Mozilla: The Good And The Bad
Rui del-Negro writes "According to this article at The Register, six security flaws in Mozilla were posted to BugTraq last weekend. They have not been added to the official Mozilla vulnerability list yet. But details can be found here, here, here and here (phew!).
Finally, two other bugs were found, relating to loading GIF files (in several Linux browsers) and Mozilla's (JavaScript) implementation of onUnload ( ).
Are they trying to prove they can beat Microsoft at their own game..? Or is someone just trying to win a prize?" On a brighter note, Zerbey writes "From Neil's Place here is 101 Things Mozilla can do which IE cannot. Very interesting reading and an excellent resource for convincing stubborn Internet Explorer users why they should switch. This article was also reported at Mozillazine. I'm still waiting for NTLM auth to be implemented so we can switch over at my workplace, the only reason we still have to use Internet Explorer."
OK, 21669 to go :-)
Trolling using another account since 2005.
As of 1.2beta almost all of these are fixed. In general opensource is not a whole lot more secure than closed source (both are programmed by humans), they just are more open with information and quicker with fixes.
There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
"...resource for convincing stubborn Internet Explorer users why they should switch..."
Should be:
- Provides a better subjective browsing experience
If that's not true, you'll never win.If you read ALL the way to the end of the article you'll note that 5 of the 6 bugs are already fixed in 1.0.1 which has been out for a couple months now. I believe the sixth is already fixed in the 1.2 nightlies.
However, also according to the article on the register, most of these bugs are in Mozilla 1.0, which makes this kind of old news. Mozilla 1.0.1 was specifically advertized as a security bug-fix release, and has been out for quite some time.
What a fool believes, he sees, no wise man has the power to reason away.
Now, is there a 10 Things IE Can Do That Mozilla Can Not such as run ActiveX properly if at all so one can go to most msn.com sponsored sites such as MSN Chat? Or how about properly running the Java plugin so Yahoo! Chat doesn't crash after a few minutes. I'm not making this up. This happens everytime.
Believe me, like the rest of you, I love Mozilla, and I live by the tabbed browsing. But unfortunetly, there are a lot of things I do on the Internet that still force me to crawl back to IE.
the Windows version is hurting
That's strange because I've found that Mozilla is more stable and faster in Windows vs. its Linux couterpart.
my other penis is a vagina
How my favourite bug was turned into a feature is the best example I have of how easy it is to get off the track with big projects like this.
The bug got lost in several threads, flames and arguments about what IE does or does not do, until it was finally marked WONTFIX by a Mozilla demi-god. IMHO, they missed the point. There is a constant refrain in Bugzilla about whether something is "standard" or not.
From my experience, the argument about web standards is used to either fix or not fix something, depending on how someone feels about a problem.
Don't think it's a problem? don't fix it and say "it's not standard, so we won;t" or "it's not standard, but we break the standard everywhere where it makes sense". Some behaviour need changing? The same arguments apply.
I may be just whining here, but sometime I think the fact that Mozilla is a web browser is lost in the arguments. I still love Moz, but the fact that the right-margin jumps around on my otherwise fine HTML 4.x and CSS pages will always bother me.
-- clvrmnky
Yeah, imagine that, the Evil MS notifies customers that an update is avaliable, but the wonderful Mozilla organisation has people visiting the site looking for an updated version or patch. I know that my family at least finds that much easier because they have a deep interest in what web browser they use to browse the interweb...
If you're gonna complain about MS, at least use a valid argument, god knows there's a lot of them, but the kneejerk whining about MS being evil doesn't really do any good for anyone.
Wax-Museum Fire Results In Hundreds Of New Danny DeVito Statues
Here's a link. On November 6, 2002, there were 31 security vulnerabilities in Microsoft Internet Explorer
The link is taken from: Windows XP Shows the Direction Microsoft is Going.. If Spanish is your native language: Windows XP muestra la dirección que Microsoft está tomando.
With some sites, yes. If they don't support the Mozilla certificates, they won't allow https. I use Mozilla for my Banking (switched banks because they supported Mozilla) and things like Hushmail. For some things at work, I still have to use IE for sites that don't support Mozilla's certs.
"History doesn't repeat itself, but it does rhyme." Mark Twain
How sad. You don't 'talk' to a support technician with Mozilla, but you can usually get in contact with the person who actually wrote the code that's giving you trouble. Personally, I find this preferable to sitting on hold, paying through the nose for phone support, and talking to someone who hardly has the technical knowledge to use a computer, let alone code a browser. Mozilla's problems and bugs are well-documented; IE's are well-hidden. Mozilla has an excellent secuity track record; IE's security track record can be seen by the seemingly endless stream of advirories and patchs.
It's a shame that these Fortune 500 companies choose inferior products with inferior support on the basis that they're able to hear a human voice when there's some sort of problem; regardless of whether or not that human voice has the slightest understanding of the problem, the solution, or even the product.
-- "Government is the great fiction through which everybody endeavors to live at the expense of everybody else."
1. You can do this by writing a 12 line VB app that embeds the MSHTML COM control on separate tab controls. Some projects already do this. (Yawn)
5. uh, hit ctrl-H in IE6
7,8. Hold control, scroll mouse-wheel
17. IE does this
22. This can be set in IE
31. IE can do this
46. Is this a joke ?
77. I don't buy this. IE is a ship-component of Windows XP, and thus exists in 25 distinct locales.
97. This is just fanboyism. There is no substance here.
101. Got me there, champ.
These are just the things I know are crap off the top of my _head_. Why does fanboy shit like this make it to slashdot on such a consistant basis ?
My opinions are my own, and do not necessarily represent those of my employer.
I've found that the Bugzilla for Mozilla, Newsgroup usefulness, and general web resources are better, or at least equal to, that of Microsoft. Microsoft has an edge with phone support but, I run 10 servers and 50 workstations, all running Microsoft with SQL, Exchange, NT, 2000, and more - and I've never had to call them. I won't.
I dread calling them. It costs money, immense amounts of time, and I would sit on hold just knowing I'd end up with a moron who would suggest that I try rebooting.
This notion that a software company must be responsible for it's software, so that someone can be held liable and can be counted on to help, is really just dependency and lack of personal responsiblity, and ultimately a crutch. MCSE means Must Consult Someone Else.
Perhaps Fortune 500 companies ARE Fortune 500 companies because they pass the task of software support and maintanence off to the companies that make the software, and focus on their core business.
But they're also the ones spending obscene amounts of money and time trying to understand Microsofts insane licensing policies.
They're spending time and money evaluating Microsoft's DRM moves, preparing to deal with the inevitable (some would say immediate) consequences of Microsoft's negative, condescending attitude toward it's customers.
They're the ones who woke up one day and realized they were renting software, not buying it, and that they have an evil landlord and can't do anything about it. They're just happy their investors also like Microsoft so that they percieve this dependency as a "strategic relationship". They're the ones subject to the whip hand.
I've never walked into a Fortune 500 company and seen Mozilla. I've also never let the public see me having sex. Neither of those means that it doesn't happen.
# Erik
Look.
Microsoft notifes us *when a patch is available*.
The Mozilla community notifies us *when a security flaw is found*.
Do you want to know about a problem when it is discovered, or after someone has already engineered a fix?
If your car was discovered to be prone to stopping dead on the highway and blowing up, you'd want to know before the manufacturer figured out how to make it stop doing that. You'd want to have the option of choosing to risk it, or parking the car and driving something else for a little while.
Now you know what activies are prone to security dangers, and can either avoid those activities or use another browser for a while.
...
"Supports blinking text
You can make text blink."
*blink*
This is GOOD?
In particular, if I wish to have Spanish-language dialogues in Mozilla, I (as of a month ago) can not upgrade to Mozilla 1.0.1 because none of the volunteer Spanish translation teams [1] has updated their 1.0.0 translations to version 1.0.1; instead they chose to direct their translation efforts towards 1.1 and 1.2.
Compare this to AbiWord, which has a translation structure such that, if a given translation team decides that meeting girls at dance clubs is far more fun than spending Saturday night translating dialogues, the translations still work for new versions of the program. If any new dialogues appear, those dialogues will be in English until someone steps up to bat to translate them, but any unchanged dialogues remain translated.
IE has an edge here, since their translation teams are paid; guaranteeing that any formal release of IE will be translated in to all officially supported languages. The disadvantage to this is, if a given language is deemed by Bill Gates to not be worthy of translation, you have to use the application in English (or one of the other official languages).
This structure causes Mozilla 1.0.1 to have translations available in languages like Estonian (a beautiful language [2] which has about, as I recall, 2 million speakers) but not in Spanish (which has more native speakers than English--about 325 million).
OK, thinking out loud, it should not be too hard to set up a perl script which unzips a translation for a given version of Mozilla, compares the labels against the English version for a given later version of Mozilla, and then translates all of the labels it can; leaving the untranslated labels in English. This would be far more productive than posting to Slashdot; perhaps a Mozilla guru can tell me if a tool like this already exists.
- Sam
[1] There are three Spanish trnaslation teams: One for Latin American spanish, one for Argentinian Spanish, and one in Spain. The Argentian is the most active group right now.
[2] One of my linguist teachers is a native Estonian speaker; she once talked to us in Estonian to demonstrate a language learning technique.
The secret to enjoying Slashdot is to realize that it should not be taken too seriously.
2) View source opens notepad. I want to be able to edit, save (without it downloading the damn thing again!), and whatever.
File --> Edit Page
I'm sure there are security bugs in Mozilla that haven't been made public yet. That was the problem with the onUnload(). It was known about for a long time, but not until it became public did it get fixed.
The main reasoning seems to be that vendors should be able to protect their customers.
But what happened with the privacy leak recently found in Mozilla? Granted, it was a minor glitch, but it is nevertheless useful in studying how policy affects security.
Did it help end users that it was marked sensitive? Well, Netscape knew about the glitch when they shipped their browser, yet, they shipped it. On the other hand, the leak was patched shortly after the story broke, so the answer should be a clear "No!"
This is an example that it is not sufficient to have the sources open, you have to get some light onto the problems too.
Employee of Inrupt, Project Release Manager and Community Manager for Solid
My favorit
My favorite bug is wh
My favorite bug is when mail cras
My favorite bug is when mail crashes whenever I tr
My favorite bug is when mail crashes whenever I try to sen
My favorite bug is when mail crashes whenever I try to send a message
It's 10 PM. Do you know if you're un-American?