Saturday, July 30, 2011

Why Firefox dumped corporate users

From a BBC story on UK government being ripped off on IT:
I'm a civil servant and have to use these IT systems. For all the money that is spent on them I'm using a machine that's 7 years old, has minimal memory and hard-drive capacity, is running Internet Explorer 6, has snail's pace connectivity speed and find it really difficult to do my job. And as you all may know, everything is done on computers these days.
Corporate use = browser fossilisation.

Friday, July 15, 2011

The safest web browser?

(OR: What connects Internet Explorer and Rush Limbaugh)

Surely not a difficult question to answer? Just look at the statistics for security vulnerabilities- especially those that were exploited by malware "in the wild" before a patch was issued and how long those vulnerabilities remained unpatched.

Source: Web Devout.

Historically, the answer would certainly not have been Internet Explorer. It has the worst record for zero-day vulnerabilities leaving the browser open to "drive-by" malware attacks for considerable periods before a patch was released- it has left its users vulnerable to such attacks on numerous occasions.

To my knowledge, Firefox has only exposed its users to one such vulnerability, and only briefly, and only to malware on one specific website, rather than widespread attacks. Still, to my recollection, Opera, although it has had vulnerabilities, has patched these before they were used in malware attacks; the same for Chrome.

So, historically, if I had to guess, Opera or Chrome might get the award. To Microsoft's credit, they recognised the security problems with their browser and recent versions have been a lot more secure. Anybody interested in the original question could look at the data on browser vulnerabilities for recent versions and follow the evidence.

The evidence will tell you the answer- a purely logical process that tends to invoke irrational responses. Why?

The first illogical response is the common statement that Internet Explorer is used by more people and therefore a bigger target and therefore more looked at for vulnerabilities. This excuse ignores the evidence that Internet Explorer is more open to exploit because it has features that other browsers don't have that have their own security weaknesses, such as ActiveX, and because it is more integrated into the Microsoft operating system. It also ignores the evidence that hackers find Internet Explorer easier to hack.

The second illogical response is usually an attack on Firefox, usually along the lines of "Firefox sucks" or similar. Should Firefox users then point out the evidence, they are then often labelled as "fanboys", despite the juvenile nature of their own emotional response- an unsophisticated form of ad-hominem attack known as "projection".

Back to the question- why? And why is it Firefox that is resented by Internet Explorer users? I think the answer is political. The people who resist the evidence that Internet Explorer is not as secure as other browsers often subscribe to a loud-mouthed extreme right wing ideology. Take for example this post to a thread on browser security:
Anything has to be better than FF. (Roll Eyes)
With the signature:
"If you want to make a Conservative angry, tell him a lie. If you want to make a Liberal angry, tell him the truth." - Rush Limbaugh
Now you could say I'm stretching one comment to make a point.

But the internet long called Poe on the American fringe right's antipathy to Firefox: Exhibit 1, Exhibit 2.

The extreme hard right mentality resents a group of people working together to produce a better browser for free: it undermines their belief in the superiority of free-market capitalism in producing better software, and indeed a better world than any collective, altruistic enterprise run by wishy-washy socialists, as they would see the open-source community.

The idea that open-source software is a tool of socialism designed to undermine capitalism is of course total nonsense. Wherever could the hard right have got that idea from?


(Possibly it's the result of a complete lack of a sense of humour?)

As a footnote, the only thing the hard right hate more than a collective, altruistic enterprise interfering with a commercial enterprise, it's a collective, altruistic enterprise interfering in the economy itself- which is why the anti-Firefox trolls have turned their attention to climate science and global warming.

Saturday, July 9, 2011

Debian Mozilla Repository engages warp drive

In response to the rapid new Firefox release cycle mentioned in my previous post, the Debian Mozilla team repository has been updated- and users need to update the appropriate lines in their source files, as detailed on the Debian forum.
In short, the new line will contain release for the latest version, instead of the version number, which will now change every six weeks or so as new versions are released and older versions are no longer supported.
There is also a beta channel for the adventurous, and an alpha channel (called aurora) for the really adventurous.

Tuesday, June 28, 2011

Firefox release cycle hits warp factor 8

-Too fast for corporate use:

By releasing small, focused updates more often, we are able to deliver improved security and stability even as we introduce new features, which is better for our users, and for the Web.

We recognize that this shift may not be compatible with a large organization's IT policy and understand that it is challenging to organizations that have effort-intensive certification polices [But] tying Firefox product development to an organizational process we do not control would make it difficult for us to continue to innovate for our users and the betterment of the Web.

Kev Needham, Mozilla's channel manager, on computerworld.com.

Asa Dotzler, director of Firefox, puts it more bluntly:
I don't care about making Firefox enterprise-friendly.
computerworld.com again.

How will this affect corporate uptake of FOSS?
Mozilla has basically said that they aren't interested, at all, in corporate deployments. Oh good, a medium-sized business investigating a switch to FOSS now has a strong disincentive to make the switch. Mozilla's rejection of corporate deployments almost certainly hurts other FOSS projects, most notably Linux.
dasein, writing on the Debian forum.

What about Debian users? Squeeze came with Firefox 3.5- by the time Wheezy arrives, Mozilla could have issued Firefox 12. Well, Debian users can get the latest release from the Debian Mozilla team, as mentioned in a previous post.

Saturday, June 18, 2011

Libreoffice arrives in Squeeze backports

I'm using an old Lenny machine at the moment and not my usually Squeeze laptop, but this is something I'm going to try as soon as I get back to it.

Details on the Debian forum.

Update: Official announcement and installation instructions on debian.org.

Mouse pointer highligher trail in GIMP

The default setting in the GIMP has a mouse pointer highlighter active. It makes working in GIMP difficult- to the point that it's been mistaken for a bug. I came across this issue before- and disabled the highlighter immediately. Using another computer today, I came across the same issue, but I'd forgotten how I'd fixed it- and it took me a while to find the solution. Eventually I found it on Pimp my GIMP.

Go to File>Preferences>Image Windows and untick Show brush outline.

Update: this looks like a Debian Lenny issue: my Debian Squeeze machine doesn't have this problem. Time to update the old laptop I was using when I wrote this post, probably.

Friday, June 10, 2011

Do I need an Anti-virus program on Linux?

This is a question often asked by new users of Linux. (See here.) The short answer often given is no, but that answer often stirs controversy. (See here.)
I haven't used an anti-virus program in Linux for years (although I've tried all the free ones). My answer to the question, as a home user of Linux only computers who doesn't share files with Windows users is also no. Obviously I've caveated that answer, and there are plenty more caveats, so here are some points to beware.
  • Saying that you don't need an anti-virus doesn't mean that Linux malware doesn't exist. It does.
  • Saying that you don't need an anti-virus doesn't mean that you don't need to be careful about security in Linux. You do.
  • For new users of Linux, that attention to security means getting software from the distributions digitally signed software repository, or trusted sources. (For example, I have installed software from Opera and HP in addition to software from the Debian repository.) This guide is not intended for or likely to be useful to more advanced users of Linux.
  • Linux malware exists, but Linux users are very unlikely to encounter it. Don't go downloading packages form the internet and you won't. (Obviously, with so much free software available in distribution repositories, Linux users won't be on crack sites or peer-to-peer networks downloading dodgy executables that claim to unlock Windows programs.)
  • Most Linux anti-virus programs don't do the background scanning of files that Windows anti-virus programs do. If you want to scan a file, you have to do it manually.
  • Why use one installed scanner to scan a file when you could send it to Virustotal and have 30 or so scanner check it? (And please see the point above about not downloading packages from untrusted sources in the first place.)
  • Linux users are simply not affected by the web-borne exploits that install software willy-nilly on Windows systems.
  • Most Linux anti-viruses are primarily intended for file servers, not desktop environments. Yes, an anti-virus is recommended in that situation- beyond the scope of this simple guide. But if you have a dual partition with Windows, or share files with Windows users, yes, an anti-virus is useful- but you'll be looking for Windows viruses.
  • There is no certainty that anti-virus programs will detect a malicious file, as I demonstrated here and here.
  • Linux anti-virus programs are meant as file scanners, not system scanners- scanning the /root (system) directory is likely to result in a lot of frightening warnings (for the new user) which actually don't indicate any sort of infection. See here and here.
  • Institutional network users running Linux may well be asked to use an anti-virus program- I'm not here to contradict your system administrator. Mostly the concern is that Linux users will pass Windows malware around. But there is also the possibility that these users will have valuable information and may be targeted by criminals- and receive a Linux Trojan in their email inbox, for example.
  • Where untrusted and possibly malicious people have physical access to a computer, there is the possibility that they may try to run malicious software. This area is outside my experience. Untrusted people don't use my computer. In institutional situations like this, the answer may be yes, an anti-virus might be a good idea. Listen to your system administrator or consult a more advanced guide.
  • Most of the people advising that home users of Linux need an anti-virus program are Microsoft shills spreading FUD. The idea that you can run a computer connected to the internet without anti-virus protection or risk of infection tempts users away from Windows, and Microsoft has never been above a little black propaganda. More importantly, these people don't actually look at the evidence when they tell you it's not safe to run Linux without an anti-virus.