On Friday, July 18, 2014 at 3:31:53 PM UTC-5, Gavin Sharp wrote:
>
> ...
>
> With click to play on by default we could probably remove the broad
> block, but we'd want to still block the known-vulnerable versions,
> which would require coming up with a regexp that matches only the
> right version
On Friday, July 18, 2014 at 4:31:53 PM UTC-4, Gavin Sharp wrote:
> https://addons.mozilla.org/en-US/firefox/blocked/p428
> It's not clear why some people in the bug are so up in arms about the
> overly broad block - is the plugin actually useful in ways we weren't
> aware of, or do people just not
On Friday, July 18, 2014 at 8:48:28 AM UTC-4, JW Clements wrote:
> The issue was resolved by Oracle some time ago.
> Continued display of this message is disconcerting to some people and
> unwarranted.
> It was a good thing when the vulnerability was first discovered but it's
> now a bad thing.
>
First, the "overly broad block" was an absolutely lazy way out, and should have
been readdressed long ago.
Second, you (in the collective sense) should "remove the broad block", by all
means. Posthaste.
Third, "block[ing] the known-vulnerable versions, which would require coming up
with a reg
>From an off-thread reply this is:
https://addons.mozilla.org/en-US/firefox/blocked/p428
https://bugzilla.mozilla.org/show_bug.cgi?id=636633
We blocked all versions last year, since it was easier than trying to
block only the vulnerable versions
(https://bugzilla.mozilla.org/show_bug.cgi?id=6366
Which warning are you referring to exactly? Do you have a screenshot?
Gavin
On Fri, Jul 18, 2014 at 5:48 AM, JW Clements wrote:
> The issue was resolved by Oracle some time ago.
> Continued display of this message is disconcerting to some people and
> unwarranted.
> It was a good thing when the
The issue was resolved by Oracle some time ago.
Continued display of this message is disconcerting to some people and
unwarranted.
It was a good thing when the vulnerability was first discovered but it's
now a bad thing.
Could some dev pick this up and clear that message?
Thanks
7 matches
Mail list logo