of unethical to say, but I think it is fair to say browser is quite secure these days and attackers are more likely to do things like clickjacking. I don't remember if Firefox rolls out update (not upgrade) that includes vulnerability fixes or not. Someone correct me on this.
- dangayle 13y agoHow did that work for the TOR browser? It didn't.
- jlgaddis 13y agoI assume you're referring to the Firefox vulnerability that was exploited to attempt to identify users of the Tor Browser Bundle? FWIW, that had also been fixed by the Tor Project and a newer version of TBB was available. The users who had upgraded were not vulnerable.
- dangayle 13y agoYes, that's what I was referring to. I was unaware that a newer version had been available that had addressed that issue. It's hard sometimes to plow through the FUD to know exactly what happened. Thanks.
- twobeard 13y agoIt's a good thing? Yeah, except that you waste half an hour EACH DAY staring at automatic software updates. At this point I simply disable automatic updates for much of the programs on my PC. This fashion of quick release cycles has gone way overboard.
- iamjustin 13y agoOh my god, that's ridiculous. Nobody spends half an hour a day waiting on auto updates. The update downloads in the background and takes just a few seconds to install after restarting the browser.
- pekk 13y agoThen Flash prompts for an update, then Acrobat Reader, then Java...
- zebulom 13y agoThen Mozilla Thunderbird, then TortoiseGit, then TortoitseSVN, then Sublime Text Editor, then Notepad++, then Notepad++ informs me there is an update of a plugin that I never use, then VLC media player, then Google Chrome, then Oracle VirtualBox, then Visual Studio proudly announces a service pack, then Windows informs me that it wants to reboot in 10 minutes.
- ams6110 13y agoHave to give a lot of the credit to Google. Before Chrome, Firefox was floundering. Updates were painful. Chrome competition eventually got Firefox refocused. Chrome also pioneered rapid release cycles and auto-updating so that users didn't have to consciously think about being "ready" to update or find reasons not to. Hopefully they don't even notice. Google's stated reason for developing Chrome was to push web browsers forward as a platform. Whatever you think of Chrome now, I think in that objective they succeeded admirably.
- bloodorange 13y agoNot at all mate! I love Mozilla. If you look at what has come out of their efforts over the last year, you'll probably see why I said that: https://blog.mozilla.org/blog/2013/12/16/mozilla-in-2013/ https://blog.mozilla.org/blog/2013/12/16/mozilla-in-2013/