data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
data:image/s3,"s3://crabby-images/9d8bc/9d8bc04c9bbc03468a69d61908a4d95f351161b7" alt="Portables Portables"
Reporter Tests Walmart's $140 Laptop 'So You Wouldn't Have To' (arstechnica.com) 200
I verified that I was on an older version of Windows 10 — build 1903, from March 2019 — and initiated an upgrade to build 2004, from April 2020. Windows 10 was having none of it. It wanted at least 8GiB of free space on C:, and I couldn't even get to 6GiB free, after only a day of using the system.... Meaningful benchmark results were impossible to attain on this laptop, since it was too slow and quirky to even run the benchmarks reliably. But I didn't let a silly thing like "being obviously inappropriate" stop me from slogging painfully through the benchmarks and getting what numbers I could. The first suite up, PCMark 10, eventually produced a score of zero. I didn't know that a zero score was even possible. Apparently, it is... Cinebench R20 also took several tries to complete successfully, and eventually the test produced a jaw-droppingly bad score of 118...
Under Fedora 32 — selected due to its ultra-modern kernel, and lightweight Wayland display manager — the EVOO was incredibly balky and sluggish. To be fair, Fedora felt significantly snappier than Windows 10 had on this laptop, but that was a very, very low bar to hurdle. The laptop frequently took as long as 12 seconds just to launch Firefox. Actually navigating webpages wasn't much better, with very long pauses for no apparent reason. The launcher was also balky to render — and this time, with significantly lower memory usage than Windows, I couldn't just blame it on swap thrashing... [W]ith the laptop completely open, several questions are answered — the reason I hadn't heard any fan noise up until this point is because there is no fan, and the horrible CPU performance is because the CPU can't perform any better than it does without cooking itself in its own juices....
At first, I mistakenly assumed that the A4-9120 was just thermally throttling itself 24/7. After re-assembling it and booting back into Fedora, I found the real answer — the normally 2.5GHz chip is underclocked to an anemic 1.5GHz. The system BIOS confirms this clockrate but offers no room to adjust it — which is a shame, since the system never hit temperatures higher than about 62C in my testing.
His verdict? Walmart's EVOO laptop "doesn't have either the RAM or the storage to do an even vaguely reasonable job for normal people doing normal things under Windows, even when limited to S mode...
"There may be a purpose this laptop is well-suited to — but for the life of me, I cannot think what it might be."
data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
Mozilla To Launch VPN Product 'in the Next Few Weeks' (zdnet.com) 73
data:image/s3,"s3://crabby-images/562bb/562bbbdc55cc6726d4a5eba7147e01a00614dfc8" alt="Privacy Privacy"
Incognito Mode Detection Still Works in Chrome Despite Promise To Fix (zdnet.com) 40
data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
Firefox 77 Arrives With Faster JavaScript Debugging and Optional Permissions (venturebeat.com) 30
data:image/s3,"s3://crabby-images/16161/161616eba7f8b49713d45eff07e099f060e8f6a3" alt="Microsoft Microsoft"
Ask Slashdot: Why is Microsoft Blocking Its Own Server Pages? 21
Your request has been blocked. This may be due to several reasons. 1. You are using a proxy that is known to send automated requests to Microsoft. Check with your network administrator if there is any proxy and what User-Agent they are sending in the request header. 2. Your request pattern matches an automated process. To eliminate, reduce the volume of requests over a period of time. 3. Reference ID: 41.70790b91.4823110533.409105b4
It turns out the advisory number doesn't matter, just the extension for "Active Microsoft Server Page" (https.../.mspx) at the end. I guess there were too many security advisory lookups for MS to handle! *snort*!
The .mspx extension indicates a page using a special internal Microsoft rendering framework with a custom web handler (built in ASP.Net). But I ran some tests Saturday, and observed the exact same glitch described above using three different browsers — Firefox, Edge, and Brave. Anyone have a theory about what's going on?
Leave your thoughts in the comments. Why is Microsoft blocking its own server pages?
data:image/s3,"s3://crabby-images/92ec3/92ec3a8bb51cd25da9a36d7360c786d62625a43b" alt="The Internet The Internet"
Chrome and Firefox Block Torrent Site YTS Over 'Phishing' (torrentfreak.com) 34
It's not clear what the exact problem is but the Chrome warning mentions that YTS was caught phishing. This is also reflected in Google's Safe Browsing report, which states the torrent site recently tried to trick visitors into sharing personal info or downloading software. Whether any of this is intentional remains a question. It seems more likely that the warning was triggered by some type of malicious advertisement.
data:image/s3,"s3://crabby-images/f2340/f2340da7236055b3e08e7e79c4c8aa4b360b6d85" alt="Chrome Chrome"
Chromium Project Finds 70% of Its Serious Security Bugs Are Memory Safety Problems (chromium.org) 154
ZDNet reports: The percentage was compiled after Google engineers analyzed 912 security bugs fixed in the Chrome stable branch since 2015, bugs that had a "high" or "critical" severity rating. The number is identical to stats shared by Microsoft. Speaking at a security conference in February 2019, Microsoft engineers said that for the past 12 years, around 70% of all security updates for Microsoft products addressed memory safety vulnerabilities. Both companies are basically dealing with the same problem, namely that C and C++, the two predominant programming languages in their codebases, are "unsafe" languages....
Google says that since March 2019, 125 of the 130 Chrome vulnerabilities with a "critical" severity rating were memory corruption-related issues, showing that despite advances in fixing other bug classes, memory management is still a problem... Half of the 70% are use-after-free vulnerabilities, a type of security issue that arises from incorrect management of memory pointers (addresses), leaving doors open for attackers to attack Chrome's inner components...
While software companies have tried before to fix C and C++'s memory management problems, Mozilla has been the one who made a breakthrough by sponsoring, promoting and heavily adopting the Rust programming language in Firefox... Microsoft is also heavily investing in exploring C and C++ alternatives⦠But this week, Google also announced similar plans as well... Going forward, Google says it plans to look into developing custom C++ libraries to use with Chrome's codebase, libraries that have better protections against memory-related bugs. The browser maker is also exploring the MiraclePtr project, which aims to turn "exploitable use-after-free bugs into non-security crashes with acceptable performance, memory, binary size and minimal stability impact."
And last, but not least, Google also said it plans to explore using "safe" languages, where possible. Candidates include Rust, Swift, JavaScript, Kotlin, and Java.
data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
Firefox 78 To Prevent Websites From Forcing Users To Save PDF Documents (thewindowsclub.com) 69
"Mozilla is rolling out this feature to the masses with the stable release of Firefox 78." Right now, Mozilla has added this feature to Firefox 78 in the Nightly channel.
The issue was first raised in 2011, and it took Mozilla 9 years to fix it. Many websites host and offer PDF documents with the following HTTP header:
Content-Disposition: attachment; filename="whatever.pdf."
This is an indication to the web browser that the PDF file should be saved with the specified name rather than try opening it in the web browser window. But since Firefox has a built-in PDF viewer, it should be for users to decide whether they want to view or save PDF documents.
data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
Firefox 76 Arrives With Password Management and Zoom Improvements (venturebeat.com) 75
[...] Firefox 76 adds support for Audio Worklets, which run custom JavaScript audio processing code for applications like VR and gaming on the web. Unlike their predecessor, ScriptProcessorNode, worklets run off the main thread in a similar way to web workers. Mozilla also notes Audio Worklets are "being adopted by some of your favorite software programs." The company specifically called out Zoom, which has become a phenomenon of its own during the pandemic. In short, you now join Zoom calls in Firefox without having to download or install the Zoom client.
data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
New Firefox Service Will Generate Unique Email Aliases To Enter In Online Forms (zdnet.com) 70
data:image/s3,"s3://crabby-images/14f0b/14f0b353db8f87a695a6969f974da224ebca9e1a" alt="Mozilla Mozilla"
Firefox Raises Its Bug Bounties to $10,000 (mozilla.org) 5
Additionally, we'll be publishing more posts about how to get started testing Firefox — which is something we began by talking about the HTML Sanitization we rely on to prevent UXSS. By following the instructions there you can immediately start trying to bypass our sanitizer using your existing Firefox installation in less than a minute...
Lastly, we would like to let you know that we have cross-posted this to our new Attack & Defense blog. This new blog is a vehicle for tailored content specifically for engineers, security researchers, and Firefox bug bounty participants.
They point out that Firefox has one of the world's oldest bug bounty programs, dating back to 2004 -- and it's still going strong. "From 2017-2019, we paid out $965,750 to researchers across 348 bugs, making the average payout $2,775 — but as you can see in the graph below, our most common payout was actually $4,000!"
data:image/s3,"s3://crabby-images/254be/254bea61091eb9825609330906918fe055c4603c" alt="Android Android"
Vivaldi Browser Gets Built-in Tracking Blocker, Goes GA on Android (techcrunch.com) 26
data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
Mozilla Installs Scheduled Telemetry Task On Windows With Firefox 75 (ghacks.net) 102
Mozilla says:
- "We're collecting information related to the system's current and previous default browser setting, as well as the operating system locale and version. This data cannot be associated with regular profile based telemetry data..."
- "We'll respect user configured telemetry opt-out settings by looking at the most recently used Firefox profile."
- "We'll respect custom Enterprise telemetry related policy settings if they exist. We'll also respect policy to specifically disable this task."
"Collecting telemetry is one way we're able to ensure we can understand default browser trends in a way that helps us improve Firefox. It's our hope that by better understanding more about our users and their choices around browser preferences, we can continue to build a better Firefox."
Long-time Slashdot reader AmiMoJo writes, "Opting out can be done via the Privacy & Security section of the preferences screen. You can view collected telemetry and view your current settings at about:telemetry."
Bleeping Computer also notes that by default, "For some time, Firefox has been collecting telemetry data about how you use the browser, such as the number of web pages you visit, safebrowsing information, the number of open tabs and windows, what add-ons are installed, and more. This telemetry data is kept for 13 months and IP addresses listed in server logs are deleted every 30 days.
"On my computer, Firefox has collected over 400KB of information."
data:image/s3,"s3://crabby-images/14f0b/14f0b353db8f87a695a6969f974da224ebca9e1a" alt="Mozilla Mozilla"
Longtime Mozilla Leader Mitchell Baker is Now CEO (cnet.com) 34
data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
Firefox 75 Arrives With Revamped Address Bar; Mozilla To Stick With 2020 Schedule (venturebeat.com) 43
When the coronavirus crisis took hold, millions found themselves spending more time in their browsers as they learn and work from home. But the crisis is also impacting software developers. Google was forced to pause its Chrome releases, which typically arrive every six weeks. Ultimately, Chrome 81 was delayed, Chrome 82 is being skipped altogether, and Chrome 83 has been moved up a few weeks. Microsoft has followed suit with Edge's release schedule, consistent with Google's open source Chromium project, which both Chrome and Edge are based on. Mozilla wants to make clear it is not in the same boat. The company took an indirect jab at Google and Microsoft today, saying: "We've built empathy into our systems for handling difficult or unexpected circumstances. These strengths are what allow us to continue to make progress where some of our competitors have had to slow down or stop work."
data:image/s3,"s3://crabby-images/dbfa9/dbfa9cde5b225fa9cff656a78863824c8217ea0b" alt="Firefox Firefox"
Edge Overtakes Firefox To Become the Second-Most Popular Browser (softpedia.com) 119
So right now, Microsoft Edge is the second most-used desktop browser on the planet with a share of 7.59%, while Mozilla Firefox is now third with 7.19%.
As for who's leading the pack, Google Chrome continues to be number one with a share of 68.50%.
data:image/s3,"s3://crabby-images/f1e47/f1e47864368802b7146688c1bcfcef953d8d34d4" alt="Twitter Twitter"
Twitter Discloses Firefox Bug That Cached Private Files Sent or Received via DMs (zdnet.com) 42
data:image/s3,"s3://crabby-images/67e04/67e04d20ffb5cd2220e93e9e408f7ceb339f051f" alt="Movies Movies"
To Conserve Bandwidth, Should Opting In Be Required Before Autoplaying Videos? (fatherly.com) 103
To give an example, a couple of days ago I was watching a show on Hulu, and either I was more sleepy than I thought or the show was more boring than I had expected (probably some combination of both), but I drifted off to sleep. Two hours later I awoke and realize that Hulu had streamed two additional episodes that no one was watching. I searched in vain for a way to disable autoplay of the next episode, but if there is some way to do it I could not find it.
What I wonder is how many people even want autoplay? I believe Netflix finally gave their users a way to disable it, but they need to affirmatively do so via a setting somewhere. But many other platforms give their users no option to disable autoplay. That is also true of many individual apps that can be used on a Roku or similar device. If conserving bandwidth is really that important, then my contention is that autoplaying of the next episode should be something you need to opt in for, not something enabled by default that either cannot be disabled or that forces the user to search for a setting to disable.
"Firefox will disable autoplay," writes long-time Slashdot user bobs666 (adding "That's it use Firefox.") And there are ways to disable autoplay in the user settings on Netflix, YouTube, Hulu, and Amazon Prime.
But wouldn't it make more sense to disable autoplay by default -- at least for the duration of this unusual instance of peak worldwide demand?
I'd be interested in hearing from Slashdot's readers. Do you use autoplay -- or have you disabled it? And do you think streaming companies should turn it off by default?
data:image/s3,"s3://crabby-images/562bb/562bbbdc55cc6726d4a5eba7147e01a00614dfc8" alt="Privacy Privacy"
Doc Searls: 'Zoom Needs to Clean Up Its Privacy Act' (harvard.edu) 32
Zoom does use certain standard advertising tools which require Personal Data ...
What they mean by that is adtech. What they're also saying here is that Zoom is in the advertising business, and in the worst end of it: the one that lives off harvested personal data. What makes this extra creepy is that Zoom is in a position to gather plenty of personal data, some of it very intimate (for example with a shrink talking to a patient) without anyone in the conversation knowing about it. (Unless, of course, they see an ad somewhere that looks like it was informed by a private conversation on Zoom.)
A person whose personal data is being shed on Zoom doesn't know that's happening because Zoom doesn't tell them. There's no red light, like the one you see when a session is being recorded. If you were in a browser instead of an app, an extension such as Privacy Badger could tell you there are trackers sniffing your ass. And, if your browser is one that cares about privacy, such as Brave, Firefox or Safari, there's a good chance it would be blocking trackers as well. But in the Zoom app, you can't tell if or how your personal data is being harvested.
(think, for example, Google Ads and Google Analytics).
There's no need to think about those, because both are widely known for compromising personal privacy. (See here. And here. Also Brett Frischmann and Evan Selinger's Re-Engineering Humanity and Shoshana Zuboff's In the Age of Surveillance Capitalism.)
Zoom claims it needs personal data to "improve" its users "experience" with ads -- though Searls isn't satisfied. ("Nobody goes to Zoom for an 'advertising experience,' personalized or not. And nobody wants ads aimed at their eyeballs elsewhere on the Net by third parties using personal information leaked out through Zoom.") His conclusion?
"What Zoom's current privacy policy says is worse than 'You don't have any privacy here.' It says, 'We expose your virtual necks to data vampires who can do what they will with it.'"