Firefox skirts Windows security feature to make silent updates happen
Firefox 12, set to release Tuesday, sidesteps Windows' UAC
Computerworld - Mozilla will ship Firefox 12 tomorrow with a key component of its years-long silent update project.
Firefox 12, which got the green light from Mozilla last week, is slated to release on Tuesday, April 24.
Among the changes to Firefox 12, the most noticeable to Windows users will be the disappearance of the UAC, or "user account control," prompt on Vista and Windows 7 during updates.
UAC is a security feature introduced in Vista -- and in a less-intrusive form, tucked into Windows 7, too -- that requires users to agree to most program installations.
Firefox 12 will be the first edition from the open-source developer that sidesteps UAC.
"[UAC] makes things like automated software updates hard to do without user interaction," Brian Bondy, a Firefox platform engineer, wrote in a March blog post. "If we don't have access to write into Program Files to perform an update, then we have to ask for elevated permissions. We ask for elevated permissions today when applying updates."
In effect, UAC stymies no-user-action-required updates, or "silent updates." UAC-bypass has been one of the five pieces in Firefox's project to introduce silent updates, which is nearing completion but won't wrap up until this summer.
Firefox skips UAC by substituting a Mozilla-created Windows service for the traditional installation process.
Google's Chrome, which has featured silent updating since its 2008 debut, installs its code in the user's folder within Windows to avoid UAC. Mozilla rejected that route.
"We chose not to because it can be an administrative headache for some people who manage updates themselves and have to maintain an installation for every user," Bondy wrote.
Mozilla has said that sidestepping UAC makes sense.
"The repeated prompting is unnecessary because the first time that you accept the prompt you indicate that you put your trust in Firefox," the company said in a February blog post on silent updating. "After you have granted Firefox permission to update it should continue to be able to update future versions of Firefox without prompting you again."
The final component of silent updating, responsible for launching and completing the update entirely in the background, will land in Firefox 13, scheduled to ship June 5, or Firefox 14, set to ship July 17.
Mozilla has been working on silent updating for nearly two years. At one point, it thought it could add the feature to Firefox 4, which shipped in March 2011, but abandoned work when that version was delayed several times for other reasons. Late last year, it said it was shooting for silent updating in Firefox 10, which debuted in January. Those plans were also scrapped.
Implementing silent updating would make Firefox only the third browser to offer the feature, after Chrome and Microsoft's Internet Explorer (IE).
Last December, Microsoft jumped on the silent update bandwagon when it announced it would automatically upgrade IE to the newest browser suitable for each version of Windows. Before the new practice began in January 2012, Microsoft had asked users for their permission before upgrading IE from one version to the next, even if Windows' automatic update service was enabled.
IE's automatic upgrading kicked off in Brazil and Australia only, but Microsoft plans to expand the practice worldwide this year.
Also tomorrow, Mozilla will push Firefox 3.6 into retirement. The company has been dunning users with pleas to upgrade for weeks, and will take the unusual step of automatically upgrading version 3.6 to Firefox 12 after the latter's release.
According to Web metrics company Net Applications, Firefox 3.6 accounted for 13% of all copies of Firefox used last month, down from 79% one year earlier.
Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer, on Google+ or subscribe to Gregg's RSS feed . His email address is email@example.com.
- Workarounds to purge search bar from Firefox's new tab page are available
- Mozilla ships Firefox 31, adds search to new tab page
- Microsoft's IE steps back from the brink of irrelevance
- Firefox falters, falls to record low in overall browser share
- Firefox risks user backlash by adding search box to new tab page
- Google unseats Microsoft as the U.S. browser powerhouse
- Safari, Chrome push to mask URLs
- Chrome on Windows champs at the 64-bit
- Google pulls trigger, cripples some Chrome add-ons
- Microsoft shoots to shorten Internet Explorer's long tail
Read more about Desktop Apps in Computerworld's Desktop Apps Topic Center.
- The Business Value of Continuous Delivery Download this whitepaper to learn more about the business value of Continuous Delivery and see why it could be a game changer for...
- Ten Factors Shaping the Future of Application Delivery Download this research report conducted by Enterprise Management Associates (EMA) to learn how those that are seeking to accelerate application delivery are leveraging...
- HTTP Status Code Cheat Sheet Look at the Graph, Find the Code and Boom - You're Solving Problems. Identifying and understanding common HTTP status codes can go a...
- Architects lead the next generation of data-driven applications Read this whitepaper to find out how application architects can quickly and confidently deliver long-lasting applications that minimize cost, complexity, and risk while...
- What Does it Take to Deliver a Superior Customer Experience? The Two Top-Rated Online Retailers, B&H Photo and Crutchfield Electronics, Share Their Secrets Discuss practical CX tools and service methods such as contact center agents and the use of realtime speech analytics to help contact center...
- Keep Servers Up and Running and Attackers in the Dark An SSL/TLS handshake requires at least 10 times more processing power on a server than on the client. SSL renegotiation attacks can readily... All Desktop Apps White Papers | Webcasts