Firefox skirts Windows security feature to make silent updates happen
Firefox 12, set to release Tuesday, sidesteps Windows' UAC
Computerworld - Mozilla will ship Firefox 12 tomorrow with a key component of its years-long silent update project.
Firefox 12, which got the green light from Mozilla last week, is slated to release on Tuesday, April 24.
Among the changes to Firefox 12, the most noticeable to Windows users will be the disappearance of the UAC, or "user account control," prompt on Vista and Windows 7 during updates.
UAC is a security feature introduced in Vista -- and in a less-intrusive form, tucked into Windows 7, too -- that requires users to agree to most program installations.
Firefox 12 will be the first edition from the open-source developer that sidesteps UAC.
"[UAC] makes things like automated software updates hard to do without user interaction," Brian Bondy, a Firefox platform engineer, wrote in a March blog post. "If we don't have access to write into Program Files to perform an update, then we have to ask for elevated permissions. We ask for elevated permissions today when applying updates."
In effect, UAC stymies no-user-action-required updates, or "silent updates." UAC-bypass has been one of the five pieces in Firefox's project to introduce silent updates, which is nearing completion but won't wrap up until this summer.
Firefox skips UAC by substituting a Mozilla-created Windows service for the traditional installation process.
Google's Chrome, which has featured silent updating since its 2008 debut, installs its code in the user's folder within Windows to avoid UAC. Mozilla rejected that route.
"We chose not to because it can be an administrative headache for some people who manage updates themselves and have to maintain an installation for every user," Bondy wrote.
Mozilla has said that sidestepping UAC makes sense.
"The repeated prompting is unnecessary because the first time that you accept the prompt you indicate that you put your trust in Firefox," the company said in a February blog post on silent updating. "After you have granted Firefox permission to update it should continue to be able to update future versions of Firefox without prompting you again."
The final component of silent updating, responsible for launching and completing the update entirely in the background, will land in Firefox 13, scheduled to ship June 5, or Firefox 14, set to ship July 17.
Mozilla has been working on silent updating for nearly two years. At one point, it thought it could add the feature to Firefox 4, which shipped in March 2011, but abandoned work when that version was delayed several times for other reasons. Late last year, it said it was shooting for silent updating in Firefox 10, which debuted in January. Those plans were also scrapped.
Implementing silent updating would make Firefox only the third browser to offer the feature, after Chrome and Microsoft's Internet Explorer (IE).
Last December, Microsoft jumped on the silent update bandwagon when it announced it would automatically upgrade IE to the newest browser suitable for each version of Windows. Before the new practice began in January 2012, Microsoft had asked users for their permission before upgrading IE from one version to the next, even if Windows' automatic update service was enabled.
IE's automatic upgrading kicked off in Brazil and Australia only, but Microsoft plans to expand the practice worldwide this year.
Also tomorrow, Mozilla will push Firefox 3.6 into retirement. The company has been dunning users with pleas to upgrade for weeks, and will take the unusual step of automatically upgrading version 3.6 to Firefox 12 after the latter's release.
According to Web metrics company Net Applications, Firefox 3.6 accounted for 13% of all copies of Firefox used last month, down from 79% one year earlier.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed . His email address is firstname.lastname@example.org.
- Workarounds to purge search bar from Firefox's new tab page are available
- Mozilla ships Firefox 31, adds search to new tab page
- Microsoft's IE steps back from the brink of irrelevance
- Firefox falters, falls to record low in overall browser share
- Firefox risks user backlash by adding search box to new tab page
- Google unseats Microsoft as the U.S. browser powerhouse
- Safari, Chrome push to mask URLs
- Chrome on Windows champs at the 64-bit
- Google pulls trigger, cripples some Chrome add-ons
- Microsoft shoots to shorten Internet Explorer's long tail
Read more about Desktop Apps in Computerworld's Desktop Apps Topic Center.
- HTTP Status Code Cheat Sheet Look at the Graph, Find the Code and Boom - You're Solving Problems. Identifying and understanding common HTTP status codes can go a...
- Simple Solution, Big Capability Meet growing employee and business demands by connecting up to 1,000 users with powerful collaboration capabilities with a single, integrated platform -- Cisco...
- The Business Value of Continuous Delivery Download this whitepaper to learn more about the business value of Continuous Delivery and see why it could be a game changer for...
- Ten Factors Shaping the Future of Application Delivery Download this research report conducted by Enterprise Management Associates (EMA) to learn how those that are seeking to accelerate application delivery are leveraging...
- Business-driven data protection Setting up data protection infrastructures with your organizations' core mission or business in mind is key. In this webinar, the ARCserve team will...
- On-Demand Webinar: Mind the Gap! Watch the webinar featuring Bob Janssen, CTO and Co-Founder of RES Software, to start building a solid foundation for business and IT to... All Desktop Apps White Papers | Webcasts