Firefox 28 released

There was yet another stealth release of Firefox yesterday. Version 28 was not announced on any of the myriad Mozilla blogs. I only discovered it because of release announcements on CERT and SANS blogs.

According to SANS, at least some of the security fixes in Firefox 28 are the result of successful hacks at the recent Pwn2Own contest. There’s a full list of the security fixes in this version at the top of the ‘Known Vulnerabilities‘ (aka ‘Security Advisories for Firefox’) page for Firefox.

The official release notes page for version 28 shows no improvement over previous release notes pages. But it does list the changes in the latest version, none of which are worthy of note.

Aside: I recently submitted two bugs to the Mozilla bug tracking system for Firefox. Bug #973330 is about the lack of proper announcements for new Firefox versions. Bug #973335 covers the many issues with the release notes pages for Firefox. So far the responses from Mozilla workers have not been encouraging.

Flash 12.0.0.77 released

Adobe announced a new version of Flash yesterday. Version 12.0.0.77 fixes two security vulnerabilities flagged by Adobe as Important.

As usual, Google Chrome will update itself with the latest version of Flash, while Internet Explorer 10 and 11 on Windows 8 and 8.1 will receive the latest Flash updates via Windows Update.

You can check the version of Flash currently installed on your computer (or more accurately, in your browser), by visiting the About Adobe Flash page, and you can download the new version from the Player Download Center (warning: this page will install additional software by default; make sure to uncheck any optional software checkboxes).

Microsoft updates for March 2014

Yesterday was Patch Tuesday, and Microsoft released five updates for Windows, Internet Explorer, and Silverlight. Two of the updates are flagged as Critical. The official summary bulletin has all the technical details, and a post on the MSRC blog has a less technical breakdown of the updates.

As expected, one of this month’s updates fixes the recently-reported zero-day vulnerability in Internet Explorer.

Advance notification of March updates from Microsoft

Patch Tuesday for March 2014 happens on March 11. Microsoft currently plans to publish five new bulletins and associated patches starting at 10am PST on that date. The patches will address vulnerabilities in Windows, Internet Explorer, and Silverlight. Two of the patches are flagged as Critical.

One of the patches will fix the Internet Explorer vulnerability recently reported here.

Firefox showing serious performance problems

Is it just me, or is Firefox behaving more like a lead weight than a web browser lately? Since about version 26, any time I browse a media-heavy site, Firefox starts consuming all my CPU, and doing a ton of I/O. This usually calms down after a while, but it’s extremely annoying.

Sometimes the excessive CPU use is associated with playing Flash videos, in which case a task viewer will usually show that it’s the plugin container and the Flash plugin that are consuming all the CPU. But that’s not always the case.

The Flash plugin seems to crash a lot these days as well. Like every other time I play a video in Firefox. Normally, I’d be happy to blame Adobe, but I’m not convinced it’s their fault this time, because Flash is currently working fine in my other browsers.

One other annoyance in recent versions of Firefox is the way animated GIFs play. They stop, start again, play really fast, then really slow, and so on. Eventually they seem to settle down, but it takes a while.

Is anyone else seeing these problems?

Update 2014Mar11: Disabling all my add-ons seems to have resolved this problem. Now to identify which one.

Windows XP will nag you to upgrade after support ends

Microsoft will prod you to upgrade your Windows XP computers after support for that O/S ends in April.

According to Ars Technica, a message will pop up on the 8th of every month, starting on March 8, 2014. Although this may be viewed as a nuisance by some users, at least the message has a “don’t bother me again” checkbox.

Microsoft is also working on making the transition easier with migration tools and a web site that tells visitors whether they are in fact running Windows XP. And they are encouraging tech-savvy people to assist friends and family with upgrading.

The Windows XP end-of-support site is a good starting point for anyone still running XP.

Rants and musings on topics of interest. Sometimes about Windows, Linux, security and cool software.