Slashdot Mirror


Mozilla To Drop Support For All NPAPI Plugins In Firefox 52 Except Flash (bleepingcomputer.com)

The Netscape Plugins API is "an ancient plugins infrastructure inherited from the old Netscape browser on which Mozilla built Firefox," according to Bleeping Computer. But now an anonymous reader writes: Starting March 7, when Mozilla is scheduled to release Firefox 52, all plugins built on the old NPAPI technology will stop working in Firefox, except for Flash, which Mozilla plans to support for a few more versions. This means technologies such as Java, Silverlight, and various audio and video codecs won't work on Firefox.

These plugins once helped the web move forward, but as time advanced, the Internet's standards groups developed standalone Web APIs and alternative technologies to support most of these features without the need of special plugins. The old NPAPI plugins will continue to work in the Firefox ESR (Extended Support Release) 52, but will eventually be deprecated in ESR 53. A series of hacks are available that will allow Firefox users to continue using old NPAPI plugins past Firefox 52, by switching the update channel from Firefox Stable to Firefox ESR.

163 comments

  1. Making Firefox GREAT Again by Anonymous Coward · · Score: 0, Flamebait

    Thanks Trump

  2. Firefox 53 won't be an ESR by NotInHere · · Score: 1

    ESR releases are only all 7 releases. So the one after firefox 52 will be 59.

    1. Re:Firefox 53 won't be an ESR by Anonymous Coward · · Score: 0

      ESR releases are only all 7 releases. So the one after firefox 52 will be 59.

      This might have something to do with why they are doing 2 back to back ESR's. https://news.slashdot.org/story/17/02/04/0516249/mozilla-binds-firefoxs-fate-to-the-rust-language

  3. Context please by ebonum · · Score: 2, Insightful

    I must be an idiot. I read TFA and I have no idea if AdBlock Plus, Ghostery, NoScript, etc. will continue to work.
    What will break? What will continue to function normally?

    1. Re:Context please by Anonymous Coward · · Score: 4, Informative

      I must be an idiot. I read TFA and I have no idea if AdBlock Plus, Ghostery, NoScript, etc. will continue to work.
      What will break? What will continue to function normally?

      There is no talk of removing support for extensions. This is only about plugins.

    2. Re:Context please by Anonymous Coward · · Score: 1

      Those are all addons not plugins. But fear not, Firefox is disabling a bunch of my favorite addons soon.

    3. Re:Context please by caseih · · Score: 1

      The chrome (in the mozilla sense of the word) add-on system is different from the NSAPI system. Add-on extensions are programmed in Javascript and can be seen by going to about:addons

      Right now the only NSAPI plugins listed are the flash plugin, the Java plugin, and a plugin from Rhythmbox that is supposed to handle itunes urls or something. None of these things I use, and all of them are disabled in my browser using the QuickJava add-on. You can see your plugins by going to the url about:plugins

    4. Re:Context please by Anonymous Coward · · Score: 4, Informative

      actually there is (more than) talk to remove extensions, well replace them with a new standard
      coming in ff 57
      it'll break a lot of nice extensions
      http://www.ghacks.net/2017/01/28/firefox-add-on-quicksaver-quits/

    5. Re:Context please by fuzzyfuzzyfungus · · Score: 1

      If Flash is being whitelisted; the main news will be Java applets(much rarer than they used to be; but a distant second to Flash in the embedded-blobs-of-stuff-that-can't be done in HTML, at least not when this site was built market); maybe Shockwave; if anyone still uses that; and then mostly shitware(at least at one point, Acrobat or Acrobat Reader would install something to grab PDF handling, some AV packages would inject their little contribution; Cisco has a hilariously vulnerable Webex support plugin that makes joining webex sessions incrementally easier and remote code execution a lot easier).

      There really just isn't all that much anymore(which is presumably why FF is doing it; and why Chrome already did). Much as Oracle is a bit petulant about it(just visit the java download page in Chrome to see a nice little whine about how Google 'disabled the standard plugin mechanism'); relatively few people care; Flash is still hanging on; but Shockwave is pretty much dead; and most of the seriously hardcore legacy cases, the ones that will probably outlive some of us now talking about it; tend to involve ActiveX somewhere; so NPAPI plugin support is irrelevant; because NPAPI-only browsers never worked; and if they also need Java or something it continues to be available as an ActiveX plugin.

    6. Re:Context please by AmiMoJo · · Score: 2

      No, add-ons as they are called will be fine for now. This API is only for binary plug-ins like Flash, Java and Adobe PDF Reader.

      Binary plug-ins are much more vulnerable because they are native code and run in the browser process. Add-ons are Javascript and run in the Javascript sandbox, although in Firefox they can really screw with the browser's security model which is why Mozilla is wanting to move away from them eventually.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    7. Re:Context please by Anonymous Coward · · Score: 1

      Those addons you listed are all "extensions" - they will continue to work.

      What's being disabled is NPAPI plugins, an older type of addon (from back in the Netscape days, before Firefox even existed - NPAPI stands for Netscape Plugin API). For the most part, the only plugins most people use are Flash (which being whitelisted) and the Java plugin (which you shouldn't be using anyway, because it's full of security problems). So no need to worry - this probably wont affect you at all.

    8. Re:Context please by Anonymous Coward · · Score: 5, Insightful

      And the day they follow through on it, is the day they for real die, despite all the propaganda floating around already about how "buggy" and "leaky" and "useless" it is. I've never had any such problems with Mozilla, but the day they kill ublock, noscript and other such necessary add-ons, and replace them with substandard, neutered google-crap, is the day not only I have absolutely no further use for them, it's the day they have actually lost the entire point of their existence.

    9. Re:Context please by Pentium100 · · Score: 1

      Java applets(much rarer than they used to be

      It seems to me that a lot of servers use Java for remote management (IPMI, ILO, DRAC...), either for everything or just remote KVM. Some networks switches (D-Link for example) also use it, at least for the live monitoring on the web interface.

      I rarely see Java used on the public internet though. Still, I guess I'll have to stop updating firefox so as not to break compatibility with the Java stuff that I have to use.

      Java already whines enough, no need to add even more inconvenience.

    10. Re:Context please by Anonymous Coward · · Score: 0

      This is already happening in Palemoon with jetpack being dropped. I will miss Decentraleyes

    11. Re:Context please by thegarbz · · Score: 1

      I read TFA and I have no idea if AdBlock Plus, Ghostery, NoScript, etc. will continue to work.

      An easy estimate at the damage would be: Does this plugin exist for Chrome? If yes, it will either continue to work or be ported across (I mean they have had a LOT of notice).

    12. Re:Context please by Anonymous Coward · · Score: 0

      The stuff that appears under Plug-Ins (in the Add-Ons manager) will stop working; the stuff that appears under Extensions will not. All the popular add-ons for Firefox are Extensions, which won't be affected by this change.

    13. Re:Context please by r1348 · · Score: 1

      Plugins extensions

    14. Re:Context please by Anonymous+Brave+Guy · · Score: 2

      Still, I guess I'll have to stop updating firefox so as not to break compatibility with the Java stuff that I have to use.

      Sadly, I doubt you'll be alone.

      I work with a lot of networked devices, which is a common environment where Java in a browser still matters. While there are now alternative technologies that can be used for much of what we used to use Java for, people should remember that they have only quite recently become stable and reliable enough for long-term professional use in an embedded context, and even today, there are plenty of bugs and performance problems with both canvas and SVG, so they're still not a perfect replacement if you had an applet for some graphical presentation purpose. Obviously it takes time to develop new versions of these UIs and then time for customers to purchase and deploy them, so expecting these embedded systems to be upgraded before the next major hardware/firmware upgrade cycle is unrealistic.

      Another case where Java applets are still useful is all the little demo pages, again typically graphical ones, that the academic community has written over the years. I came across one of them just this weekend, and was glad that I was using Firefox instead of Chrome so I could still watch them. It's a horrible shame that access to all of this content, much of it developed over two decades but as relevant today as ever, is being lost just because the browser developers and Oracle couldn't get their acts together. This isn't how the Web was supposed to work, no user benefits from the loss, and there's no magical fairy who's going to come along and rewrite all of these pages using shiny new HTML5 standards just because Google and Mozilla would prefer it if Java went away.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    15. Re:Context please by Anonymous Coward · · Score: 0

      Never heard of him or any of his add-ons, Dumb as hell to quit instead of learning the new language. Thats like quitting Windows because DOS is no longer supported.

    16. Re:Context please by arglebargle_xiv · · Score: 1

      There is no talk of removing support for extensions. This is only about plugins.

      And they're specifically keeping the least secure plugin there is, while disabling all the others. Thanks, Mo://http:://a.

    17. Re:Context please by Anonymous Coward · · Score: 0

      uBlock was a Chrome extension first, then ported to Firefox; given that their new system is supposed to be compatible, that would probably keep working. It is unclear if NoScript would continue to work.

    18. Re:Context please by MrL0G1C · · Score: 1

      100% agree, I use Firefox because of the extensions, killing extensions is killing Firefox.

      --
      Waterfox - a Firefox fork with legacy extension support, security updates and better privacy by default.
    19. Re:Context please by fyrewulff · · Score: 1

      Nah. It'll be the day Firefox doesn't need to die with every upgrade because the old extension structure was more or less direct access to every little nook and cranny, which sounds like "full power" but really meant that the bigger the extension was, the more it was (for all intents) rewriting Firefox.

      The newer style doesn't have breakage, has proper privilege separation, process separation, etc etc, and the browser itself won't break everything because of Dave's Way Cool Website Toolbar.

      And you still have the actual freakin' source code if you want to make internal changes to the browser.. which will also be more stable, and upstream to everyone if it's a cool idea.

      --
      "We need to get over this notion, that, for Apple to win... Microsoft must lose." - Steve Jobs, 1997
    20. Re:Context please by drinkypoo · · Score: 1

      It's a horrible shame that access to all of this content, much of it developed over two decades but as relevant today as ever, is being lost just because the browser developers and Oracle couldn't get their acts together.

      Uh no. It's because the academics jumped on a language encumbered by shitty licensing agreements. They had a choice, they could have made javascript pages, but instead they used Java. Anyone could see that Sun had too much control over the language, and later, that Oracle exerted even more. Well, anyone thinking. Academics often think only about what they want to think about, and nothing else seems important. Well, guess what? It is, since we live in the really real world.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    21. Re:Context please by Anonymous Coward · · Score: 0

      use Opera presto,no problem

    22. Re:Context please by Anonymous+Brave+Guy · · Score: 1

      They had a choice, they could have made javascript pages, but instead they used Java.

      You could draw interactive diagrams, or animate them, in JavaScript in the year 2000? It was difficult enough doing these things in JavaScript ten years later! The reason the <applet> tag existed was that Java was the standard way to do things beyond what basic HTML could handle for a long time before.

      As for too much control, I invite you to consider that the likes of Apple, Google and now Mozilla have been successfully killing off access to useful content that has existed for 10-20 years for their own purposes, while encouraging us to instead use perma-beta web "standards" that have about as much stability and longevity as a drunk riding a unicycle over a beach ball floating towards a waterfall.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
  4. Mozilla...getting it wrong so you don't have to. by Anonymous Coward · · Score: 5, Insightful

    "We have announced today that we will be dropping support for all plugins, except the one that's really the problem judging by the security advisories. You can expect your specialty software to stop working immediately, while the security-hazard that is Flash will continue to work for several, pointless version number bumps."

    If it weren't for mistakes the Mozilla Foundation wouldn't be good at making any fucking thing.

  5. Fuck you, Mozilla. by Anonymous Coward · · Score: 4, Insightful

    Blocking NPAPI, *execpt* the worst of them all, security ala mozilla, like we know it for years. Running out of ways to piss off every single admin on the planet, are we...?

    1. Re: Fuck you, Mozilla. by Anonymous Coward · · Score: 0

      It's quite simple. Don't use Firefox.

    2. Re:Fuck you, Mozilla. by TheRaven64 · · Score: 4, Insightful

      I don't know - between Java and Flash, it's hard to tell which has the worse security record. Though these days about the only Java applets on the web are malware, so at least you get a lower false positive rate by blocking them all.

      --
      I am TheRaven on Soylent News
    3. Re:Fuck you, Mozilla. by Anonymous Coward · · Score: 0

      People don't need flash to work - with java that's another story. But as usual, the zilla does not give a fuck, but in addition, they don't even have the balls to go through with it and simply remove NPAPI (which at least could be argued to actually better security), no, they just do to it what they did to the ssl/cert handling, fuck it up...

    4. Re:Fuck you, Mozilla. by NotInHere · · Score: 1

      That is in fact their plan. First remove all NPAPI plugins except flash, then move flash over to use PPAPI, then remove NPAPI support entirely.

    5. Re: Fuck you, Mozilla. by Anonymous Coward · · Score: 0

      Then what do we use? Chrome is basically unusable at this point due to the failure of Google to fix the freezes. I'm sure there are other options, but if you're not using Windows or OSX the options get rather limited.

      And most of the alternatives are little more than reskins anyways.

    6. Re:Fuck you, Mozilla. by Anonymous Coward · · Score: 0

      its a good thing you're not paid to use uh kum-pew-ter. i'll enlighten you on java use. many enterprise management applications require java in the browser. now go forth and fud some more.

    7. Re:Fuck you, Mozilla. by ArhcAngel · · Score: 2

      these days about the only Java applets on the web are malware

      You mean like Intercontinental Exchange's WebICE? A multi-billion dollar commodities trading platform.

      --
      "A person is smart. People are dumb, panicky dangerous animals and you know it." - K
    8. Re:Fuck you, Mozilla. by Tough+Love · · Score: 1

      many enterprise management applications require java in the browser

      They should have started converting those to Javascript long ago, it's not like they didn't know this was coming years ago. As a bonus, you get to not write Java, and not deliver a less than satisfactory end user experience with all the waiting around for mammoth Java applications to load and slowly jit themselves, and the generally crappy Java UI design because developing in Java is so cumbersome that you are pretty must stuck with the first piece of alpha crap that comes down the pipe.

      --
      When all you have is a hammer, every problem starts to look like a thumb.
    9. Re:Fuck you, Mozilla. by Anonymous+Brave+Guy · · Score: 1

      They should have started converting those to Javascript long ago, it's not like they didn't know this was coming years ago.

      That's... not how any of this works.

      For one thing, JS has only recently become a viable alternative for a lot of what used to be done with plugins. In many cases it's still relatively slow and/or buggy as hell.

      For another thing, it costs time and money to produce software, and big rewrites are notoriously expensive. Expecting people to just dump working software because it's inconvenient to continue supporting its platform is unrealistic.

      As for criticism of Java's speed, it takes longer to display Facebook than almost any Java-based management interface I've used in the past five years. Where do you think a lot of the JIT compilation technologies that are behind modern JS engines were first developed?

      Finally, while the Java language and ecosystem are far from ideal, with a JVM you can also write code in much more powerful programming languages if you want. And frankly, modern JS-based web development is such an unstable mess that almost anything else would be better for the kinds of long-term projects that typically used Java applets in the past.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
    10. Re:Fuck you, Mozilla. by AmiMoJo · · Score: 1

      Can't you just run the applet outside the browser, using the desktop JRE? Running Java in the browser via a plug-in seems like a silly way of doing it, and limits the app's UI quite severely.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  6. Flash by dschiptsov · · Score: 4, Insightful

    Which is the absolute champion in vulnerabilities exploited by hackers, tracking, malware and every possible kind of crap, including banners, which is the only reason it is still exist and pushed by the browser vendors.

    1. Re:Flash by Anonymous Coward · · Score: 0

      I'm proud to be in your basket of deplorables.

    2. Re: Flash by Anonymous Coward · · Score: 0

      I'm proud to oppose you. You openly support a rapist.

    3. Re: Flash by Anonymous Coward · · Score: 0

      Hit a nerve faggot? Why are most Trump support queer?

  7. Which ones are NPAPI by freeze128 · · Score: 1

    How do I tell which plugins are NPAPI? It really doesn't say under the plugins tab.

    1. Re:Which ones are NPAPI by squiggleslash · · Score: 1

      All of them. (Plugins anyway)

      --
      You are not alone. This is not normal. None of this is normal.
    2. Re:Which ones are NPAPI by Anonymous Coward · · Score: 0

      All the ones in about:plugins except the built-in ones (OpenH264 and Widevine), and also Flash.

      The ones in about:addons will continue to work until at least the end of the year, and will do so beyond that if they migrate over to using WebExtensions.

    3. Re:Which ones are NPAPI by Anonymous Coward · · Score: 0

      All. That's what the Plugins section is for.

    4. Re:Which ones are NPAPI by CByrd17 · · Score: 1

      Firefox has Add-Ons which are what most people are using in that browser. Things like Ghostery and Ad Block Plus.

      These are not plugins.

      In the future, Firefox will have extensions; just as Chrome does. In fact, they will be the same code.

  8. A Year of My Life Lost on NPAPI by glennrrr · · Score: 2

    5 years ago, part of my job was keeping an NPAPI plugin running on the Mac. Apple had transitioned their support to a new graphics and event model and it was a lot of work refactoring our plugin. And of course, that ended up being wasted time we should have spent transitioning to writing a Javascript version of our app.

    1. Re: A Year of My Life Lost on NPAPI by Anonymous Coward · · Score: 0

      oh and to add about my comment above advocating CGI application services, this to generate only html and not a python or perl module to do the same. Hell there are so many console tools that are pf the *2html nomenclature that would do anything custom.

      ontopic: O still have a harddrive i was saddened of years and tears that hasnt been recovered of a failed armature; full of all my original bookmarks and Slashdot discussion in the direction of VRML on Netscape (wasit v3 or v5 i dunno). Netscape crashed all the time in Linux if it wasnt a genuineIntel bullshit. LinuxFromScratch was a good try before Ubuntu. and VRML was a wtf on 3dfx and Matrox and nvidia hardware.

      Xgl or whatever from Sun Microsystems was what should be on Android, not this Google flakeware.

  9. But my business bank deposit Java app... by __aaclcg7560 · · Score: 1

    When Google Chrome pulled support for plugins on the PC, I had to use Mozilla Firefox for a Java app that my business bank uses for check deposits at home. Looks like that is going away. It'll be interesting to see if the business bank will move away from Java or keep it. I'll have to download the app on my iPhone.

    1. Re:But my business bank deposit Java app... by wvmarle · · Score: 1

      With Firefox and Chrome having over 2/3 of the browser market between them, your bank will have not much of a choice. Sooner or later nothing supports Java anymore and their plugin is simply obsolete.

    2. Re:But my business bank deposit Java app... by myowntrueself · · Score: 2

      With Firefox and Chrome having over 2/3 of the browser market between them, your bank will have not much of a choice. Sooner or later nothing supports Java anymore and their plugin is simply obsolete.

      There is still a lot of hardware out there and embedded systems that depend on Java for management eg KVM consoles. I know people who keep an XP virtual machine around just so they can manage certain pieces of hardware.

      --
      In the free world the media isn't government run; the government is media run.
    3. Re:But my business bank deposit Java app... by __aaclcg7560 · · Score: 1

      With Firefox and Chrome having over 2/3 of the browser market between them, your bank will have not much of a choice.

      Banks can be pretty stubborn. I did a Token Ring to Ethernet conversion project at a bank branch office in 2005. I was shocked to see Token Ring in the field. My previous experience with Token Ring was taking apart a NIC card to find an 80186 processor in 1995 and reading about them in certification exams prior to 2005. The five-year-old branch office had coaxial cables installed beside the already installed Ethernet cables. The bank was perfectly fine with 16Mbps for decades. The killer app for the conversion project was TV video. With 500 workstations at this branch office, 100Mbps Ethernet was required. I made an extra four hours of overtime because the high school kids plugged the Ethernet cable into the Token Ring NIC (which took coaxial and twisted pair) instead of the motherboard NIC and the project manager sent them home without checking their work.

    4. Re:But my business bank deposit Java app... by Anonymous Coward · · Score: 0

      With Firefox and Chrome having over 2/3 of the browser market between them, your bank will have not much of a choice.

      Many users (apparently about 40% if one extrapolates from 2013 - http://www.pewinternet.org/2013/08/07/51-of-u-s-adults-bank-online/ ) are still not the online-banking kind, likely stuck in the world of paper checks, offline payments to their utilities, and ATMs. Aren't chip and pin machine rollouts in the US more relevant to the recent bank effort to protect themselves financially from liability? I still don't get forced to use them, and IIRC the deadlines are long past.

      Remember when Y2K came and went, and support for dates was still broken?
      I remember seeing Excel dates showing a date in the form of something like
      x Month, x Day, year 19100

      "Not having a choice" when it comes to the mundane hidden world of browser support is still not quite relevant in reality.
      GP's bank will release an app (maybe) but only months after the breakage when enough of their users have been roaring and complaining for a while.

    5. Re:But my business bank deposit Java app... by ericlondaits · · Score: 1

      The argentine tax collecting agency still has critical parts of their web site (particularly the one where small business and independent professionals declare their gross income) that only work under IE6 due to use of MS-only javascript API. The "funny" thing is that with newer versions of IE you have to use the site in "compatibility mode" which with the latest versions has to be activated through the developer tools panel. The tax collection agency gives instructions on how to do this instead of fixing the site... while some enterprising folks have developed browser extensions that inject fixed versions of the scripts in the page. I use a mac and have to boot a VM with Windows every 3 months for this purpose.

      (The quality of argentine web sites is quite good by international standards... this site is just the worst shitstorm possible).

      --
      As a Slashdot discussion grows longer, the probability of an analogy involving cars approaches one.
    6. Re:But my business bank deposit Java app... by Anonymous Coward · · Score: 0

      If your bank is sticking to problematic software, tell them they stand to loose you as a customer.

      I did that when internet banking first took off in the nineties. And the banks liked to demand some specific version of "IE". This for "safety", so they knew what software was being used to do banking.

      So I wrote them a letter (on paper, not email) telling them
      1. There is no "safety" in the browser string. Even in those days, mozilla could be told to lie and claim to be IE - any version.
      2. Banking sites are not very special - the html works with any browser if they don't actively put up roadblocks.
      3. People who don't use windows can't use IE. They are a few percent of the customers. But even windows people may prefer another browser.
      4. Why turn away some (possibly small) percentage of the customers for a browser check that provides NO safety?
      5. Not checking the browser string is not extra work for them. They can support all customers - with LESS work on their part.

      And guess what, most banks understood this. I have switched banks twice. Only once to get away from software problems, and once to get a solution with significantly fewer fees. Banks have very little incentive to keep people on windows/IE - it means nothing to them. Customers migrating to other banks that don't have software hangups - now that is something. Even a percent or two of the customers is money. They have enough competition on fees and interest rates and foreign bank conglomerates - they don't need an extra way of loosing customers.

  10. webCGI over secureTelnet by Anonymous Coward · · Score: 0

    just pick a low performance html browser to obscure it's name as MyCompProgr, and just keep writing your main shit in C as an application server to dish out to clients.

    websites were supposed to be a compeying standard similar to Portable Document Format so whatis all this shit graduating to Java and AppleScript anf Flash?

  11. Mozilla business plan by alexhs · · Score: 1

    1.1 Drop feature
    1.2 Drop feature
    ...
    1.(n-1) Drop feature
    1.n Drop product altogether
    2. ???
    3. Profit!

    --
    I have discovered a truly marvelous proof of killer sig, which this margin is too narrow to contain.
    1. Re:Mozilla business plan by QuietLagoon · · Score: 1

      You forgot: 1.0 Add unwanted bloat

    2. Re:Mozilla business plan by wvmarle · · Score: 1

      MS has always been noted for its ability of turning bugs into features.

      It seems the Mozilla foundation has now found a way of turning features into bugs.

      Not sure which version I prefer.

    3. Re:Mozilla business plan by Anonymous Coward · · Score: 0

      You forgot: 1.0 Add unwanted bloat

      They're already working on that, ever since Firefox 50 memory use has gone thru the roof again.

      Mozilla have lost the plot, shame there's no real alternative :/

  12. That's why Firefox will forever suck by Doloresanto · · Score: 1

    Flash Player is the one to ditch first. Everyone is doing it, but not the ever slow (and not so free) Firefox.

  13. Flash was modelled after JavaScript by Anonymous Coward · · Score: 0

    JavaScript can at-least becustom-handled by NoScript, but Flash is the Secure JavaScript mode so needs an outside engine to run the shit without interference.

    and remember: never forget that tge crap we call media presentation in Flash or Javascript was all derived of a branch known as APPLEscript.

    All this nonunix shit problems werent from Macrosh1t Wangblows N1ggert Exploder but actual Apple Computing inspirations. Netscape and it's neighboring Mosaic engine browsers just need to cut out Javascript from descending as a 3rd testicle.

    1. Re:Flash was modelled after JavaScript by Anonymous Coward · · Score: 0

      Are you drunk or just severely lacking in mental acuity?

  14. No real benefits (only perceived ones) by admin7087 · · Score: 4, Insightful

    There really is no benefit in replacing native plugins with a strictly inferior technology - Javascript instead of the language of your choice and then removing the former. This is just another closing down of an ecosystem for the sake of nonexistent "security" under the obviously dubious presumptions that the developers of the base technology are more competent about security than plugin developers and that users need to be constantly patronized. Instead, they should open a native plugin technology to as many languages as possible and let people decide what language to use and which developer to trust.

    But you can see this trend everywhere. Less power to users and third-party developers and more control to the people who run the "platform".

    1. Re:No real benefits (only perceived ones) by Anonymous Coward · · Score: 0

      Javascript instead of the language of your choice and then removing the former

      Lucky for you WebAssembly is on the way. Compile whatever language you want to WebAssembly and run it in your browser.

    2. Re:No real benefits (only perceived ones) by Tough+Love · · Score: 1

      Lucky for you WebAssembly is on the way. Compile whatever language you want to WebAssembly and run it in your browser.

      The best you can say about that is, it works. It's ugly beyond belief, and "near native speed" would be true only for some very liberal definition of "near".

      --
      When all you have is a hammer, every problem starts to look like a thumb.
    3. Re:No real benefits (only perceived ones) by Anonymous Coward · · Score: 0

      It's ugly beyond belief

      Seems to work well. Do you actually have anything to contribute other than to say you don't like it?

  15. Re:Mozilla...getting it wrong so you don't have to by NotInHere · · Score: 1

    Flash only has so many security vulnerabilities discovered and fixed because its so popular. The other add ons are similarly insecure, they just don't get used by the malware authors because there is too few users to target.

    And the idea with flash is to move it to use PPAPI (project mortar) and then continue to work towards its deprecation.

  16. To much IT hardware needs java for management by Joe_Dragon · · Score: 4, Informative

    To much IT hardware needs java for management. LIke switch admin, IPMI's, others.

    1. Re:To much IT hardware needs java for management by NotInHere · · Score: 1

      And they should have moved to javascript a long time ago, requiring people to install modern browsers instead of continuing to use internet explorer 6 and microsoft XP without any service packs.

      Still, you can just back up Firefox 51 and put it to a live linux cd of some sort, then making it access the hardware you need via a VM.

    2. Re:To much IT hardware needs java for management by myowntrueself · · Score: 3, Insightful

      And they should have moved to javascript a long time ago, requiring people to install modern browsers instead of continuing to use internet explorer 6 and microsoft XP without any service packs.

      Still, you can just back up Firefox 51 and put it to a live linux cd of some sort, then making it access the hardware you need via a VM.

      Yeah the vendors should have released firmware patches or hardware modules to deal with the changes to browsers. Never going to happen. People with very sensitive jobs are going to keep using crappy unsecurable browsers because they no longer have any choice.

      --
      In the free world the media isn't government run; the government is media run.
    3. Re:To much IT hardware needs java for management by NotInHere · · Score: 1

      The plugins were totally unsecurable already. Just use that browser for accessing those devices only, without internet access.

    4. Re:To much IT hardware needs java for management by Anonymous Coward · · Score: 0

      The plugins were totally unsecurable already.

      Recent Java versions prompted users to enable an applet before it was run, flash still doesn't. 1998 wants its complaints and crappy flash animations back.

    5. Re:To much IT hardware needs java for management by Skuld-Chan · · Score: 1

      Get used to Internet Explorer ;).

    6. Re:To much IT hardware needs java for management by thegarbz · · Score: 1

      And they should have moved to javascript a long time ago, requiring people to install modern browsers instead of continuing to use internet explorer 6 and microsoft XP without any service packs.

      Move? I didn't realise we upgraded equipment worth multiple hundreds of thousands of dollars based on market trends in browsers.

    7. Re:To much IT hardware needs java for management by myowntrueself · · Score: 3, Insightful

      The plugins were totally unsecurable already. Just use that browser for accessing those devices only, without internet access.

      'Without internet access' isn't going to work when you are accessing KVM consoles on servers on the other side of the world which are at a hosting company where you don't have the option of a VPN. There are many thousands such sites perhaps millions. I deal with about a hundred personally.

      Out in the real world people do need java, and often flash as well, in a browser, to be able to do their jobs. You can't just say "Well I'm not going to do my job if you don't upgrade the systems so I don't need java" because they'll just fire you and hire someone who will. Obviously.

      --
      In the free world the media isn't government run; the government is media run.
    8. Re:To much IT hardware needs java for management by NotInHere · · Score: 1

      Well the switch manufacturers. Obviously, if your switch is already an older model and the manufacturer made js available only in the new iterations of it, then its excusable, but then you still are required to use older software. I mean, some software only runs on Windows XP, right? So you still continue to use Windows XP to operate that software. Same here. Plugins are an outdated concept and insecure, you shouldn't expect to be able to run them on the newest browser versions.

      You don't even need a vm, just download firefox somewhere, set up some little wrapper that starts it with a custom profile, and disable auto updates in that profile.

    9. Re:To much IT hardware needs java for management by NotInHere · · Score: 1

      Then whitelist the IPs of the devices you maintain. Just make sure you don't use the older browser version as your main browser.

  17. Retrograde step by Archtech · · Score: 1

    As a general principle, anything that tends to disable large amounts of good working software is a bad idea. Even if a particular mechanism must be retired, surely it isn't beyond Mozilla's ingenuity to find some way of letting existing plugins go on working somehow. A shim layer of some kind?

    --
    I am sure that there are many other solipsists out there.
    1. Re:Retrograde step by Anonymous Coward · · Score: 0

      They tried. It was called Shumway. Nobody cared to help, and Adobe and Google just wanted to make Flash work better on Chrome. It died. Now everyone is pointing fingers at Mozilla for being the last hold-outs on NPAPI (and probably Flash) despite their efforts over the years. Life is fun that way.

    2. Re:Retrograde step by Anonymous+Brave+Guy · · Score: 1

      Mozilla aren't the last hold-outs on NPAPI. Plenty of business users still run IE, and will continue to do so for a long time because of measures like this. All it's doing is turning IE11 into the new IE6.

      --
      If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
  18. Re:Mozilla...getting it wrong so you don't have to by fuzzyfuzzyfungus · · Score: 2

    I certainly don't disagree that Flash should be taken out and shot on security grounds; but it is pretty much the last NPAPI plugin that you are likely to piss users off by dropping support for. iOS got away with it; but Safari continues to support it(though grudgingly); Chrome killed NPAPI; but the 'Pepper' plugin interface appears to exist primarily to support Flash; Edge also whitelists Flash; and Flash on Android died mostly because Adobe couldn't make it work very well; not because Google shoved them off the platform.

    Given Mozilla's less-than-commanding presence in the browser market; I suspect that they can't afford to take a hard line on flash right now.

  19. "This add-on will stop working..." by Futurepower(R) · · Score: 5, Informative
    Posting this again: The reason I like Firefox is the add-ons.
    1. Classic Theme Restorer

      "This add-on will stop working when Firefox 57 arrives in November 2017."

      This add-on will stop working when Firefox 57 arrives in November 2017 and Mozilla drops support for XUL / XPCOM / legacy add-ons. It should still work on Firefox 52 ESR until ESR moves to Firefox 59 ESR in 2018 (~Q2).

      There is no "please port it" or "please add support for it" this time, because the entire add-on eco system changes and the technology behind this kind of add-on gets dropped without replacement.

    2. Cookies Manager+
    3. Ghostery DON'T UPDATE. New versions don't allow sufficient user control.
      USE THIS: ghostery-5.4.10-sm+an+fx.xpi Link: Version 5.4.10
    4. Mozilla Archive Format
    5. NoScript
    6. Nuke Anything Enhanced
    7. Open link in...
    8. Print Edit
    9. Session Manager
    10. Snap Links Plus DON'T UPDATE. New versions don't have as many features.
      USE THIS: snap_links_plus-2.4.3-sm+fx.xpi Link: Version 2.4.3
    11. uBlock Origin
    12. Video DownloadHelper
    1. Re:"This add-on will stop working..." by Anonymous Coward · · Score: 3, Insightful

      when they kill the unique-to-firefox flexibility of addons, it WILL KILL FIREFOX itself. rip. it was a good run but your days are now numbered unless the morons-in-charge over there get their shit together.

    2. Re:"This add-on will stop working..." by Anonymous Coward · · Score: 0

      add tabgroups to that list... http://fasezero.com/

    3. Re:"This add-on will stop working..." by guises · · Score: 1

      Ghostery [mozilla.org] DON'T UPDATE. New versions don't allow sufficient user control. USE THIS: ghostery-5.4.10-sm+an+fx.xpi Link: Version 5.4.10 [mozilla.org]

      I'd suggest not using Ghostery at all, and going with Privacy Badger instead.

    4. Re:"This add-on will stop working..." by trawg · · Score: 1

      When Classic Theme Restorer stops working, I'm off to PaleMoon or something else. I've stuck with Firefox through thick and thin but I don't like the new interface, and losing access to it as well as a bunch of other plugins will be the last straw.

    5. Re:"This add-on will stop working..." by MrL0G1C · · Score: 1

      I'd suggest not using Ghostery at all, and going with Privacy Badger instead.

      Why's it better?

      --
      Waterfox - a Firefox fork with legacy extension support, security updates and better privacy by default.
    6. Re:"This add-on will stop working..." by guises · · Score: 1

      Ghostery is produced by a for-profit company with some dubious motives. It's closed source, and it does collect information, but maybe that information isn't so bad? I don't know, I don't want to slander them unfairly and I do think that the information collection is optional. It also uses a block list to determine what to block which... while not terrible, is not the best approach I think. You just wind up playing wack-a-mole and something's always going to slip through.

      Privacy Badger is produced by the Electronic Frontier Foundation, is open source, and uses a pattern-recognition approach in determining what to block.

    7. Re:"This add-on will stop working..." by Anonymous Coward · · Score: 0

      Ublock origin exists for chrome also. If the back end is going to be more 'chrome like' then at least that one should still exist.

    8. Re:"This add-on will stop working..." by MrL0G1C · · Score: 1

      I did a bit of researching and am entirely unconvinced so far that privacy badger actually works, I think I'd only use it to bolster ad-block / ublock.

      --
      Waterfox - a Firefox fork with legacy extension support, security updates and better privacy by default.
    9. Re:"This add-on will stop working..." by guises · · Score: 1

      Well... it kinda depends on what you're trying to do. Privacy Badger is about protecting your privacy, Adblock just blocks ads. There's some overlap there, but they're not the same thing. That said, I don't think that Privacy Badger is foolproof. It's not the only thing that I use. If you want a blocklist-based privacy filter though, I still wouldn't go with Ghostery. Try Disconnect.

    10. Re:"This add-on will stop working..." by CByrd17 · · Score: 1

      So, Firefox is moving to extensions. I will tell you (as a nightly tester) that NoScript and ABP already have extension versions.

      This is so that add-on/extension writers can write once and run in Chrome and Firefox.

      But, as others have said the ancient NPAPI plugins are what's being discussed here.

    11. Re:"This add-on will stop working..." by CommanderRyalis · · Score: 1

      I use both, Privacy Badger has options to block cookies from third parties or block the third parties domain entirely... Also it's written and or sponsored by the EFF

  20. Enterprise management applications by Anonymous Coward · · Score: 0

    Guess we'll be keeping old versions of firefox et al around so we can continue to access management interfaces to enterprise devices/processes.

  21. Re:Mozilla...getting it wrong so you don't have to by Anonymous Coward · · Score: 0

    Yeah...you obviously don't understand malware authors. At all.

    Malware authors will use any and every attack vector available to them in order to get their payload installed on your system, period. The fact that they're "not as popular" doesn't enter into the equation.

    But hey, I'm willing to prove you wrong using the garbage you spouted out of your own mouth. The other addons are "similarly insecure," are they? Please cite your sources. Go ahead, mention one plugin with as many vulnerabilities as Flash and post links to those vulnerabilities. I'll do what you won't, here's a fairly comprehensive list:

    https://packetstormsecurity.co...

    Over 400 results, on one website that tracks vulnerabilities, for Adobe Flash. Over 400 security advisories for Flash itself, distributions and software that make use of it.

    Your turn. Or are you just talking out of your ass like the rest of the low ID lusers that the moderation system is bumping to the top these days?

  22. Re:Mozilla...getting it wrong so you don't have to by Anonymous Coward · · Score: 0

    The Mozilla _Corporation_ does all the software stuff. It is owned by the Foundation, but the latter is a smaller group of people doing educational programs and such. It has nothing to do with the software. Almost every time you hear talk of "Mozilla," it's the corporation.

  23. Re:Mozilla...getting it wrong so you don't have to by AmiMoJo · · Score: 1

    No, this is good news. Flash isn't the only bad plug-in out there, and by only supporting just that one they can more heavily sandbox it like Chrome does. Flash vulnerabilities typically are mitigated in Chrome anyway, only being of much danger to Firefox and IE users.

    Adobe Reader, Java and numerous anti-virus plug-ins are all just security nightmare crap that are long overdue for deprecation. Unfortunately a lot of people still like Flash but at least once (now?) most sites have moved to HTML5 for video it can be made click-to-play, mitigating drive-by attacks and annoying ads. Since putting out a browser that doesn't support Flash would be considered "broken" by a lot of users (well, at least 3 of the 5 remaining ones) this is the best possible option at the moment.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  24. Re:Mozilla...getting it wrong so you don't have to by NotInHere · · Score: 1

    I said discovered and fixed, not existing. I didn't dispute that Silverlight had less security vulnerabilities discovered and fixed.

  25. Firefox is getting worse by melting_clock · · Score: 1

    I've been using Firefox since the early versions and it is only in the last couple of years that it has given me any problems. The most frustrating is strange crashes on mainstream websites, on multiple platforms. By far the worst Firefox version is on Android which really pisses me off. I like checking in on several websites on my Android tablet of a morning and Firefox crashes more than once a day and I am really sick of that stupid sorry message...

    I also use Firefox on Linux and Windows - both have problems - and the only reason I keep using it is the support for plugins and extensions that I want and that Chrome does not support on Android. If Mozilla screws with those, there is no reason to just move to Chrome and forget about Firefox. While I do not think that Mozilla will care about the loss on one user, I suspect there are more people in a similar position which is why Firefox has been losing market share for a while. Maybe someone will fork Firefox and Mozilla will just fade away.

    Chrome is the only browser I use on my work PC and is used at home for Netflix on Linux. It isn't terrible, just lacking some of the extension I have on Firefox that make it inconvenient to use.

    1. Re:Firefox is getting worse by smartr · · Score: 1

      I felt like a holdout last year, and then gave up on it this past fall and fully switched to Chrome as my primary browser for both development and general use. Too many glitches in Firefox these days. Hopefully they can roll out something fresh that works, Mozilla really has made the web better over the years.

  26. Except Flash? by mi · · Score: 1

    How do you enforce such an exception? By filename? By some kind of digital key?

    And why pick Flash? I don't use it (there is no FreeBSD-variant), but I do use the Java-plugin to control an old (but still nicely functional) network switch. Did Adobe pay the Mozilla Foundation to retain the exception — while Oracle refused to pay for Java?

    Anyway, hopefully, it will remain possible to disable the "feature" at compile-time...

    --
    In Soviet Washington the swamp drains you.
    1. Re:Except Flash? by tepples · · Score: 1

      Your problem isn't that the network switch is administered through a Java applet. Ideally, you could edit the source code to use JNLP (Java Web Start) instead of an applet. Your problem is that the switch's administration firmware is proprietary software.

    2. Re:Except Flash? by mi · · Score: 1

      Your problem is that the switch's administration firmware is proprietary software.

      You are right, that is the problem! But currently I have a solution for it. A solution, which Mozilla is about to take away...

      --
      In Soviet Washington the swamp drains you.
    3. Re:Except Flash? by tepples · · Score: 1

      The solution I intended to imply was to insist on buying switches that come with at least enough API information to make your own client instead of using the included applet.

    4. Re:Except Flash? by mi · · Score: 1

      Software is much easier to change than hardware, is not it? Or should be?..

      Anyway, the problem I intended to underline is the dubious choice of the plugin to survive — why Flash? What process was used to pick Flash, and how will the choice be enforced — the questions, that remain unanswered.

      --
      In Soviet Washington the swamp drains you.
    5. Re:Except Flash? by NotInHere · · Score: 1

      I think the reason for why they've picked flash to survive is that its by far the most popular plugin both in install base and in use in websites.

      https://w3techs.com/technologi...

      Flash is said to have 7.2% of use, while Java has less than 0.1%.

      Of course, it can be different for the sets of websites you visit.

      Flash install base is about 76%: https://metrics.mozilla.com/fi...

    6. Re:Except Flash? by Anonymous Coward · · Score: 0

      Today flash is been used mostly to do useless things that you can ignore. For java it is not the case despite its popularity.

    7. Re:Except Flash? by tepples · · Score: 1

      Software is much easier to change than hardware, is not it?

      Which is why people who care about their freedom ought to consider hardware carefully before buying it.

  27. Left the worst one? by duke_cheetah2003 · · Score: 1

    Left flash enabled? Gah, that's like the worse plugin of all. Should disable it and leave everything else alone.

  28. Re: Mozilla...getting it wrong so you don't have t by Anonymous Coward · · Score: 0

    Safarion macOS supports Flash with a lot of questions like, "Are you really sure you want to install this?" The last time I needed Flash, I had to give admin privs to install the plugin, then turn on plugins generally in Safari (all NPAPI plugins were off by default), then allow Flash specifically to work on whitelisted sites (or allow for all sites). Apple made it a pain to open your box up to attack via Flash. Mozilla should have emulated macOS: ship with NPAPI off by default, allow plugins to be turned on, and whitelist sites with access to plugins.

  29. Re:Mozilla...getting it wrong so you don't have to by Anonymous Coward · · Score: 0

    Adobe Reader, Java and numerous anti-virus plug-ins are all just security nightmare crap that are long overdue for deprecation.

    Java could be configured to only run signed code with whitelisted signatures and addresses and didn't even run applets by default in recent versions. It was safe for internal applications and a passable solution when you needed full access to the local system from a "website" .

    Adobe Reader still beat the built-in of Firefox on low powered devices last time I checked, of course any native PDF readed was infinitely more responsive than whatever code monster mozilla devs created.

  30. ILO/IDRAC gen7/8 = e-waste by npoqwiegrgw · · Score: 1

    Will ilo/idrac for gen7/8 servers be possible to remote control with any browser now? I don't think so, chrome already dropped support and Dell/HP doesn't update their ilo/idrac firmware anymore. It's essentially impossible to reinstall such servers now, because won't use IE6 and my HP machines cannot boot on "big" usb sticks that are required for any modern OS (win2012r2).

    1. Re:ILO/IDRAC gen7/8 = e-waste by tepples · · Score: 1

      Dell/HP doesn't update their ilo/idrac firmware anymore

      Which is a problem only because said management firmware is proprietary software.

      my HP machines cannot boot on "big" usb sticks that are required for any modern OS (win2012r2).

      Can you use a "small" USB stick to install a free operating system, such as Debian netinst, instead of Windows Server 2012 R2?

  31. rtjrtj by npoqwiegrgw · · Score: 1

    ghkdyjryjrsyjsrj

    1. Re:rtjrtj by Anonymous Coward · · Score: 0

      ghkdyjryjrsyjsrj

      This is highly fascinating.

  32. Straight from God by Excelcia · · Score: 1

    It's decisions like this that make me believe in God with an absolutely pure, inviolable faith. Divine intervention is the only explanation for this decision - it had to come straight from God, since no one on earth could have thought of it.

    Actually, I haven't been able to fathom the decisions coming out of Mozilla for some time now. The current version number almost says it all. How can you get excited about a new Firefox release with any feature, when it's just another rapid release. It could have true hard AI and no one would notice any more. It would get lost in the staggeringly mediocre array of non-features nobody wants, forced UI changes, broken addons, ripped out plugins, and developers that decide they know more about what people want than the users do.

    Firefox adopted Google's rapid release cycle on a project that it was neither technically nor culturally suited for. One has to actually admire their dogged persistence to holding this course in the face of what is an almost a completely unified chorus of "WHAT THE FUCK PEOPLE?!?!?".

    I recommend Palemoon. A fork of an earlier Firefox LTR, it has refused to add features unless they make sense, it is compatible with most addons, and has a growing body of its own native addon developers that are quite loyal to the project for the simple reason that the project remains loyal to them. That's not to say that it's a static browser. Just one that took the best of what Firefox was and decided to continue in the direction of sensible goals and not alienating its user base.

    1. Re:Straight from God by Luckyo · · Score: 1

      But it has killed jetpack add-on support recently, well ahead of Firefox which will only do it later this year for main channel and Q2 2018 for ESR. A good chunk of critical add-ons simply no longer work on it.

      Essentially it's gone down the path of Mozilla, but decided to do it before Mozilla at some points.

  33. Does Adobe Systems sell vulnerabilities? by Anonymous Coward · · Score: 0

    "Flash only has so many security vulnerabilities discovered and fixed because its so popular."

    It has seemed to me that Flash has so many security vulnerabilities because Adobe Systems is selling vulnerabilities to secret U.S. government agencies.

  34. Use Emscripten by tepples · · Score: 2

    You can use any programming language you want, so long as you have access to a compiler to compile it into JavaScript. Treat JavaScript as an object code format, not the source code. That's what asm.js was supposed to be about: a subset of JavaScript that the JIT engine can convert trivially for which things like Emscripten can generate code.

    1. Re:Use Emscripten by Anonymous Coward · · Score: 0

      Seems like Mozilla/Firefox is dreaming of their own walled garden.

    2. Re:Use Emscripten by tgv · · Score: 1

      Exactly. And Javascript may be a language with some really dumb features, you can write decent programs in it (TypeScript!) and it's safe, much safer than any plugin written in C could ever be.

  35. Flashblock by tepples · · Score: 1

    Recent Java versions prompted users to enable an applet before it was run, flash still doesn't.

    Yes it does, at least for the past several years. There used to be a Firefox extension called Flashblock that prompted users to activate each SWF object on a site that the user hasn't added to the extension's whitelist. Nowadays, Firefox itself includes click-to-play for Flash Player. But no matter how activated, SWF click to play behavior used to be an effective plausibly deniable ad blocker until the iPad took off and ad networks got the "mobile first" hint.

  36. If you want NPAPI, there is Pale Moon by SEE · · Score: 5, Informative

    Pale Moon is a long-established fork of Firefox that, among other things, is maintaining NPAPI support.

    1. Re:If you want NPAPI, there is Pale Moon by Luckyo · · Score: 1

      But it has killed jetpack add-on support recently, well ahead of Firefox which will only do it later this year for main channel and Q2 2018 for ESR. A good chunk of critical add-ons simply no longer work on it.

      I.e. it's gone down the path of Mozilla, but decided to do it before Mozilla at some points.

    2. Re:If you want NPAPI, there is Pale Moon by Anonymous Coward · · Score: 0

      This is all untrue.

      Pale Moon is excellent.

      The bits they have removed from the original Firefox code, were all useless shit.

    3. Re:If you want NPAPI, there is Pale Moon by Anonymous Coward · · Score: 2, Informative

      FYI, actually people are trying to port back jetpack add-ons to Pale Moon as they were removed for changes in the compiler code as they needed to drop Windows XP support for stablity.

      Remember Pale Moon != Firefox, they were like that in 20 version.

    4. Re:If you want NPAPI, there is Pale Moon by Luckyo · · Score: 3, Interesting

      I imagine people would. This change basically crippled Pale Moon to the point of uselessness to people like myself who migrated to it in search of alternative to Firefox when Firefox went nuts with UI experiments and other weird BS.

      That said, to me that also demonstrated full willingness on part of PM devs to remove add-on compatibility for [reasons]. Browser is a platform for add-ons, and many of them are crucial for me. That patch basically broke several add-ons that are absolute deal breakers for me. And considering the state of forums when I came to ask for support in possibly making these add-ons work, as I did after the previous patch that also broke many add-ons (but I was able to find replacements for all crucial ones then), it demonstrated to me that developers simply did not understand the same thing that Firefox developers miss. We don't come to them for the browser. We come to them for the browser that is also the add-on platform for our favourite add-ons that make everyday browsing far more comfortable, or meet specific work flow demands. As a result, removing support for some add-ons is simply unacceptable, especially when you consider that many of the more esoteric add-ons that people like are often not updated, ever. They just work. Until browser devs decide that they will break them.

    5. Re:If you want NPAPI, there is Pale Moon by Luckyo · · Score: 1

      In other news, nothing new on Eastern Front.

  37. Re:Mozilla...getting it wrong so you don't have to by gravewax · · Score: 2

    not quite, Adobe and Flash are in a class of their own, the sheer extent and severity of vulnerabilities far outstrips any other piece of software including those with much larger user bases.

  38. So what's the best thing to use in the future? by innocent_white_lamb · · Score: 1

    I like Firefox since it isn't a mystery box like Chrome. I use a bunch of plugins like adblock, too. I've never really looked into alternative browsers since Firefox just kind of showed up along with an operating system installation some years back and hey, this works well so good enough for me.

    Since I run Centos I don't imagine there's any rush to change to anything else in the near future, but what's the best non-intrusive web browser to use that isn't going to try to take over my life or computer?

    elinks works for some things but it's not very pretty and doesn't work with numerous modern websites.

    --
    If you're a zombie and you know it, bite your friend!
    1. Re:So what's the best thing to use in the future? by Anonymous Coward · · Score: 0

      Adblock will continue to work. This is only the very old native plugins.

    2. Re:So what's the best thing to use in the future? by Anonymous Coward · · Score: 0

      Just keep using Firefox. I often think it's a mistake for Mozilla to announce anything. Every time they do there's nothing but wailing and gnashing of teeth from people who are surprisingly unsophisticated in their understanding and use of web browsers, even though they use a browser every day.

      So don't worry, be happy. Just use Firefox.

    3. Re:So what's the best thing to use in the future? by MadMaverick9 · · Score: 1
  39. So long Firefox by Anonymous Coward · · Score: 0

    I still have to interact with Java applets for my bank and my employer, so this move will basically kill Firefox for me.

    1. Re:So long Firefox by TroII · · Score: 1

      If my bank was reliant on Java applets, I'd be switching banks, not browsers!

    2. Re:So long Firefox by Anonymous Coward · · Score: 0

      Like the government agency that deposit my retirement fund can do that with a simple email. :P

  40. please shoot flash by Anonymous Coward · · Score: 0

    in the head, twice, just to make sure.

  41. Re:Mozilla...getting it wrong so you don't have to by Anonymous+Brave+Guy · · Score: 1

    Also, as browsers start to emulate the extra functionality that used to be provided by plugins, it is logical to assume based on past performance that they will probably start to suffer from related security issues as well.

    But let's not let facts get in the way of bashing web technologies more than a year or two old and promoting replacement technologies that aren't necessarily as capable as the old ones, because that would totally spoil all the fun.

    --
    If you disagree, post your argument. (-1, Overrated) isn't your personal censorship tool for views you don't like.
  42. Re:Mozilla...getting it wrong so you don't have to by Anonymous Coward · · Score: 0

    I notice you failed to address my challenge to you in any way. I assume that is because I was right and you were wrong. Why? I asked you for evidence to back up your claim and instead, you posted a two-sentence argument over semantics. I, on the other hand, actually presented evidence to support my claim.

    So it's obvious at this point that yes, you are talking out of your ass. Typical. I won't waste any more time on you, you're participating in a discussion that you aren't intellectually qualified for.

    If you'll excuse me, there are intelligent people in this thread to discuss with. You aren't one of them. Go back to reddit.

  43. Re:Mozilla...getting it wrong so you don't have to by Anonymous Coward · · Score: 0

    Flash only has so many security vulnerabilities discovered and fixed because its so popular.

    Now that is an amazingly backwards attribution of causality. Yes, there is a higher incentive to exploit software that is more popular - but incentives do not predict results.

  44. Thanks. by Futurepower(R) · · Score: 1

    Thanks for the suggestion. I'll try it.

    1. Re:Thanks. by Anonymous Coward · · Score: 0

      or disconnect. open source instead of closed and made by ad companies...

  45. SeaMonkey by Anonymous Coward · · Score: 0

    Anyone know if SeaMonkey will be maintaining plugin API compatibility?

  46. Should we start a lottery? by Anonymous Coward · · Score: 0

    Over how low the user population will have to go before Mozilla realizes it is on the wrong path?

  47. Amazingly bad management by tech. companies by Futurepower(R) · · Score: 1

    Pale Moon no longer supports Ghostery.

    I forgot to mention: Tab Mix Plus

    No only the Mozilla Foundation, but many technology organizations are poorly managed. Any theories about why that is so?

    1. Re:Amazingly bad management by tech. companies by drinkypoo · · Score: 1

      Lots of pages which work in normal Firefox don't work in Pale Moon. Nobody tests for it, which makes it a total non-worker. I used it for a while, but had to give up due to compatibility issues.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    2. Re:Amazingly bad management by tech. companies by trawg · · Score: 1

      Boo, really? I haven't tried it for years but I understood it to be a fairly standard derivative of mainline Firefox.

    3. Re:Amazingly bad management by tech. companies by drinkypoo · · Score: 1

      Boo, really? I haven't tried it for years but I understood it to be a fairly standard derivative of mainline Firefox.

      Some time ago they changed their rendering engine and that's when the trouble began. I was a fan at first but that ended my love affair with their browser and I went back to Firefox. Compatibility is job 1.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  48. you can disable plugins - so what is the point by Anonymous Coward · · Score: 0

    I still have some older management interfaces (networking stuff for example) that rely on a java interface.

    Either do it for everything or nothing.

  49. Re:Mozilla...getting it wrong so you don't have to by Anonymous Coward · · Score: 0

    I notice you failed to address my challenge to you in any way.

    because you "challenged" him to something he wasn't arguing.

  50. Plugin workaround for Firefox 52 missing from TFAs by ahenryop · · Score: 1

    If you add the plugin.load_flash_only preference to about:config (and then turn it off) you will temporarily re-enable NPAPI plugins in Firefox 52. This is useful because you can turn it on in normal (pre-version 53) Firefox, and then update to 52 ESR once that is released, to keep people on a supported version until 2018 while you migrate away from plugins.

  51. Thanks for the info. by Futurepower(R) · · Score: 1

    Thanks for saying that. Apparently you mean Firefox is moving to extensions and away from add-ons. I don't know the difference. I only know that there have been add-ons, exensions, and plugins, 3 names for what seems the same to users.

    It's amazing how bad Mozilla Foundation is at communicating.

    The Classic Theme Restorer author is saying we will be forced to use the new Firefox theme.

  52. News for nerds, huh? by allo · · Score: 1

    "A series of hacks"
    Nope, these aren't hacks, they are simple settings.

    And there is a much easier way. Download the f*cking ESR-Release, unzip it and use it instead of the normal release. This even works coming from a newer version (nobody will guarantee you a smooth downgrade, but normally it works without major problems).

    And on the other hand, the ESR will only delay the change. ESR is similiar to stopping upgrading firefox, but guarantees you security patches until the next ESR superseedes the current one.

  53. End of Plugins = Techno racism by neutrino38 · · Score: 2

    This move from Mozilla foundation is consistent with what we have seen happening with Chrome, Edge. It has been initiated long by Apple which decided to drop flash support on their mobile device.

    The motivation of these move are well known: less battery usage, more security. For general public it is justified.

    However there are a whole range of corporate application that relied and still rely on plug-ins. Not just flash. So deep down, by not providing at least a supported version of browser with plugin, the industry is building a monolithic platform ...again. Single language, single platform. Its about control not user choice.

    The argument that HTML5 is now mature enough does not fly very far. Mature enough for common web app sure. But it you start using advanced feature such as WebRTC, you'll start seeing glitches and incompatibilities that pushes some service to advertize "please use Chrome" ...

    The fact is that now people in general (users, developers and software editors) are techno racists. They want security and despite technology that is not 'like them'. So the prefer to slam the door and drop the plugins and by decree ban any foreign technology from our beloved HTML / JS free platform.

    This is unfortunately consistent with the behavior of the political world of today ...

  54. Thanks! by Futurepower(R) · · Score: 1

    Disconnect looks good. It works with Pale Moon. Ghostery doesn't.

  55. One thing I do know, Slashdot... by Anonymous Coward · · Score: 0

    ... This Squarespace ad on this page taking up 1/3rd of the vertical screen space, with persistence as I scroll down, is way the fuck too annoying. I won't even read the other comments on this story. And no, I won't click on the side square that seems to be a collapse button. Too many experiences with doing that acting like a click elsewhere.'

    Please require your ads to be a little less intrusive, Slashdot!