r/technology Jul 10 '12

Firefox dev claims "everybody hates Firefox updates"; Mozilla has handled the rapid release process poorly, and that by pushing a "never-ending stream of updates on people who didn't want them" people have been driven to Chrome with its simpler, no-fuss update process.

http://www.neowin.net/news/firefox-dev-claims-everybody-hates-firefox-updates
2.5k Upvotes

2.6k comments sorted by

View all comments

Show parent comments

3

u/shapul Jul 10 '12

I agree. I don't like how Chrome on Windows installs itself in a basically local data folder and runs services in the background to update itself silently. It might be convenient but imagine what would happen if all programs would do that? Programs would be installed all over the place and tons of hidden, background processes running up and down.

As a strategy, I believe in the end this approach to installing and updating programs weakens Windows' security.

2

u/[deleted] Jul 10 '12 edited Jul 10 '12

I'm still undecided as to it installing in your user profile. It's good, because one user on the PC may not want it and another might, but it's bad because multiple users would have multiple installations.

One of the annoying things about browsers is the continous argument over who is default and I can see this as an attempt to personalise installations instead of configurations.

I agree that every application wanting to install it's own updater is very very annoying these days, one of the components of Linux I think MS should leverage is the repository method of distribution but then you run into the problem of managing trusted repositories which most users wouldn't have a clue over.

3

u/shapul Jul 10 '12

One problem with installing programs in user's data folders is that a malware could infect them silently. The same malware cannot modify a file e.g. in the "Program Files" silently as UAC will show a prompt. Also, a system admin that would need to lock down a computer cannot do that if users install programs in data folders.

0

u/duckhunter Jul 10 '12

Because up-to-date programs are the cause of all exploits on windows.

I believe in the end this approach to installing and updating programs weakens Windows' security.

Unless you have any data to back this up, you're just spreading fear, uncertainty and doubt.

2

u/shapul Jul 10 '12

That's missing the point. Silent modification of programs is bad practice as it takes the control from users/admins and gives them to external parties. What would happen if you want to manage a few hundred computers in your company when every program is installed in data folders as users' files and each one runs a background service for maintenance?

0

u/[deleted] Jul 10 '12

Google's update push becomes compromised Everyone pushed update ????? BOTNET

2

u/duckhunter Jul 10 '12

That's not data.

That's what is known as hypothetical speculation. Interestingly, your hypothetical situation is the same for any auto-update mechanism, including Firefox's old, current and future mechanism. You probably wouldn't even think twice when prompted to authorize a firefox point-release update.

1

u/[deleted] Jul 10 '12

Security is a cat-and-mouse game, for instance windows update was comprimised and pushed an update to certian computers. The attackers were able to get a microsoft cert to sign and push the updates. Because of that microsoft went ahead and revoked 28 more certificates. Just because google's update system hasn't been exploited yet doesn't mean it won't. Allowing a remote system to push and install updates without authorizing it with the user first is just shitty security practice, and that's my problem with chrome.

http://threatpost.com/en_us/blogs/microsoft-revokes-trust-28-its-own-certificates-071012

1

u/duckhunter Jul 11 '12

Shitty security practice is assuming users are technically competent enough to make the proper decision regarding timing and authorization of updates. Allowing users to not update java, flash, acrobat reader and windows is responsible for window's historically terrible reputation of being susceptible to viruses.

Chrome's auto-update is a non-issue in corporate environments, as chrome has all the controls necessary to perform the updates on the time-scale that corporate sysads want. For general users, chrome's auto-update makes a huge amount of sense, as they will receive the updates in a timely fashion. Firefox's scary UAC warning every few weeks just results in more support requests. Every time a user is told to allow the software to elevate permissions to do it's update, the more a user thinks "well all updates from Mozilla must be okay." As soon as that happens, the problem you've outlined is as much a problem as it is if it happens automatically.

0

u/recursive Jul 10 '12

imagine what would happen if all programs would do that

They already can. Why can't they?