Page 1 of 1

FF 56 not secure? Also NS 5.1.8.7

Posted: Fri Sep 14, 2018 8:24 pm
by harryray2
I have a vague recollection of you saying that FF56 is not as secure as 55, is that correct?
I'm currently using 55.0.3 and was thinking of going to 56 (not quantum, under any circumstances)

Also I've managed to install Noscript 5.1.8.7 (thanks to the hack)...does this correct the bug that Zerodium was going on about?

Thanks a lot.

Re: FF 56 not secure? Also NS 5.1.8.7

Posted: Fri Sep 14, 2018 8:53 pm
by therube
FF56 is not as secure as 55, is that correct?
No.
I'm currently using 55.0.3 and was thinking of going to 56 (not quantum, under any circumstances)
If anything, I'd think you'd want to be on 52.9.0 ESR.
(Now that, the ESR version, does have later security updates then FF 56. And will be as up to date, security wise, in FF, pre-Quantum, that you can be.)

Likewise, you'll want to ensure that you disable updates.

Re: FF 56 not secure? Also NS 5.1.8.7

Posted: Fri Sep 14, 2018 9:26 pm
by barbaz
harryray2 wrote:I have a vague recollection of you saying that FF56 is not as secure as 55, is that correct?
Quite the opposite. FF56 is more secure than 55 - https://www.mozilla.org/security/adviso ... sa2017-21/
harryray2 wrote:Also I've managed to install Noscript 5.1.8.7 (thanks to the hack)...does this correct the bug that Zerodium was going on about?
Yes, as mentioned in the changelog -

Code: Select all

v 5.1.8.7
=============================================================
x [Security] Fixed script blocking bypass zero-day (thanks
  Zerodium for unresponsible disclosure,
  https://twitter.com/Zerodium/status/1039127214602641409)