Skip the navigation
News

Mozilla plans to silently update Firefox

Joins Google, Adobe in auto-update movement to take patching out of users' hands

By Gregg Keizer
August 6, 2010 01:44 PM ET

Computerworld - Taking a page from rival Google's playbook, Mozilla plans to introduce silent, behind-the-scenes security updating to Firefox 4.

The feature, which has gotten little attention from Mozilla, is currently "on track" to make it into the final of Firefox 4, the major upgrade slated to ship before the end of the year. Mozilla has released two beta previews of Firefox 4 in the last four weeks, and has set a third beta for next week.

Firefox 4's silent update will only be offered on Windows, Mozilla has said.

Most updates, including all security updates, will be downloaded and installed automatically without asking the user or requiring a confirmation, said Alex Faaborg, a principal designer on Firefox.

"We'll only be using the major update dialog box for changes like [version] 4 to 4.5 or 5," Faaborg said in a late July message on the "mozilla.dev.apps.firefox" forum. "Unfortunately users will still see the updating progress bar on load, but this is an implementation issue as opposed to a [user interface] one; ideally the update could be applied in the background."

Unlike Google, Mozilla will let users change the default silent service to the more traditional mode, where the browser asks permission before downloading and installing any update.

Chrome is the poster boy for automatic updates. Google's browser kicked off in September 2008 with a then-controversial mechanism that removed the user from the update equation. Chrome continues to rely on an automated service that updates the browser in the background, and can't be switched off.

Taking updates out of the hands of users keeps them safer, Google has claimed. A May 2009 paper co-authored by a Google engineer argued that, "Any software vendor [should] seriously consider deploying silent updates, as this benefits both the vendor and the user, especially for widely used attack-exposed applications like Web browsers and browser plug-ins."

According to "Why Silent Updates Boost Security" (download PDF), 97% of Chrome users were running the latest version of the browser within 21 days of the last update's release. By comparison, 85% of Firefox users were up-to-date in the same span, while only 53% Safari users could say the same.

Faaborg and Robert Strong, the Mozilla engineer who has been writing the behind-the-scenes updater, defended the move toward a Chrome-like service.

"I think the majority of users would prefer an application that doesn't bother them with what they view as little details, where a little detail is a minor update," said Faaborg. "We get a lot of complaints that Firefox updates too often, people can't see the difference with the new version (it was actually a security patch), that we change our mind too much and should just ship one version (it was actually a security patch), etc."

"There are people that don't like being notified of updates," Strong said on the same Mozilla discussion group. "There is 'no one size fits all' behavior for this that will please everyone."

Strong also took exception to the use of the term "forced" to describe how Firefox would keep users up-to-date. "As for 'forced' update ..., Chrome accomplishes this in part by forcing the install of Chrome into the user's profile which has a set of issues associated with it that we don't want to have, so we aren't taking that route," he said.

Mozilla isn't the only major developer toying with changing how its users receive patches: Adobe has added a silent updater to Reader and Acrobat, for instance. At the moment, users must manually switch on the new tool, and Adobe has said it has no plans to enable fully-automated updates without some kind of user permission.

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at Twitter @gkeizer or subscribe to Gregg's RSS feed Keizer RSS. His e-mail address is gkeizer@ix.netcom.com.

Read more about Browsers in Computerworld's Browsers Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Browsers White Papers
Smarter Commerce is redefining value chain visibility
Smarter Commerce is redefining the value chain in the age of the customer. It starts with putting the customer at the center of...
Digital Transformation: Creating New Business Models Where Digital Meets Physical
Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil...
IBM Synchronizes its Commerce 2.0 Strategy with 'Smarter Commerce' Initiative
On March 14, IBM announced "Smarter Commerce", a strategic initiative that addresses the surging market for Commerce 2.0 solutions that take advantage of...
Identity Governance: The Business Imperatives
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make...
CA Technology Brief: CA Point of View: Content Aware Identity & Access Management
This paper explores the concept of content-aware IAM, describes the integrated architecture for this new approach, and highlights the benefits that this approach...
All Browsers White Papers
Browsers Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Browsers Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs