Firefox 48.0

The announcement for Firefox 47.0 highlights a few changes: synchronized tabs (between Firefox instances), improved video playback, and some security and performance improvements for Android users.

According to the release notes, Firefox 47.0 takes a few more steps in the process of moving away from Flash and toward HTML5 for video, and removes support for some older technologies related to plugins. The click-to-activate plugin whitelist, a security feature that was introduced in 2013, has been removed.

Most importantly, Firefox 47.0 fixes at least thirteen security issues. So don’t delay, update Firefox as soon as you can.

Check your Firefox version and trigger an update by navigating to its About page:

  1. Click the ‘hamburger’ (three horizontal bars) menu button at the top right.
  2. Click the question mark at the bottom of the menu.
  3. Click ‘About Firefox’ in the menu.

TeamViewer: security risk

The free-for-personal-use remote control software TeamViewer is currently under intense scrutiny. Large numbers of users are reporting unauthorized access to their computers, theft of login credentials, and in some cases, access to online financial systems and theft of funds.

It remains unclear exactly how these unauthorized intrusions are happening. TeamViewer officials are so far denying that the software has been hacked, insisting that the current surge in TeamViewer-based attacks are the result of password re-use, combined with the recent publication of several databases of stolen credentials.

Until we know for sure what’s going on, we recommend removing TeamViewer from all computers on which it is installed.

If removal is not an option, as may the case for some support setups, then you should configure TeamViewer to not start with Windows, only start it when asked to do so by support staff, and then close it when their work is complete.

TeamViewer General Settings
Recommendation: disable the option that starts TeamViewer with Windows.

You should also avoid using fixed, personal passwords, relying instead on the temporary passwords TeamViewer generates when it is started, or at least make sure that your personal passwords are strong and unique. Oddly, there’s no way to disable a fixed, personal password, once it’s set up, so your only option in that case is to set it to something very long and random.

TeamViewer Security settings
Recommendations: set the personal password to something very long, complex, and unique, then don’t use it. Avoid the ‘Grant easy access’ feature. Change password strength of random passwords to 10 characters.

Criticism of TeamViewer is building, and the company’s response to this issue has been somewhat less than stellar. If they are convinced that the problem is re-used passwords, why have they not forced a password change for all TeamViewer accounts?

TeamViewer’s makers also seem unwilling to consider the notion that the software itself has been hacked in some way, instead focusing on TeamViewer accounts. An account is not required to use TeamViewer, and exists only as a master address book for people who use TeamViewer to access many different computers. If your TeamViewer account is compromised, an attacker will then have full access to all computers in your account.

To their credit, Teamviewer is working to add new features to the software that should beef up its security. But the new features only affect TeamViewer accounts. If you don’t have a TeamViewer account, you won’t see any benefit.

Update 2016Jun06: TeamViewer management continues to insist that the problem only affects TeamViewer accounts, not the TV desktop client. We recommend avoiding TV accounts if possible. If that’s not an option, make sure you enable two factor authentication (2FA) for the account, and use a complex, unique password.

There’s a lot of discussion about this over on Reddit. One post contains reports from users who have experienced TeamViewer-related intrusions. Another provides instructions for determining whether your computer has been accessed via unauthorized use of TeamViewer.

Meanwhile, we’re wondering whether it might be helpful if TeamViewer showed a large red warning when setting up an account, like this:
WARNING: if there's only one site or service where you use a strong password, let it be your TeamViewer account. Because if someone gets access to your TeamViewer account, they will also have full access to all of the computers you access through your account.

Vivaldi: not ready to replace Firefox

Well, I tried. I used Vivaldi as my main web browser for a month, and while there’s a lot to like, I found I had to change the way I work to get around its limitations and problems.

The biggest problem is Vivaldi’s inconsistent and confusing handling of links, bookmarks, and tabs. The Vivaldi developers have apparently failed to grasp that links should behave differently, depending on their context.

The bookmark editor is extraordinarily clunky, which is surprising, given that it should be a simple feature to code.

A lot of basic functionality that I take for granted in Firefox and other browsers is still missing from Vivaldi. Dragging and dropping bookmarks (eg. from the address bar to the bookmark sidebar) doesn’t work. Hovering the mouse over a bookmark doesn’t show the full URL. There’s no way to edit bookmarks directly in the bookmark toolbar. The right-click context menu for images doesn’t include a ‘Properties’ option. And so on.

Vivaldi’s developers seem to be aware of these issues, and have been working on them in developer ‘snapshot’ versions of the browser. I started using the snapshot versions in the hope that I’d get some relief from the problems I mentioned, but instead ran into even more problems.

Meanwhile, I’ve switched back to Firefox. I’m still optimistic about Vivaldi, but for now I’m only using it experimentally.

Latest Hard Drive reliability report from BackBlaze

Backblaze provides online backup services. The core of their service is an enormous collection of hard drives of various makes, capacities and models. Backblaze tracks the reliability of the hard drives in their systems, and publishes their findings yearly.

This year’s report shows that HGST (Hitachi) drives are still the most reliable, but also shows substantial improvement in Seagate drives over previous years.

Rants and musings on topics of interest. Sometimes about Windows, Linux, security and cool software.