Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dveditz_
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
dveditz_
1y ago
The "exposing information about..." bit in the Mozilla statement is fingerprinting/privacy argument like WebKit's
2.
▲
by
dveditz_
1y ago
Removed MNG and started work on APNG 20 years ago! https://bugzilla.mozilla.org/show_bug.cgi?id=257197
3.
▲
by
dveditz_
1y ago
It supports JavaScript when used as a document, but when used as an "image" by a browser (IMG tag, CSS features) JavaScript and the loading of external resources are disabled.
4.
▲
by
dveditz_
1y ago
The capabilities are already expanded in most common implementations. This update is largely blessing those features as officially "standard".
5.
▲
by
dveditz_
2y ago
It's not a "goal", it's a requirement (right there in the name!). Failing to comply to a government requirement subjects you to the associated penalties. They haven't said which requirement (we assume it's Russ
6.
▲
by
dveditz_
4y ago
Tails has updated their advisory to remove that statement: https://tails.boum.org/security/prototype_pollution/index.en...
7.
▲
by
dveditz_
4y ago
We are not aware of any such thing. As rebelwebmaster noted, when we know that we put it in our advisory. Clearly the vulnerabilities are exploitable as demonstrated by Manfred Paul's winning Pwn2Own entry. The details were disclosed o
8.
▲
by
dveditz_
5y ago
Did the execs get raises after the layoffs? About half the ones that were at Mozilla at that time are gone now.
9.
▲
by
dveditz_
5y ago
Or you just turn it off in the normal preference UI and trust that California's AG will sue Mozilla into oblivion if they weren't honoring the CCPA. https://blog.mozilla.org/netpolicy/2019/12/31/
10.
▲
by
dveditz_
5y ago
Those are in no way substitutes for each other -- you have to do both. People are not able to self-report accurate measurement data, and telemetry data can't tell you anything about what a person wants or why they do things.
11.
▲
by
dveditz_
7y ago
How to know when unrelated domains are actually part of the same site is a hard problem. The Public-suffix List approach works okay-ish for cookies, but no one's really happy enough with it to trust for riskier features, and it doesn&#
12.
▲
by
dveditz_
7y ago
Are you using an Extended Support Release (ESR)? That's expected then.
13.
▲
by
dveditz_
9y ago
Mozilla has never sponsored the Pwn2Own contest.
14.
▲
by
dveditz_
11y ago
You can't compare counts of published vulnerabilities when organizations have vastly different standards of publication. Open source projects (e.g. Firefox, chromium) publish everything, even internally found flaws. Closed-source proje
15.
▲
by
dveditz_
11y ago
The target is not illegal malware which, as you say, would do anything. But there's a vast amount of detrimental foistware doing malicious things (e.g. injecting ads, tracking) under legal cover because the user somewhere forgot to unc
16.
▲
by
dveditz_
11y ago
zing !
17.
▲
by
dveditz_
11y ago
39.0.1 and 39.0.2 fixed serious regressions in Firefox for Android in some configurations. They weren't security fixes.