FF 56 not secure? Also NS 5.1.8.7

Ask for help about NoScript, no registration needed to post
harryray2
Posts: 16
Joined: Wed Mar 08, 2017 4:53 pm

FF 56 not secure? Also NS 5.1.8.7

Post by harryray2 »

I have a vague recollection of you saying that FF56 is not as secure as 55, is that correct?
I'm currently using 55.0.3 and was thinking of going to 56 (not quantum, under any circumstances)

Also I've managed to install Noscript 5.1.8.7 (thanks to the hack)...does this correct the bug that Zerodium was going on about?

Thanks a lot.
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:55.0) Gecko/20100101 Firefox/55.0
User avatar
therube
Ambassador
Posts: 7929
Joined: Thu Mar 19, 2009 4:17 pm
Location: Maryland USA

Re: FF 56 not secure? Also NS 5.1.8.7

Post by therube »

FF56 is not as secure as 55, is that correct?
No.
I'm currently using 55.0.3 and was thinking of going to 56 (not quantum, under any circumstances)
If anything, I'd think you'd want to be on 52.9.0 ESR.
(Now that, the ESR version, does have later security updates then FF 56. And will be as up to date, security wise, in FF, pre-Quantum, that you can be.)

Likewise, you'll want to ensure that you disable updates.
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.19) Gecko/20110420 SeaMonkey/2.0.14 Pinball NoScript FlashGot AdblockPlus
Mozilla/5.0 (Windows NT 5.1; rv:52.0) Gecko/20100101 SeaMonkey/2.49.5
barbaz
Senior Member
Posts: 10847
Joined: Sat Aug 03, 2013 5:45 pm

Re: FF 56 not secure? Also NS 5.1.8.7

Post by barbaz »

harryray2 wrote:I have a vague recollection of you saying that FF56 is not as secure as 55, is that correct?
Quite the opposite. FF56 is more secure than 55 - https://www.mozilla.org/security/adviso ... sa2017-21/
harryray2 wrote:Also I've managed to install Noscript 5.1.8.7 (thanks to the hack)...does this correct the bug that Zerodium was going on about?
Yes, as mentioned in the changelog -

Code: Select all

v 5.1.8.7
=============================================================
x [Security] Fixed script blocking bypass zero-day (thanks
  Zerodium for unresponsible disclosure,
  https://twitter.com/Zerodium/status/1039127214602641409)
*Always* check the changelogs BEFORE updating that important software!
-
Post Reply