Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
maskenfreiheit
Dec 30, 2004

Xenoveritas posted:

So it turns out that Firefox has decided that they want to do "staged rollouts" of their updates, slowly letting more and more people access them over several weeks.

Problem: this includes security updates.

Firefox won't let me install Firefox 55 despite the fact that it fixes 5 critical security flaws. You can't force the update. You can't just install the latest version since it's already installed and they use a "stub installer" that downloads the rest. Your only option is to uninstall the entire thing and install from scratch, just to get security updates.

:eyepop:

Adbot
ADBOT LOVES YOU

Silver Alicorn
Mar 30, 2008

𝓪 𝓻𝓮𝓭 𝓹𝓪𝓷𝓭𝓪 𝓲𝓼 𝓪 𝓬𝓾𝓻𝓲𝓸𝓾𝓼 𝓼𝓸𝓻𝓽 𝓸𝓯 𝓬𝓻𝓮𝓪𝓽𝓾𝓻𝓮
messed up if true

Wiggly Wayne DDS
Sep 11, 2010



can't see where security patches aren't being handled properly, just that features are a/b tested for crashes. then again their wiki still thinks aurora exists so who knows what's happening

pairofdimes
May 20, 2001

blehhh

Xenoveritas posted:

So it turns out that Firefox has decided that they want to do "staged rollouts" of their updates, slowly letting more and more people access them over several weeks.

Problem: this includes security updates.

Firefox won't let me install Firefox 55 despite the fact that it fixes 5 critical security flaws. You can't force the update. You can't just install the latest version since it's already installed and they use a "stub installer" that downloads the rest. Your only option is to uninstall the entire thing and install from scratch, just to get security updates.

Did you try running the installer? I was on 54, ran the installer, and it updated me to 55 just fine. I used the download link from this page which seems to just link you to a regular stub installer: https://support.mozilla.org/en-US/kb/update-firefox-latest-version

Carbon dioxide
Oct 9, 2012

pairofdimes posted:

Did you try running the installer? I was on 54, ran the installer, and it updated me to 55 just fine. I used the download link from this page which seems to just link you to a regular stub installer: https://support.mozilla.org/en-US/kb/update-firefox-latest-version

I was on 54, couldn't install update from the About screen (it just claims I have the latest version), downloaded the installer and ran that, it said to restart Firefox to start the newly installed version. Did so, I'm still on 54, still no update available.

So that installer only works if your system has already been 'selected' to be in the next group to get an update.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Carbon dioxide posted:

I was on 54, couldn't install update from the About screen (it just claims I have the latest version), downloaded the installer and ran that, it said to restart Firefox to start the newly installed version. Did so, I'm still on 54, still no update available.

So that installer only works if your system has already been 'selected' to be in the next group to get an update.

file that and PM me the bug number?

Carbon dioxide
Oct 9, 2012

Subjunctive posted:

file that and PM me the bug number?

That means finding out where firefox' bug reports have to go and how to file them. :effort:

pairofdimes
May 20, 2001

blehhh

Carbon dioxide posted:

I was on 54, couldn't install update from the About screen (it just claims I have the latest version), downloaded the installer and ran that, it said to restart Firefox to start the newly installed version. Did so, I'm still on 54, still no update available.

So that installer only works if your system has already been 'selected' to be in the next group to get an update.

Can you try again? I searched for why Firefox wasn't updating to 55 and it looks like all updates were stopped for a while due to a bug: No pages are rendered / Shutdownhang crashes with aetpkss1.dll PKCS#11 module in Firefox 55

Raere
Dec 13, 2007

I had the same issue where I was on 54 and the about page wouldn't show any updates. I downloaded the full installer for 55 and it installed fine. It updated itself to 55.0.1 just fine today.

Carbon dioxide
Oct 9, 2012

pairofdimes posted:

Can you try again? I searched for why Firefox wasn't updating to 55 and it looks like all updates were stopped for a while due to a bug: No pages are rendered / Shutdownhang crashes with aetpkss1.dll PKCS#11 module in Firefox 55

Okay, after a double check I found it DID install the 55 version but an additional 'bug' happened.

Windows 10 machine.
I had the 32-bit version (Firefox 54) installed in "Program Files (x86)/Mozilla Firefox". The installer which I downloaded from the official website installed 64-bit Firefox 55 in "Program Files/Mozilla Firefox", without telling me. It also did not uninstall or overwrite the 32-bit version. The Firefox shortcut on the desktop was updated to start the new 64-bit installation, however the pinned shortcut on my taskbar was NOT updated and still pointed at the Firefox 54 version.

I have now uninstalled the 32-bit version and now everything is okay. But that was a rather confusing thing.

E: Also apparently you cannot run 32-bit and 64-bit simultanously. If you start one and then try to start the other, it just opens a new windows of the version you got already running.

Carbon dioxide fucked around with this message at 20:40 on Aug 12, 2017

pseudorandom name
May 6, 2007

lol you have shortcuts on your desktop

James Baud
May 24, 2015

by LITERALLY AN ADMIN
Android - on Nexus/Pixel, at least - recently figured out that it would be good to let manual update checks bypass the staged rollouts since determined people were just going to get it another way more complicated way, maybe Firefox will be nice enough to do that too... I was annoyed at having to hit the website and download the (no visible sign of a version number, run it blindly) stub installer the day the update came out too. I think Mozilla took down/are taking down the ftp site, so didn't try that route.

Incidentally, I don't know what happened in the last year but Chrome's resource utilization has blown up making it unusable on machines that it formerly on ran just fine. (So I switched to Firefox on those work PCs after returning from an extended parental leave.)

Raere
Dec 13, 2007

James Baud posted:

Incidentally, I don't know what happened in the last year but Chrome's resource utilization has blown up making it unusable on machines that it formerly on ran just fine. (So I switched to Firefox on those work PCs after returning from an extended parental leave.)

Have you tried purchasing a new computer? Perhaps a genuine Google Chromebook(R)?

apseudonym
Feb 25, 2011

James Baud posted:

Android - on Nexus/Pixel, at least - recently figured out that it would be good to let manual update checks bypass the staged rollouts since determined people were just going to get it another way more complicated way, maybe Firefox will be nice enough to do that too... I was annoyed at having to hit the website and download the (no visible sign of a version number, run it blindly) stub installer the day the update came out too. I think Mozilla took down/are taking down the ftp site, so didn't try that route.

Incidentally, I don't know what happened in the last year but Chrome's resource utilization has blown up making it unusable on machines that it formerly on ran just fine. (So I switched to Firefox on those work PCs after returning from an extended parental leave.)

Probably a bit of Chrome and a lot of websites, people keep bloating and bloating websites to a painful degree.


Also gently caress the web.

Dylan16807
May 12, 2010

Carbon dioxide posted:

E: Also apparently you cannot run 32-bit and 64-bit simultanously. If you start one and then try to start the other, it just opens a new windows of the version you got already running.

you can run firefox with -no-remote if you want to start another process. that applies whether you use the same exe or a different one.

might need -profilemanager too

edit: single dashes at the start, apparently?

Dylan16807 fucked around with this message at 02:49 on Aug 13, 2017

chestnut santabag
Jul 3, 2006

Xenoveritas posted:

So it turns out that Firefox has decided that they want to do "staged rollouts" of their updates, slowly letting more and more people access them over several weeks.

Problem: this includes security updates.

Firefox won't let me install Firefox 55 despite the fact that it fixes 5 critical security flaws. You can't force the update. You can't just install the latest version since it's already installed and they use a "stub installer" that downloads the rest. Your only option is to uninstall the entire thing and install from scratch, just to get security updates.

and just in case you still don't have the full installer, you can download it from https://www.mozilla.org/en-US/firefox/all/ or directly from https://ftp.mozilla.org/pub/firefox/releases/

effika
Jun 19, 2005
Birds do not want you to know any more than you already do.
All I know is I upgraded to Firefox 55 this weekend, and then today when I upgraded to Fedora 26 it downgraded Firefox back to 54.

cinci zoo sniper
Mar 15, 2013




i still cant upgrade to firefox 55

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

Linux distributors are the worst. install your browsers directly from the vendors

cinci zoo sniper
Mar 15, 2013




Subjunctive posted:

Linux distributors are the worst. install your browsers directly from the vendors

im on windows and installed it directly from the vendor

geonetix
Mar 6, 2011


same for os x here, what's up with that?

spankmeister
Jun 15, 2008






Mozilla has a bad update policy that's what's up.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

spankmeister posted:

Mozilla is bad that's what's up.
after chrome started doing a lot of major updates quickly, mozilla changed their update policies to match. now that windows 10 is out, mozilla broke their updater. you just can't trust them.

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

did they break the updater? nightly is still working, but I did see some tweets go by about things being rough on Windows for a week or two

10-year-ago me would have cared enough to ask about it

Hed
Mar 31, 2004

Fun Shoe

cinci zoo sniper posted:

i still cant upgrade to firefox 55

somebody call Sammy Hagar

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Subjunctive posted:

did they break the updater? nightly is still working, but I did see some tweets go by about things being rough on Windows for a week or two

10-year-ago me would have cared enough to ask about it
according to everyone else they're doing some a/b testing on updates, to include security updates, and if you're not in the right group you can't update

Xenoveritas
May 9, 2010
Dinosaur Gum

Carbon dioxide posted:

Okay, after a double check I found it DID install the 55 version but an additional 'bug' happened.

Windows 10 machine.
I had the 32-bit version (Firefox 54) installed in "Program Files (x86)/Mozilla Firefox". The installer which I downloaded from the official website installed 64-bit Firefox 55 in "Program Files/Mozilla Firefox", without telling me. It also did not uninstall or overwrite the 32-bit version. The Firefox shortcut on the desktop was updated to start the new 64-bit installation, however the pinned shortcut on my taskbar was NOT updated and still pointed at the Firefox 54 version.

I have now uninstalled the 32-bit version and now everything is okay. But that was a rather confusing thing.

E: Also apparently you cannot run 32-bit and 64-bit simultanously. If you start one and then try to start the other, it just opens a new windows of the version you got already running.

Exactly what happened to me - I ran the installer and it installed the 64-bit version, didn't touch the 32-bit version, didn't change the pinned version, but also didn't make the 64-bit version the new "default web browser" so depending on how you launched it, you'd either get Firefox 54 or Firefox 55.

And while I find A/B testing goddamned infuriating as a user I do understand why it gets done.

But seriously - A/B testing security updates?! What the gently caress?!! Either backport the security updates to the older version or do the same A/B testing done for Electrolysis where it either was enabled or not but you still got updates. Not giving people an update with five critical security updates and lying to them and saying they're "up to date" if they check the About box - just - what the gently caress?!

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

is this bubbling up in the blogs and twitters?? or do we have a case of yospos FIRST POST

maskenfreiheit
Dec 30, 2004
i have to restart firefox to update and i set it to clear cookies on restart so i don't want to... too many 2fs

fishmech
Jul 16, 2006

by VideoGames
Salad Prong
still haven't seen any evidence that security updates are being "a/b tested" but rather just that 55 was too buggy and they're holding off until 55.0.2 is out (55.0.1 was already out)

akadajet
Sep 14, 2003

Always fun to see on the page of a library you're playing with.

https://node-postgres.com/announcements

edit: lol

quote:

connecting to an untrusted database and executing a query which returns results where any of the column names are malicious.

akadajet fucked around with this message at 03:21 on Aug 14, 2017

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal
who the gently caress connects to an untrusted postgres db? maybe i'm just sheltered or something but gently caress

oh and come on, you forgot the best part

quote:

executing unsafe, user-supplied sql which contains a malicious column name like the one above

no really it's not a sql injection it's a feature. i'm serious. please stop laughing!

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Deep Dish Fuckfest posted:

who the gently caress connects to an untrusted postgres db? maybe i'm just sheltered or something but gently caress

psql -h sql.supermeatboy.com -u uglyburpandfartgame -p foridiots high_scores

akadajet
Sep 14, 2003

The craziness is needing to do an eval at all.

Daman
Oct 28, 2011
so we all know kaspersky is the best AV, but now they've really cemented the title.

new official marketing





(USER WAS PUT ON PROBATION FOR THIS POST)

akadajet
Sep 14, 2003

mods?

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki

Daman posted:

so we all know kaspersky is the best AV, but now they've really cemented the title.

new official marketing





and i thought the roscomnadzor anime girl was bad

Deep Dish Fuckfest
Sep 6, 2006

Advanced
Computer Touching


Toilet Rascal

Cocoa Crispies posted:

psql -h sql.supermeatboy.com -u uglyburpandfartgame -p foridiots high_scores

heh, i remember that. although i think it was mysql, which is even more shameful

Adbot
ADBOT LOVES YOU

Dylan16807
May 12, 2010

Xenoveritas posted:

But seriously - A/B testing security updates?! What the gently caress?!! Either backport the security updates to the older version or do the same A/B testing done for Electrolysis where it either was enabled or not but you still got updates. Not giving people an update with five critical security updates and lying to them and saying they're "up to date" if they check the About box - just - what the gently caress?!
if a patch is from the 55 branch and not backported, that means it's already several weeks old on release day. it had to go through developer and nightly builds which are each a release cycle ahead. another week wouldn't really hurt.

if it's a critical security patch that got backported to 55 but not to 54, then they screwed up.

right now I'm assuming it's the former, but maybe teams didn't talk to each other and they stumblefucked into doing the latter.

  • Locked thread