Mozilla blocks Java in Firefox for some Mac users
Disables outdated plug-in for Firefox on Leopard and earlier
Computerworld - Mozilla this week began blocking outdated versions of a Java plug-in in Firefox for some Mac users after calling the threat posed by the Flashback malware "evident and imminent."
The move came two weeks after Mozilla disabled unpatched versions of Oracle's software on Firefox for Windows.
Although Mozilla said on April 2 that it might add the Java plug-in to Firefox for Mac's blocklist -- a list it maintains of add-ons and plug-ins that the company disables because they're infected with malware or have been targeted by attackers -- it didn't follow through until Monday.
In a post to the company's Add-Ons blog, Mozilla said the delay was due to the uptake of the patched plug-in Apple began distributing April 3.
As Mozilla noted, cleanup efforts have made headway on the number of Macs infected with the Flashback malware. While more than 600,000 Macs were infested with Flashback as recently as two weeks ago, that number fell by 60% last week.
On Tuesday, Symantec -- which had "sinkholed" command-and-control domains used by Flashback to communicate with its makers -- said the botnet had shrunk even more in the last several days, and controlled fewer than 100,000 Macs.
Another reason for Mozilla's pause between blocklisting Java on Windows and Mac: Firefox has a bug.
"There's a bug in Firefox that prevents it from reloading plug-in metadata after an update," acknowledged Mozilla. "This means that even if someone updates Java on Mac, Firefox will continue to say an old and vulnerable version is installed."
Mozilla has fixed the bug and will roll the patch into Firefox 12, which is set for release April 24.
For those reasons, Mozilla instituted only a partial block of the Java plug-in, limiting it to copies of Firefox running on Macs powered by OS X 10.5 or earlier. OS X 10.5 is better known as Leopard.
While Apple no longer packages Oracle's Java with OS X -- it stopped that practice with Lion in July 2011 -- it continues to issue Java security updates to people running Lion as well as 2009's Snow Leopard, or OS X 10.6. Java may be on some Lion systems: Users are prompted to install the software the first time they try to run a Java applet.
Because Apple no longer supports OS X 10.5, or Leopard, its predecessor Tiger or any older operating system, it doesn't ship patches for Java to those users.
"People who are using Mac OS X 10.5 and older won't get the Java update, which means they will remain vulnerable unless they update their operating system or upgrade their hardware," noted Mozilla. "For these users there's no point in waiting, so we have blocked the Java plug-in for them."
Firefox users running OS X 10.5 or earlier, will have JRE 1.6.0_31 and earlier, or JRE versions 1.7.0 through 1.7.0_2 disabled.
Mozilla called its move a "soft block," which means users are notified that the plug-in has been disabled, but they can continue using it at their own risk by clearing the "Disable" box in the notification dialog. Users can also later enable the plug-in from the Plug-ins section of Add-ons Manager by selecting "Add-ons" from the Tools menu.
Firefox users running OS X 10.6 and later will have outdated Java plug-ins disabled next week if they upgrade to version 12 of the browser.
While Mozilla's block of Java on Firefox for Windows didn't go flawlessly -- it mistakenly was issued as a "hard block," which gave users no way to use the plug-in -- there's no evidence of a similar problem on Mozilla's support forum for Mac users after Monday's move.
In a blog post April 6, Christian Holler, a Mozilla security engineer, gave more details on the thinking behind Mozilla's blocking of the Java plug-in.
"As the popularity of the Mac platform has grown so has its attractiveness as a target for attackers," Holler said. "The threat to Mac users is evident and imminent, thus prompting our response on all platforms."
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at
@gkeizer, on Google+ or subscribe to Gregg's RSS feed
. His email address is gkeizer@computerworld.com.
See more by Gregg Keizer on Computerworld.com.
Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Security for Virtualization Learn more.
- When Malware Goes Mobile: Causes, Outcomes and Cures Cybercriminals are increasingly setting their sights on smartphones and other mobile devices. Learn about platform-specific policies and strategies you can employ to protect...
- Protection for Every Enterprise: How BlackBerry 10 Security Works Get an IT-level review of BlackBerry® 10 Security, addressing data leakage protection, certified encryption, containerization and much more.
- Manage Virtualized and Cloud Environments and the New Software-defined Data Center Analyst report by Enterprise Management Associates on the newly announced EMC Service Assurance Suite, and how well it addresses operational challenges and market...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in...
- Enterprise File Sharing: All You Need to Know Security. Scalability. Control. These are just some of the many benefits of enterprise cloud file-sharing that you'll discover in this KnowledgeVault, packed with... All Malware and Vulnerabilities White Papers | Webcasts