Slashdot Mirror


Mozilla Announces Long Term Support Version of Firefox

mvar writes "After a meeting held last Monday regarding Mozilla Firefox Extended Support Release, the new version was announced yesterday in a post on Mozilla's official blog: 'We are pleased to announce that the proposal for an Extended Support Release (ESR) of Firefox is now a plan of action. The ESR version of Firefox is for use by enterprises, public institutions, universities, and other organizations that centrally manage their Firefox deployments. Releases of the ESR will occur once a year, providing these organizations with a version of Firefox that receives security updates but does not make changes to the Web or Firefox Add-ons platform.'"

31 of 249 comments (clear)

  1. Good by Anonymous Coward · · Score: 5, Insightful

    This is a nice solution to the problem everyone has been complaining about.
    I really see no complaints to this move.

    (inb4 shill)

    1. Re:Good by freedumb2000 · · Score: 4, Insightful

      I hope they will do the same for Thunderbird.

    2. Re:Good by deadsquid · · Score: 4, Informative

      The Thunderbird team is talking about an extended support released on their mailing list. There's more info on the Mozilla Wiki, but it is being planned.

      --
      Idiot, n. A member of a large and powerful tribe whose influence in human affairs has always been dominant
    3. Re:Good by Hadlock · · Score: 4, Insightful

      ESR's support is only for a year though, it seems? It might take institutions 2-3 months to decide it's worth upgrading to. A 2 year solution seems like a better, long term plan. In 2002-2009, having your web browser being a year out of date meant losing out on a lot of features and security fixes, but in the last 2 years innovations have really slowed down and I think 2 years support (as opposed to 1) would give institutions a lot more reason to stick to Firefox. Think of it - the many 4 year undergrad students (perhaps the less technically inclined student) would only have to experience one change in the web browser in their college career in school computer labs, etc. By changing this yearly, you're just adding another thing to the pile of the "annual make sure it all works together without crashing checklist".

      --
      moox. for a new generation.
    4. Re:Good by BZ · · Score: 4, Insightful

      Er... Browsers are adding security improvements and features at a much much faster rate now than in the 2002-2009 timeframe. This is true at least for Microsoft, Mozilla, and Google.

      In the specific case of Mozilla, it has about 60x more employees now than in 2002 (and 3x what it had in 2009). It would be _really_ odd if improvement rate were actually slower as a result, since the codebase was already quite mature in 2002.

    5. Re:Good by Hadlock · · Score: 4, Interesting

      I would assume LTS would include security fixes, but would be a feature freeze with only security updates (improvements)? Did I mis-read the blurb when it said "providing these organizations with a version of Firefox that receives security updates but does not make changes to the Web or Firefox Add-ons platform"?
       
      Honestly I could care less about most new features, 99.99% of the time features add extra clutter and are better executed as plugins anyways.

      --
      moox. for a new generation.
    6. Re:Good by BZ · · Score: 3, Insightful

      The LTS would include critical security fixes. It wouldn't include all minor security fixes or general architectural improvements that improve security-in-depth, because typically those have visible effects and the whole point of the LTS is to avoid such effects. Or put another way, "does not make changes to the Web or Firefox Add-ons platform" excludes a wide range of security improvements.

      To be more specific, fixing an exploitable crash is LTS material. Adding JIT hardening or process separation or something like HTTP Strict Transport security or UI changes to improve the ability of users to make informed security decisions are all not LTS material.

    7. Re:Good by RoLi · · Score: 4, Interesting

      Exactly!

      In fact I think they only did the Firefox-LTS version because people got the idea to fork it, not because they really listen to their users. Maybe somebody could threaten to do a Thunderbird-fork...

      However, Thunderbird is not as profitable (important) as Firefox. Firefox brings in AFAIK 100 Million/year while Thunderbird probably brings close to nothing.

    8. Re:Good by Hadlock · · Score: 3

      You've got to draw the line somewhere though. I would be very nervous to have a bunch of untested updates running around on my network, especially if my job/performance review/bonus depended on the quality of someone elses' untested code.
       
      I'm not especially keen to answer my boss about a security exploit in a new feature that ruined the company by saying "yeah we just let it update itself, i don't really get involved in all that. it seems to work ok most of the time, I'm sure we'll catch it in time NEXT time". At least in the real world if something happens you can fall back on "we're using the secure version that we've tested against known exploits; this new exploit was out of our hands. Since we're familiar with the software we have, we were able to reduce the damage by X".

      --
      moox. for a new generation.
    9. Re:Good by BZ · · Score: 3

      Oh, I understand perfectly why a managed deployment environment might want an LTS release, both to ease deployment and for the practical "well, we tested it against the things we knew about" bit.

      My point was that not updating your browser for 2 years right now will leave you with a browser that's considered hopelessly insecure by the standards of the day (not preventing entire new classes of attacks, etc), even if you patch actual exploitable security holes that come up.

    10. Re:Good by RebelWebmaster · · Score: 3, Informative

      There's a lot of work underway now to improve cycle collection times, which is where many of the pauses come from. Also, work is underway for both Generational and Incremental GC, which should improve things on the GC side. At least with a rapid release schedule, those improvements will ship when they're ready rather than waiting for other things to finish up first like they would have in the past.

  2. Enterprises Will Like This! by americamatrix · · Score: 4, Insightful

    This will be good news for Enterprises that want(ed) to deploy Firefox but didn't because of Mozilla's release schedule.

    Now if there was only a way to control/deploy this through group policy, then Firefox in the Enterprise will really take off.


    -th3r3isnospoon

    1. Re:Enterprises Will Like This! by grahamlee · · Score: 3, Funny

      Then, at some point in the future, Mozilla will run a campaign explaining that 10% of the interwebs is on Firefox 11 ESR, but there have been loads of new features and enhancements since then so we should all tell people to upgrade to Firefox 17. Friends don't let friends use IE 6^W^WFF 11.

    2. Re:Enterprises Will Like This! by acoustix · · Score: 4, Informative

      FrontMotion Firefox Community Edition has a MSI version that can be pushed out via GPO and also has adm/admx templates available.

      --
      "A plan fiendishly clever in its intricacies"- Homer Simpson
    3. Re:Enterprises Will Like This! by SteelZ · · Score: 5, Informative

      Now if there was only a way to control/deploy this through group policy, then Firefox in the Enterprise will really take off.

      Run "Firefox Setup.exe -ms" to do a silent install or if you must have a .msi, download it from these guys

    4. Re:Enterprises Will Like This! by Luckyo · · Score: 3, Interesting

      Not only this, but mozilla officially stated in their blog that they will actively work to prevent people from getting ESR version, so only the corporations have access to it "because it shouldn't be the fix for add-on breaking problem".

      Basically, "you will have the problems we shove down your throats and you will like them", once again.

    5. Re:Enterprises Will Like This! by deadsquid · · Score: 5, Informative

      It actually says "The ESR is specifically targeted at groups looking to deploy it within a managed environment. It is not intended for use by individuals, nor as a method to mitigate compatibility issues with addons or other software. Mozilla will strongly discourage public (re)distribution of Mozilla-branded versions of the ESR." Mozilla software will remain freely available. The ESR is not targeted at individuals, and the changes to addon compatibility (compatible by default) and updates (silent/background) in the next 18 weeks will hopefully address a lot of the issues people have with the regular release. In the end, it's up to the individual to choose, but the installers will be available to download if you really want them.

      --
      Idiot, n. A member of a large and powerful tribe whose influence in human affairs has always been dominant
    6. Re:Enterprises Will Like This! by Chaos+Incarnate · · Score: 3, Interesting

      "In the next 18 weeks" is about eight months too late for them to fix those problems. They needed to have all that worked out before Firefox 5.

      --
      Benford's Corollary to Clarke's Law: "Any technology distinguishable from magic is insufficiently advanced."
    7. Re:Enterprises Will Like This! by bigrockpeltr · · Score: 5, Funny

      This year will be the year of Firefox in the Enterprise!

      --
      $ unzip, strip, touch, finger, grep, mount, fsck, more, yes,fsck,fsck,fsck,umount, sleep
    8. Re:Enterprises Will Like This! by owlnation · · Score: 4, Insightful

      Absolutely correct. However, I wonder why Mozilla is trying to prevent the ESR version from having widespread access.

      There's no commercial gain in so doing, it's built anyway -- so people may as well use it, it won't affect support particularly -- just move questions perhaps. So where is the harm in giving people freedom of choice? Is freedom of choice not intrinsic in the philosophy of open source software?

      I suspect the only reason for limiting the ESR version is vanity and arrogance. FF's arrogant developers know fine well that the ESR version would quickly become the default version of FF out there. It is exactly what everyone wants, a stable version of the software without new, worthless, feature-bloat ever two weeks.

      FF developers, why not just have balls to admit you fucked up? Give people a free choice between ESR or the rapid-deployment constant-flux FF versions. See which people prefer -- and then run with that, and concentrate more on that version.

      Really, what is the fucking point on forcing your idiotic ideas on users who really want something else? That's why you are too cowardly to make ESR freely available. And we know it.

    9. Re:Enterprises Will Like This! by jdgeorge · · Score: 3, Insightful

      The reason for limiting the ESR version as much as they propose is almost certainly resource (people) limitations.

      By the way, insults to the actual developers who work on code for software that you evidently like (or presumably you just wouldn't care about this issue), only discourage those developers from being interested in your opinion.

    10. Re:Enterprises Will Like This! by broken_chaos · · Score: 3, Informative

      Uh, Chrome's even worse than Firefox when it comes to forced upgrades...

    11. Re:Enterprises Will Like This! by bendodge · · Score: 3, Insightful

      a chrome ripoff

      That. I wish I could buy a billboard in front of wherever Mozilla's people work and put up:

      If we wanted Chrome, we'd use Chrome. Bring back Firefox.
      Sincerely,
      Everyone who used Firefox before the versions numbers went haywire

      in MASSIVE text as a daily reminder of the old glory days.

      Seriously, I shouldn't have to rearrange and twiddle with everything to get Firefox as much like 3.6 as possible every time I install it. What true UI improvements have we had since then? I can think of two: tabs that don't resize while I'm hovering on them, and tab groups. Why was the rest of it randomized?

      Also, what's with the stupid launch defaults? I close Firefox when I want a clean slate, not a glorified minimize. "Restore my windows and tabs from last time" is antithetical to the whole idea of closing all the tabs! Can you imagine if Windows restored all your programs and junk from last time? People would come unglued.

      Also, we live in an age of large LCD displays. I can spare a few pixels of screen space to keep the bookmarks and buttons I use all day long visible instead of burying them somewhere underneath gloss and shiny.

      One last gripe: Tools > Add-ons should take me to Extensions, not the "Wonderful World of Stuff You Could Bloat Your Firefox With." I go to Add-ons to remove extensions other programs installed without asking far more often than I feel the urge to add bloviated toolbars. Speaking of which, can we finally make Firefox ask before allowing programs (like nearly every AV, Skype, whatever) to hang their useless (or worse, Google-search-invading) lampshade in Extensions?

      --
      The government can't save you.
    12. Re:Enterprises Will Like This! by dbug78 · · Score: 3, Informative

      Also, what's with the stupid launch defaults? I close Firefox when I want a clean slate, not a glorified minimize. "Restore my windows and tabs from last time" is antithetical to the whole idea of closing all the tabs!

      I've just spent 5 hours experimenting with customizing the installer for a company deployment and so I've repeatedly uninstalled and reinstalled Firefox, deleting %appdata%\Mozilla each time. Every time I started it up, it would open about:home and nothing else. It puts a button at the bottom of that screen to restore your last session, but that's it.

      Also, we live in an age of large LCD displays. I can spare a few pixels of screen space to keep the bookmarks and buttons I use all day long visible instead of burying them somewhere underneath gloss and shiny.

      The bookmarks toolbar? Click the Bookmarks button and check View Bookmarks Toolbar. In the time you took to whine about it, you could have turned it on and off 20x.

      One last gripe: Tools > Add-ons should take me to Extensions, not the "Wonderful World of Stuff You Could Bloat Your Firefox With."

      Again, based on my work with the installer today, it only defaults to Get Add-ons if you don't have any already installed. If you have extensions, it goes there by default. If you don't, what would the point of going there be?

      Speaking of which, can we finally make Firefox ask before allowing programs (like nearly every AV, Skype, whatever) to hang their useless (or worse, Google-search-invading) lampshade in Extensions?

      This was added in 8.0.

  3. ESR? by Anonymous Coward · · Score: 5, Funny

    I'm going to keep reading this as the Eric S. Raymond release.

  4. Did they fire Asa? by xenoc_1 · · Score: 5, Insightful

    This is still reactive damage control to foolish arrogance by Asa "we don't give a crap about enterprises" Dotzler.
    That's what you get why you hire a fanboy to become the voice of your company.

    1. Re:Did they fire Asa? by Rogerborg · · Score: 4, Informative

      Sadly no, the ADHD Kid is still jumping up and down and shrieking about how great it is that there are (at least) 4 major versions currently on the go. I only wish I were joking about that.

      --
      If you were blocking sigs, you wouldn't have to read this.
  5. Re:Oh good. ANOTHER browser to support. by Lennie · · Score: 4, Informative

    1. It is only one version to support and you can run it next to the latest version of Firefox. I would think this is a good thing if it keeps the people that do not what all those changes on the same older version instead of, some users on 6, some users on 7, some users on 8.

    2. What you are looking for is called the "Add-on Compatibility Reporter":

    https://addons.mozilla.org/en-US/firefox/addon/add-on-compatibility-reporter/

    It was obviously meant for a different purpose, so with that name it makes it kind of hard to find.

    --
    New things are always on the horizon
  6. Re:Oh good. ANOTHER browser to support. by deadsquid · · Score: 3, Informative

    The ESR is going to be based on Firefox 10 (which, incidentally, changes addons to be compatible by default), and most of the core rendering will not be affected. It is Firefox, but it won't get new features. It'll be "standard", but new additions will not be available, and that's a compromise that corporate deployment groups ere willing to make. Chrome's silent updates present the same problems to these orgs, in that the browser is changing rapidly and orgs have problems with testing and certification on the schedule.

    --
    Idiot, n. A member of a large and powerful tribe whose influence in human affairs has always been dominant
  7. Re:Hope they are serious by BZ · · Score: 3, Insightful

    Then you would be hurting those regular users, since the ESR will almost certainly be less secure than the regular version; the longer into its year of life you get the more this will be true.

  8. I kind of like Mozilla fumbling... by HBI · · Score: 5, Interesting

    My reasoning is as follows: I don't want to be using what the mass of the Internet is using in terms of browser. I want something with strong plugins and the ability to filter out dynamic code embedded in pages. That means Firefox.

    When it looked like Firefox was going to gain 50% share, I was worried. First, my browser gets targeted. Second, people would be motivated to detect and block those using the script and ad blocking plugins I use. The decline in FF market share is pretty good news to me.

    Keep at it, Asa!

    --
    HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.