Advance notification for May 2014 Patch Tuesday

Next Tuesday we’ll find out whether Microsoft is going to stick to its original plan and stop providing Windows XP security updates to us ordinary folks.

According to the Advance Notification post on the MSRC blog, this month’s updates will include eight bulletins, with two of those being Critical. The updates affect the usual suspects, including Windows, Office, Internet Explorer and .NET.

The more technical Advance Notification security bulletin on the TechNet Security Tech Center blog definitely does not list Windows XP anywhere.

DropBox issue exposes private documents

Security researchers recently discovered a flaw in DropBox that could allow access to users’ private documents in certain circumstances. DropBox responded quickly to fix the vulnerability. It’s not clear whether the vulnerability was known to – or exploited by – any nefarious persons.

If you use DropBox, you should review your Shared Links settings and restrict shared links to collaborators only.

Opera 21

The latest Webkit-based Opera is version 21.0.1432.57. There’s nothing much of interest in this new version, with the major change being the use of ‘Aura’, an improved desktop window manager that’s also part of the toolkit used by Google for its Chromium O/S and Chrome web browser.

There’s still no sidebar, which makes one wonder whether Opera will ever recover its former full-featured glory. The developers keep insisting that they will add missing features back to the browser, but if they’re pushing out major releases with nothing changed except a slightly faster user interface, it seems they are concentrating on the wrong things.

There are apparently no security fixes in this version.

Microsoft issues special update for Internet Explorer

We recently reported on a serious vulnerability affecting all versions of Internet Explorer that is being exploited on the web.

Well, it appears that Microsoft sees this vulnerability as very serious, because they are planning to release an update – later today – that addresses the problem. This is an ‘out-of-band’ update, meaning that it’s considered too important to wait for the next Patch Tuesday.

Just in case you were wondering, this vulnerability affects all versions of Internet Explorer on all versions of Windows, including Windows XP. But the patch will not be made available for Windows XP computers.

Update 2014May02: Surprisingly, Microsoft has decided to make this update available for Windows XP. I confirmed this by running Microsoft Update on my WinXP test system: security update 2964358 was offered, and I installed it without any difficulties. Reading through the associated bulletin (MS14-021) there is no explanation for this decision, but there is confirmation, in the section titled “Security Update Deployment
– Windows XP (all editions)”, and in a related post on the MSRC blog. The Verge has additional details, as does Ars Technica. The Ars Technica post includes the official explanation from Microsoft:

Even though Windows XP is no longer supported by Microsoft and is past the time we normally provide security updates, we’ve decided to provide an update for all versions of Windows XP (including embedded) today. We made this exception based on the proximity to the end of support for Windows XP. The reality is there have been a very small number of attacks based on this particular vulnerability and concerns were, frankly, overblown. Unfortunately this is a sign of the times and this is not to say we don’t take these reports seriously. We absolutely do.

Update 2014May02: Another Ars Technica post makes the argument that releasing a patch for Windows XP was a mistake. The moment of truth will be Patch Tuesday for May 2014: will Microsoft stick to its guns and leave Windows XP out of the next set of patches?

Firefox 29 released

Another new version of Firefox was announced on April 29.

Version 29 is touted by Mozilla as ‘elegant’ and ‘the most customizable’ Firefox ever, but there’s been a lot of noise on the web from people who are unhappy with the user interface changes.

It’s not really clear why many major browser developers are trying to make their browser look exactly like Google’s Chrome, but that does seem to be what’s happening. A few months ago, Opera chucked their browser engine in favour of WebKit, with the result being that Opera is now almost indistinguishable from Chrome. Mozilla hasn’t gone that far: their browser engine hasn’t changed, but in terms of appearance, Firefox now looks a lot more like Chrome. Perhaps they think that if Firefox looks like Chrome, users won’t realize they’re not actually using Chrome.

Has anyone done any actual usability studies on these UI elements that are now so popular among developers, like rounded corners on everything? Do rounded corners make people more productive? I doubt it. Another example is Firefox 29’s tab bar, which (besides having those awesome rounded corners we should apparently care so much about) now makes unselected tabs fade out so that they are hardly visible. How is this a good thing? Mozilla seems to think that being able to read what’s on those unselected tabs is a major distraction. Nope.

As for Firefox 29 being more customizable, I beg to differ. I was previously able to open and close the bookmark toolbar with a single click of a toolbar icon. That icon is nowhere to be seen in Firefox 29. Instead, I now have to click the ‘Show your bookmarks’ icon, then click ‘View bookmarks sidebar’. This is progress?

The release notes page for Firefox 29 lists several new features and changes, none of which are particularly useful or interesting.

The best thing about Firefox 29, in my opinion, is that web site favicons – those little icons that appear next to the page title in the tab bar and desktop shortcuts – now seem to work reliably. Previous Firefox versions had a lot of trouble with some favicons.

Several security issues were fixed in version 29, so even if you think you’ll hate the new UI, you should probably upgrade anyway.

On a related note, despite my having diligently reported my problems with the Firefox release notes pages (bug #973335) and version announcement pages (bug #973330), Mozilla has done nothing to improve them, as you can see from the pages for Firefox 29.

Ars Technica has their own review of the changes in Firefox 29.