Slashdot Mirror


10-Day Patch Guarantee Not Mozilla's Policy

narramissic writes "Mozilla has officially backpedaled from a pledge made at Black Hat by the company's director of ecosystem development, Mike Schaver, to fix any critical security bugs in the browser within 'Ten ****ing Days.' On Friday, Mozilla security chief Window Snyder wrote in a blog posting that the 10-day pledge is not Mozilla's policy, saying 'We do not think security is a game, nor do we issue challenges or ultimatums.' And today, the open source browser maker issued a statement retracting the pledge."

4 of 125 comments (clear)

  1. Mozilla Corporation becoming truly corporate? by paulius_g · · Score: 2, Interesting

    For me, I always thought that Mozilla was a small and nice open source company. These days, it feels to me as if Mozilla is starting to blend into the corporation scene just like any other evil corporation. The whole Firefox naming debacle on Debian, and now this. Now that they're controlling a big market of the web browsers space, should we continue trusting them? Would it be time to look at Konqueror or other browsers?

    1. Re:Mozilla Corporation becoming truly corporate? by Anonymous Coward · · Score: 4, Interesting

      Yeah, that explains why all those Linux(TM) distributions can't use the trademark "Linux" - after all, almost all of them patch the Linux kernel. Or why the distributions have to rename KDE or GNOME. Or any other piece of open source software.

      No, the reason Mozilla forced Debian to rename Firefox is even stupider than that. Debian fixed their build process. They didn't actually patch the browser. They simply corrected the build process to work under Debian. That was enough to prevent them from using the name "Firefox".

      Personally I can't wait until WebKit and Konqueror finish remerging code. Once Konqueror gets a Windows build, it's game-over for Firefox. It's a better browser - it just hasn't, until recently, run on Windows.

    2. Re:Mozilla Corporation becoming truly corporate? by _Sprocket_ · · Score: 4, Interesting

      No, the reason Mozilla forced Debian to rename Firefox is even stupider than that. Debian fixed their build process. They didn't actually patch the browser. They simply corrected the build process to work under Debian. That was enough to prevent them from using the name "Firefox". Is it just that, though? Before the whole Icedove rename, I had two copies of Firefox on my Debian desktop. One was the Debian package. The other was from Mozilla. I had the Mozilla version because something broke in the Debian package. It had something to do with my laptop's Xorg config (I have a config that allows dual screens when docked and just the single screen when not). When it wasn't docked, Debian's Firefox would run but wouldn't show. The Mozilla version came up without a problem. I could never figure out why (wish I could - then I would have filed a bug report).

      I bring this up because this was going on around the same time the whole rename issue was getting a lot of attention. It seemed to me that Debian was introducing changes that Mozilla wasn't - as demonstrated by my own odd behavior of the two Firefox installs. Of course - I don't know enough about the bug I had or the issue in general to really know for sure. Maybe someone else can take a swing at it?
    3. Re:Mozilla Corporation becoming truly corporate? by moosesocks · · Score: 1, Interesting

      Sure, Mozilla's trademark is pretty stupid.

      However, FireFox is still the superior browser in many cases. WebKit's javascript and CSS implementations are incomplete in several cases. It's not as common as it used to be, but there are still a few sites that will legitimately work in Firefox, but not Safari or Konqueror.

      --
      -- If you try to fail and succeed, which have you done? - Uli's moose