View Full Version : Why is Mozilla Firefox 1.0 better than IE ?
jernst
6th December 2004, 04:40
Originally posted by virus
Fine. Why don't you post some of your passwords here? Keeping them secret won't improve your security ;)
If Neo Neko's passwords (=secrets) are week (=no security) there is no point using them to protect his data.
Hiding secrets in your closed-source code is week as well (reverse engineering, code-leeks) and thus doesn't provide security.
Neo Neko
6th December 2004, 06:30
Originally posted by virus
That's fine. What about malicious code stored in memory? Once you've gained access to the system, you may rely on other OS flaws to keep the fun going. I recognize that it's not FF's fault if the host OS is a piece of crap... but the same "limitation" applies for all software running under Windows - and most of it poses no serious security problems.
Actually most of what you just described covers most if not all of the worst vulnerabilities and security problems. And more or less leads us to this. Worst case scenario it is as insecure as IE but more featurefull and standards compliant. Best case scenario it is worlds more secure than IE but still more featurefull and standards compliant. So even if we loose we win. It is kind of a win win thing.
Originally posted by virus
Yes, I'm making this hypotesis. If it's very popular, it can be an easy target for people that want to exploit it.
Firefox is not aiming to dominate the market like Microsoft. Or in place of Microsoft. That would be practically impossible anyway. They don't have a monopoly to fund their browser product or get install base. Worst case scenario Firefox would fail and the mono-culture that makes such vulnerabilities a catastrophy will continue unhindered. Best case scenario firefox would gain a large portion of the market and re-introduce competition and innovation. Thereby reducing the mono-culture that makes these vulnerabilities a catastrophy. I guess what I am saying is that with Firefox or Moz you can't loose.
Originally posted by virus
I see no reason for an opensource project to be immune and a closed source one no.
No one is claiming immunity. You misunderstand. What is being said is that the impact of that which you are concerned about would be less than it is now. Hence better.
Originally posted by virus
All browser out there have bugs and some security flaws; they're discovered continuously. Thinking that FireFox is/will be perfect and invincible is naive at least.
That is why no one has claimed it. Firefox can be fixed faster. And typically it is fixed faster. And the more people who use it the faster it will get fixed. Unlike IE where no matter how many use it, will not get fixed any faster.
Originally posted by virus
More to the point of my remark: by "too late" I meant to say that reverting to a safer version after the malware has striked won't bring back your lost data.
Never does. What was the point? That will happen whether you use firefox or not. If firefox is worse than IE no one will use it. If IE continues to be worse then Firefox will be used more. Firefox is only about choice. And choice is good.
Originally posted by virus
You're shifting from the main discussion point here. I'm talking about FF extensions written by some random guys over the net. Are we reasonably sure all of them can be stopped timely if they want to do damage?
Oh all the previous discussion led me to believe we were discussing the plugins on the official firefox update page and mozdev. And not random stranger X hosting his own plugin/malware. Sorry. But that probably has something to do with the fact that I don't unquestioningly trust strangers. :p
Originally posted by virus
I trust FF's core, and I'm not trying to say that the main developers will try to "sneak something" into the core. But controlling thousands of extensions that get uploaded/updated daily poses some problems. This has absolutely nothing to do with IE and M$'s faults. Saying "there's no problem because IE is even worse" won't solve security problems in FF (if they exist).
What's the point again? Isn't IE just as vulnerable? Isn't it not a double standard not to hold them just as responsible for what other people do? It's your fault if you download and install a plugin on purpose from someone you don't know and your computer gets infected. However when your computer gets infected via a direveby download instigated by a vunerability at the core of the browser. Well then the browser manufacturer would bear some responsibility.
Originally posted by virus
Fine. Why don't you post some of your passwords here? Keeping them secret won't improve your security ;)
If my passwords were my security I would. But may passwords are not my security. They are keys to my security. Posting them would be insane. I can post the source to the cypher that portects me. That is my security. But that does you little good without the key!
Originally posted by virus
More seriously. You can improve security by writing robust code. It is my opinion - but just my opinion - that writing robust code and keeping it secret can make security even higher, because it requires much more skill to find a flaw by reverse engineering than by staring at a C function.
But here is a flaw in your logic. Keeping code secret leads to it being less robust. And less secure. Conversely having open code means more people can inspect it. Which also means people can find vulnerabilities faster. To exploit and fix. Which measn it will be more robustand secure.
Originally posted by virus
Of course with opensource you've plenty of other advantages, but you're giving away your ability to "make things more difficult" for evildoers. Sure the burglars can enter your home even with a locked door if they're skilled enough... but then why you lock your door every night?
Because locking your door is "security". Trusting that no burglar will ever find your door is stupidity. There is no such thing as absolute security. But there is such thing as no security. Further I would rather rely on tested security rather than security based on secrets. If you need security to protect secrets and secrets are security then why do we need security again?
Originally posted by virus
Too bad, Crafty is such an amazing opensource chess engine :)
That's fine. But it is not something that I need or would rely on even if I did need it. Not like my OS or my browser. BTW why are you not as worried about some unrelated stranger writing mallicious code (or plugins) for crafty? :p
virus
6th December 2004, 07:48
Originally posted by Neo Neko
Firefox is not aiming to dominate the market like Microsoft.
And so? If people use it frequently, hackers may target it. I don't think hackers care too much at what Firefox is aiming to be. A potential door to several millions of PC always deserves a look.
Never does. What was the point?
The point was that the solution you suggested (reverting back to a previous plugin version) won't work if you apply it too late ;)
Oh all the previous discussion led me to believe we were discussing the plugins on the official firefox update page and mozdev.
And we are. But the official plugins are provided by random strangers. The bare fact that they're required to have a regular account doesn't make them so much less "strangers".
I can trust the official development team. I cannot trust random strangers, even if they upload on official sites (we agreed on the fact that mozilla.org is unable to check extensively every version of every extension, remember?). I fear that evildoers can find an easy way to get into this system.
What's the point again? Isn't IE just as vulnerable?
The point is that I'm willing to discuss the security of FF extensions. Instead you keep talking about M$. I think we can talk about FF extensions without even mentioning the word "Micro$oft", can't we?
But here is a flaw in your logic. Keeping code secret leads to it being less robust.
If you keep equating "closed-source = Micro$oft", then there's nothing that can be argued. Their code would be filled of holes in any case.
But there's life beyond M$. Not everyone write that shit. Not everyone invent their own incompatible and insecure standard every day. Not everyone fixes their buggy code every 2 years. Not everyone allow pieces of their code to leak on the net. M$ simply does not represent the "closed-source community" in any way. They're a pathologic case.
And you seem to ignore the bare fact that thousands of hackers can look at the source code as well as the thousands of people supposed to check and fix it. Unfortunately this is a point against opensource (maybe the only one, but it's there). All in all, weighting every factor, I'd say that, concerning security, opensource doesn't improve anything over closed-source; and may even be worse.
In that specific case (Firefox) there's another problem, given that the developers said that some portions of the code are so complex that they can't even fix/mantain them properly. Who's gonna "check and fix in a few days" as you said? We can only hope that hackers are not smarter than the development team.
why are you not as worried about some unrelated stranger writing mallicious code (or plugins) for crafty? :p
No need to. Crafty does not allow 3rd party plugins - no strangers knocking at the door :p
Joe Fenton
6th December 2004, 08:53
Originally posted by virus
But the official plugins are provided by random strangers. The bare fact that they're required to have a regular account doesn't make them so much less "strangers".
I can trust the official development team. I cannot trust random strangers, even if they upload on official sites (we agreed on the fact that mozilla.org is unable to check extensively every version of every extension, remember?). I fear that evildoers can find an easy way to get into this system.
This is a lame argument. Just because YOU don't know them doesn't mean they are "random strangers". Also, anything getting posted on the official Mozilla page will come under HEAVY scrutiny from thousands of coders. Even if some "random stranger" got an account and tried to slip a naughty extension into the system, it would be caught quickly - more than likely within hours.
You seem to be under the impression that ANYONE can post ANYTHING onto the official Mozilla site. That there are THOUSANDS of untested extensions being blindly run on FF. You have some very strange ideas - you are thinking of Microsoft, not Mozilla.
:)
Neo Neko
6th December 2004, 11:56
Originally posted by virus
And so? If people use it frequently, hackers may target it. I don't think hackers care too much at what Firefox is aiming to be. A potential door to several millions of PC always deserves a look.
But you miss the point that Firefox being differnet to the core if it became popular would help to mitigate the effect of such attacks. Even if it should prove vulnerable itself. With IE having an average 90% market control. On average 90% of the market can be efected by a single exploit. Lets get super optimistic and say Mozilla/Firefox manages to snag 50% of the market. At any one point the most of the population any one exploit can expect to effect is 50% either way. That is an improvement. Every bit of reduction in IE usage is a benefit to security.
Originally posted by virus
The point was that the solution you suggested (reverting back to a previous plugin version) won't work if you apply it too late ;)
Nothing you can do to stop that. But due to the nature of the code those sort of things should be less likely to happen and will be fixed quicker in the event they do.
Originally posted by virus
And we are. But the official plugins are provided by random strangers. The bare fact that they're required to have a regular account doesn't make them so much less "strangers".
I can trust the official development team. I cannot trust random strangers, even if they upload on official sites (we agreed on the fact that mozilla.org is unable to check extensively every version of every extension, remember?). I fear that evildoers can find an easy way to get into this system.
What part of the official site being run and administered by the official team needs to be re-explained? Even if they themselves can't inspect everything. How hard would it be for them to suspend an account on their site and further push a package to remove the dangerous code over Firefox update at the first report of trouble? Further since all the plugins on the official sites have source code avalible such malicious code would have to be hidden in plain sight again.
Originally posted by virus
The point is that I'm willing to discuss the security of FF extensions. Instead you keep talking about M$. I think we can talk about FF extensions without even mentioning the word "Micro$oft", can't we?
First of all you make mention of such things as if they are rather new. And further you give the impression that firefox and most of it's plugins being opensource are for some reason more vulnerable. Why should any of this concern someone wanting to use firefox? When if they are not using firefox it most likely means they are using IE and thus already highly vulnerable to such attacks already? So switching to firefox as a worst case scenario means they are no worse off. And if we are going to talk about Firefox comparisons to IE and thus mentioning Microsoft are inevitable.
Originally posted by virus
If you keep equating "closed-source = Micro$oft", then there's nothing that can be argued. Their code would be filled of holes in any case.
You kind of miss the point though that they with their sloppy coding and product rushing to meet deadlines could benefit form the wide spread peer review avalible with opensource. Microsoft is arguably one of the biggest detractors of true opensource who would ironically greatly benefit from it. I would equate Opera with closed source. But since they have less market than Mozilla they are not such a good comparison.
Originally posted by virus
But there's life beyond M$. Not everyone write that shit. Not everyone invent their own incompatible and insecure standard every day. Not everyone fixes their buggy code every 2 years. Not everyone allow pieces of their code to leak on the net. M$ simply does not represent the "closed-source community" in any way. They're a pathologic case.
Name one influential company with no ties to Microsoft who so espouses closed source over opensource at all costs to be in the same league as Microsoft. If you can do that and name someone recognisable wo represents closed source in that manner I will be impressed.
Originally posted by virus
And you seem to ignore the bare fact that thousands of hackers can look at the source code as well as the thousands of people supposed to check and fix it.
First of all you perpetuate the myth that hackers are all bad people. Further more hackers work for mozilla than against it.
Originally posted by virus
Unfortunately this is a point against opensource (maybe the only one, but it's there). All in all, weighting every factor, I'd say that, concerning security, opensource doesn't improve anything over closed-source; and may even be worse.
Explain again how trying to hide bad code is more secure than openly publishing code so it can be fixed quicker and better? Even closed source code can be disassembled. Granted it will not reveal the original source. But you can still tell exactly what a program is doing and how to exploit it. Which largely negates your constant misconcieved claims that since something is opensource it is less secure. That is plain wrong. you make it sound like the only way to find vulnerabilities in closed source is by accident or shere luck. Which is wrong as well.
Originally posted by virus
In that specific case (Firefox) there's another problem, given that the developers said that some portions of the code are so complex that they can't even fix/mantain them properly. Who's gonna "check and fix in a few days" as you said? We can only hope that hackers are not smarter than the development team.
Hellooooooooo. Opensource anyone? The developers as you call them are not the only coders who contribute. The users contribute as well.
Originally posted by virus
No need to. Crafty does not allow 3rd party plugins - no strangers knocking at the door :p
But to use your argument it is opensource so surely it must be less secure than a closed source chess program. :p Further being opensource any nefarious character can sneak mallicious code in can't they?
If you are trying to play devils advocate it is not working. :D
Tuesday
6th December 2004, 14:00
Yet another reason why FF kicks IE ass
Portable FireFox, lets you take YOUR browser,config,extensions,bookmarks - the lot, anywhere. Especially nice on a Pen drive.
http://johnhaller.com/jh/mozilla/portable_firefox/
virus
6th December 2004, 15:23
Originally posted by Neo Neko
If you are trying to play devils advocate it is not working. :D
Yep. Especially if you keep grossly misrepresenting what I've written into previous posts and keep asking to explain things I've already explained at least a couple of times.
Also I can't answer if you keep adding 20 lines of comment to every 2 lines of my post. Either I'm forced to cut important things, or to post a reply 50000 lines long ;)
Anyway, I won't waste your time any more. You surely have other things to do, including joining the millions of people who spend the day downloading the source code from mozilla.org to put it "under HEAVY scrutiny" lol.
Personally, I'll just wait and see if the system is going to be exploited or not. Talk about Micro$oft doesn't bother me. I was mostly looking for technical details about how and how well FF blocks malicious attempts but you're mostly avoiding them or simply saying they are not needed because the hackers actually work for Mozilla. (!!!)
jernst
6th December 2004, 15:35
Originally posted by virus
simply saying they are not needed because the hackers actually work for Mozilla. (!!!)
The comment about "hackers" was meant to show the common misinterpretation of the word hacker.
http://en.wikipedia.org/wiki/Hacker
Mug Funky
6th December 2004, 16:03
virus: it's already been said to some extent how malware extensions are blocked by firefox.
have you used this browser? have you tried to install an extension?
there's a big fat warning about only downloading from trusted sources, and there's a signature system (which, like in windows, doesn't seem ever to be used). that's 2 more things that IE does not do with activex, and that's not counting the fact that the user must install the extension themselves, rather than drive-by downloading.
the proof is in the pudding, and i'm getting bored from your circular arguments.
every system has bugs, and FF has already had a couple of security holes patched. note that as far as i'm aware, none of these were ever exploited, except by people testing firefox out.
now granted, as FF's market share increases (hopefully to a good number, but i fear it'll only be as high as the percentage of cyber-hippies out there) it is less likely that ALL holes will be found by testers, but with the rapid and enthusiastic development going on, i suspect by the time FF gets that widely used, there will be jack-all holes left. possibly none at all.
also note that the multi-platform nature of FF makes it a headache to exploit security holes, even if they exist. imagine how clever a hacker must be to be able to:
a) find a hole
b) find a way to code malware into an extension in such a way that nobody will have the slightest idea from reading the code what it actually does, and
c) make it work cross-platform.
i suppose that (c) is optional, but still (a) and (b) are tough enough for any coder. a hacker like that would most likely be getting paid work if they're that good. i suspect that if there are hackers like that out there, and they really want to get into your computer, they'll be in before firefox even loads, through some other back door.
please, the proof is in the pudding (i hate that expression...), and if you haven't used firefox yet, you're talking out of somewhere other than your mouth.
[edit]
i just thought of something... avisynth can run external programs, can't it? and it can write to text files. in theory you could use a malware plugin for avisynth and nuke your computer as soon as you load your avs file.
but is that any reason to settle for just virtualdub, or some expensive-as-F NLE application that crashes all the time and can't even do denoising or anything but the most basic of deinterlace functions?
of course not.
virus
6th December 2004, 16:54
Originally posted by Mug Funky
and i'm getting bored from your circular arguments
and if you haven't used firefox yet, you're talking out of somewhere other than your mouth.
...the usual, aggressive, useless "Spead Firefox"-style campaign... bash everyone that doesn't say that FF is pure gold. :rolleyes:
Go back a couple of pages where I wrote that I actually use FF (without extensions, of course).
I'm out of this thread. But remember that I didn't try to insult anyone. Unlike you.
neo75903
6th December 2004, 18:29
Nope, he coulnd handle the truth :)
Have to say thanks all guys who were defending FF with true facts unlike virus being super suspecious about the open community.
Neo Neko
6th December 2004, 19:46
Originally posted by virus
...the usual, aggressive, useless "Spead Firefox"-style campaign... bash everyone that doesn't say that FF is pure gold. :rolleyes:
No the agressiveness you are seeing is likely due to the forming conception that you are a bit thick on the plugins issue. And people are frustrated trying to figure out exactly what you are trying to get at. No one has said that firefos "is pure gold". It has it's own problems. Of whitch people being exploited by unrelated 3rd party plugins manually installed by the user is not on the list. Plugins could provide an entry point for malicious code in any program. Not just Firefox. It is an ever present risk that is basically always oughtweighed by the good it provides.
Originally posted by virus
Go back a couple of pages where I wrote that I actually use FF (without extensions, of course).
What is it with your plugin phobia? Do you not use plugins anywhere? In any program? It is your perogative. But it all sounds rather silly to me. If you are afraid of plugins then what are you doing on the net. It is at least as dangerous as unknown 3rd party plugins. And surely you have never installed software from someone you did not know personally. Right? I am all for being cautious. But being so rigid in paranoia that you can't take action or live comfortably in not a good position to be in.
Originally posted by virus
I'm out of this thread. But remember that I didn't try to insult anyone. Unlike you.
Name calling is not called for. No matter how frustrating you may be at times. ;)
moon1234
6th December 2004, 21:13
2, Websies that are IE-only are rare on internet. I've been using Firefox since version 0.8 and Mozilla for months before that - and I found one (ONE) site that doesn't work with them.
Then you must not live or work in a corporate world. Almost ALL, 100%, of corporate apps rely on IE in some way at this point. .NET and other technologies that many corporations rely on are the advances that have been made in IE. If you have Windows XP SP2 you have a built-in pop-up blocker, You can turn off ActiveX (Most good sysadmins have had it off for a long time), you can turn on or off all plugins that are installed on your system.
You also fail to see the manageablity side. IE can be managed via local policies, Group Policy, SMS, etc. If I need to lock down most of the office and restrict the sites they can vist, but let sales and marketing go anywhere, I can have this done and deployed in 15 minutes to several thousand PCs. This is not easily or quickly done with firefox.
This whole debate is centered around home users and fully neglects all of IE's benefits in a corporate environment. As for the security issues, If Firefox had 92% of the market, it would have the same problem. The fact that Microsoft can catch and fix the bugs quickly and distribute them automatically via Windows Update to my internal SUS machines and then out the to the desktop PC's all automatically means that Microsoft is commited to fixing the bugs.
IE on Windows XP SP2 is very usable, stable and most importantly it just works.
akupenguin
6th December 2004, 21:27
Originally posted by moon1234
IE can be managed via local policies, Group Policy, SMS, etc. If I need to lock down most of the office and restrict the sites they can vist, but let sales and marketing go anywhere, I can have this done and deployed in 15 minutes to several thousand PCs. This is not easily or quickly done with firefox.
Maybe I'm just not a corporate shill, but I fail to see how that would work. If you really want to restrict internet access, it _must_ be done at the firewall level. If you don't trust people to have real internet access, a client-side block won't stop them. After all, anyone who cared to bypass your restriction could simply run firefox ;).
stephanV
6th December 2004, 21:51
it is not uncommon though that employees cannot install software themselves on a PC (no admin rights)
but yeah, preventing this on a firewall level would be much better.
akupenguin
6th December 2004, 21:53
FireFox requires no "install". (Or at least, such mods of FF exist.) And I have yet to see a configuration of Windows (or any other OS) that prevents people from running any EXEs they can get their hands on.
stephanV
6th December 2004, 23:16
i stand corrected :)
Cyberman
6th December 2004, 23:35
Well, I tried FireFox.
Not bad, especially that it apparently adheres closer to HTML than IE. (I promptly found a few bugs in my site...)
There are a few things I find extremely annoying, though - so Iīd like to ask if thereīs a way around them:
*) When starting FF, it loads the starting page(which is fine), but when I hit the CANCEL button, it continues loading(or, at least, displaying) it.
Does it really load the file or is it loaded already and merely being displayed? IE usually cancelled everything and showed an error.
*) It is loading VERY slow. I understand that this is because itīs not integrated in the OS as IE is - is there a way to fasten the process?
Well, thatīs it. Either I canīt remember anything else, or I found the solutions already.
I have to admit, though, that despite all itīs obvious features I am not sure if I do the switch entirely - Iīm too used to IE...
--
About PNG: As I saw today, Photoshop canīt save anything below 8Bit PNG files - while it can save 1Bit GIF files.
I guess thatīs a reason why PNG still isnīt too common...
[edit]Well, Iīm wrong, as so often. Even though PNG is shown as PNG 8Bit, it apparently does save with less, as color reduction is just as possible.
moon1234
6th December 2004, 23:57
Originally posted by akupenguin
Maybe I'm just not a corporate shill, but I fail to see how that would work. If you really want to restrict internet access, it _must_ be done at the firewall level. If you don't trust people to have real internet access, a client-side block won't stop them. After all, anyone who cared to bypass your restriction could simply run firefox ;).
Almost all corporate environments restrict the ability for end users to install any programs. This prevents firefox or anything else for that matter from slipping onto the machine. In my environment end users are prevented from downloading any .exe files. They are also prevented from copying any downloaded file out of the temporary internet cache. IE is set to restrict the launch of any executable in any of the internet zones.
There is also no abilty for a user to copy files to the local drive. All CD-DVD drives are prevented from launching any executable. In 4 years I have never had a major system crash due to illeagle downloads.
I also run websense and filter all .exe files snoop all compressed files for .exe . If the compressed file is encrypted and cannot be scanned it is blocked.
Almost all larger institutions that are worth their salt operate in a similar fashion. Would you want to go to a hospital where you life was in the hands of the employee loading firefox on the machine that is used to lookup your medical records?
If the employee was caught modifying or running non-approved software they would be reprimanded and based on the severity, terminated as well.
KpeX
7th December 2004, 00:08
Originally posted by moon1234
If the employee was caught modifying or running non-approved software they would be reprimanded and based on the severity, terminated as well. No offense is intended, but it sounds like you have a really good policy for restricting employee creativity and productivity.
sysKin
7th December 2004, 00:34
Originally posted by moon1234
Would you want to go to a hospital where you life was in the hands of the employee loading firefox on the machine that is used to lookup your medical records? As for firefox, yes. I do however see your point, see this article (http://www.wired.com/news/technology/0,1282,65906,00.html?tw=rss.TOP)...
The fact remains, that even under this lockdown, you still were vulnerable to the latest iframe exploit, and there is not much you could do (unless you made all browsers useless).
Many things can be said about security, but I didn't switched to mozilla (and then firefox, when it was 0.7) because of security. It was just much better.
jernst
7th December 2004, 01:40
Originally posted by Cyberman
*) When starting FF, it loads the starting page(which is fine), but when I hit the CANCEL button, it continues loading(or, at least, displaying) it.
Does it really load the file or is it loaded already and merely being displayed? IE usually cancelled everything and showed an error.
Maybe it's because by default, Firefox doesn't try to render a web page for 250 milliseconds, because it's waiting for data. So maybe it has already all the data when you click your stop button.
If you have a fast computer you can speedup page rendering and maybe fix this problem by following these tips:
http://www.mozilla.org/support/firefox/tips
Follow the tip "Speed up page rendering" and "Enable Pipelining". Instead of editing user.js as requested, just type about:config in your address bar (without the space) and create modify the settings values.
On my computer I saw a big difference in page loading time. You can also use this plugin which tweaks the network settings for you (but doesn't do the 250ms trick):
https://update.mozilla.org/extensions/moreinfo.php?application=firefox&id=327
*) It is loading VERY slow. I understand that this is because itīs not integrated in the OS as IE is - is there a way to fasten the process?
See here: http://www.digitalmediaminute.com/article/1058
I have to admit, though, that despite all itīs obvious features I am not sure if I do the switch entirely - Iīm too used to IE...
If you are too used to IE don't forget this page and you'll get an IE like browser with the power of firefox: http://www.firefoxie.net/
About PNG: As I saw today, Photoshop canīt save anything below 8Bit PNG files - while it can save 1Bit GIF files.
I guess thatīs a reason why PNG still isnīt too common...
Yes photoshop has a very bad support for png. Use The Gimp http://www.gimp.org/ it's like photoshop but free, opensource and multiplatform. You can furthermore crush your png files to the maximum (lossless) using pngcrush : http://pmt.sourceforge.net/pngcrush/
Mug Funky
7th December 2004, 05:24
another thing on PNG... there's a photoshop i/o plugin called "superPNG" that is extremely nice (and free). the same company also do a jpeg2000 plugin.
http://www.fnordware.com/
it'll also save (and load) 16-bit-per-channel png files from apps such as 3dsmax. very useful feature, and photoshop's continual lack of support for it (in spite of it's support for several operations in 16 bit) always drove me mad, because 3dsmax never supported 16 bit tiff like photoshop does...
it will do 1-bit png as well, but it seems to load back in inverted (though the space saving compared to 1-bit LZW TIFF is worth the simple ctrl+i required).
the png's come out very small at defaults, too - pngcrush barely dents them (and only on exhaustive search mode, which takes minutes for a single image).
@ virus: sorry, no personal insult intended. i tell my best friend she's talking out her arse when it seems appropriate :) maybe it's an aussie thing?
Neo Neko
7th December 2004, 05:46
Originally posted by moon1234
Then you must not live or work in a corporate world. Almost ALL, 100%, of corporate apps rely on IE in some way at this point. .NET and other technologies that many corporations rely on are the advances that have been made in IE. If you have Windows XP SP2 you have a built-in pop-up blocker, You can turn off ActiveX (Most good sysadmins have had it off for a long time), you can turn on or off all plugins that are installed on your system.
As to almost all corporate apps relying on IE that is a deficiency. It puts the company at the whim of another company. SP2 will break alot of said aplications. So it comes down to a choice between getting business done or being secure. And business wins every time. So all this SP2 fixes everything is a bit simplistic at best. Even if it did fix everything (and it doesn't) there are still problems. And all these so called "advances" made in IE are nothing special either. The exact same aplications could be written and wider deployed in Any browser and not just IE. Active-X, COM, COM+, and .Net are nothing special. They are simply proprietary, incompatable, platform dependant versions of tools that were already largely avalible before.
Oh and BTW there are as many or more bad or deficient sysadmins than there are good ones by the measure you set.
Originally posted by moon1234
You also fail to see the manageablity side. IE can be managed via local policies, Group Policy, SMS, etc. If I need to lock down most of the office and restrict the sites they can vist, but let sales and marketing go anywhere, I can have this done and deployed in 15 minutes to several thousand PCs. This is not easily or quickly done with firefox.
Actually it is not as bad as you paint it. I think you are factoring in the set up and switch time going from an existing system using proprietary Microsoft technologies. Frankly once you get switched and set up I can't see how it would take longer. Sure the switch will take more initial time and effort. Swithching almost always does. But frankly I think you can use all the non-Microsoft technologies the Microsoft tools you listed were derived from originally. And further you can use them on any OS including MS Windows. You can do local and group policy type restrictions just fine on non-Microsoft OS. Granted you can't use Microsoft tools. But then what would you expect from Microsoft.
Originally posted by moon1234
This whole debate is centered around home users and fully neglects all of IE's benefits in a corporate environment. As for the security issues, If Firefox had 92% of the market, it would have the same problem.
Benefits in the corporate environment? What benefits would those be other than the fact it is already what most of them are currently using?
Originally posted by moon1234
The fact that Microsoft can catch and fix the bugs quickly and distribute them automatically via Windows Update to my internal SUS machines and then out the to the desktop PC's all automatically means that Microsoft is commited to fixing the bugs.
Hardly. It just means you are more aware and more comfortable with their tools. Frankly Microsoft has more critical vulnerabilities that typically go unpatched longer than their copmpetitors. Further they rush products out the door all to meet artificial deadlines often without alot of regard towards testing and security. That to me does not sound like someone commited to fixing bugs or ensuring quality. Neither do the times they have been quoted in the press as claiming that no one exploits a vulnerability till they publish it. Frankly that is a bit naieve and not indicative of someone with a mind on security. Microsoft does an OK job. Not great. But ok.
Originally posted by moon1234
IE on Windows XP SP2 is very usable, stable and most importantly it just works.
Yes but the default options generally suck. And then there is the fact that it is not really any more usable or stable than it's competitors. Which cost alot less to license, often have better defaults, and generally allow the company access to the source to fix and modify to better fit their needs. Sure the Microsoft solution just works. It just does not work better in alot of ways.
communist
7th December 2004, 10:38
Originally posted by Cyberman
*) It is loading VERY slow. I understand that this is because itīs not integrated in the OS as IE is - is there a way to fasten the process?
If you mean page loading / rendering its because the sites you generally load in IE have most of their (unchanged) assets already loaded into IE' s cache folder. When you start FF for the first time it will really download the whole page from the internet AFAIK.
stephanV
7th December 2004, 11:31
i think he just means startup time... i notice that too...
but i also notice running Ad-Aware has become pointless since i use FF :)
Cyberman
7th December 2004, 11:37
Originally posted by jernst
If you are too used to IE don't forget this page and you'll get an IE like browser with the power of firefox: http://www.firefoxie.net/
I tried that, but either it didnīt work or simply didnīt do much beside hiding the google bar and showing text beneath the buttons.
Originally posted by communist
If you mean page loading / rendering its because the sites you generally load in IE have most of their (unchanged) assets already loaded into IE' s cache folder. When you start FF for the first time it will really download the whole page from the internet AFAIK.
No I mean at startup - page rendering seems fine, though it is different somehow...
neo75903
7th December 2004, 14:39
@moon1234:
From what i hear here you are better off with a dumb terminal and save your company a thousand of windows licenses to do your job.
Unless you are using things like activeX at client side.
I have seen our government instances running XP pcs just to run somekind of terminal program. What a waste of our taxes!
And some more modernised departments have a browser as their interface, then you really wonder why they are not running Linux.
edit: http://browsehappy.com/
Neo Neko
7th December 2004, 20:51
Originally posted by neo75903
@moon1234:
From what i hear here you are better off with a dumb terminal and save your company a thousand of windows licenses to do your job.
Unless you are using things like activeX at client side.
That is true. But unfortunatly many companies like moon1234's have fallen for and become smitten by the Microsoft/Intel backed methodology of over priced hardware and software. Actually it is not that overpriced. Not when you have many of their resources. They can amoritize the cost out over a long period. And many don't actually buy the systems but rather lease them and then have them upgraded every few years as terms of the lease. So honestly the average company's switching to thin clients in the medium term would not save them that much. In the long run it would save them alot though. But not alot of companies considder the long term that much. Rather choosing to opperate in the moment. Further the very people who would propose or decide on such a switch are generally opposed. Imagine having to go from updating and maintaining 3000 computers to just 3. Why you could really drop a good portion of your IT staff. And if you IT staff really knows what's good for it, it will vote against such actions. The only downside to the thin client method is that you have a few central points of vulnerability for an attacker to hit in order to compromise the entire structure. But that is not as bad as it sounds. Especially when even with a spread out infrastructure all the systems are generally easily vulnerable as they are now. The thin client model presents an easier to mannage and fix solution.
Originally posted by neo75903
✇I have seen our government instances running XP pcs just to run somekind of terminal program. What a waste of our taxes!
And some more modernised departments have a browser as their interface, then you really wonder why they are not running Linux.
edit: http://browsehappy.com/
Microsot is canvasing the government sector. Huge burocracy is their best friend.
Atamido
7th December 2004, 21:40
Originally posted by dragongodz
i never said Mozilla was an open source version of Netscape 5 for the record, i said(again) that Mozilla was started with the Netscape 5 source code. if you cant understand the difference then there is no point discussing it with you. I know and understand what you said, it's that you do not understand me. There are conflicting sources of information and I'm am inclined to believe the one that opposes the one that you believe. Chill, it's not the end of the world.
neo75903
7th December 2004, 22:23
@neo neko:
You have made a nice picture for what is going on in ict and also described why the concept of a thin client never hit the coorporated market. Guess we need a bigger Wallstreet crash before companies will take such measures.
Until then we have to get used to a world is the dominating factor.
Cyberman
7th December 2004, 22:59
Originally posted by jernst
Yes photoshop has a very bad support for png. Use The Gimp http://www.gimp.org/ it's like photoshop but free, opensource and multiplatform.
Iīm just visiting that site.
Am I the only one thinking itīs a bad omen if the graphics for the site are larger than necessary? One of the graphics is 10K in PNG, but only 5K in GIF(saved with MS Photo Editor).
Iīm talking about this one here: http://www.gimp.org/images/thegimp.png
Still, Iīll give it a try.
[edit]OK, I tried. Quite frankly, I didnīt like this program from the beginning. The interface is terrible, and I donīt want to spend time learning it.
Neo Neko
7th December 2004, 23:10
Originally posted by Cyberman
Iīm just visiting that site.
Am I the only one thinking itīs a bad omen if the graphics for the site are larger than necessary? One of the graphics is 10K in PNG, but only 5K in GIF(saved with MS Photo Editor).
Iīm talking about this one here: http://www.gimp.org/images/thegimp.png
Still, Iīll give it a try.
Not a bad omen at all. Remember that unless one of the Gimp devs happens to be good at HTML and web page design and thus aware of such concerns how are they to know that people might be up in arms over 5Kb. I doubt that if some one went in and fine tuned their site, If it still looked and functioned the same in the end they would refuse the donation. Good aplication programmers don't necessarily make good web programmers.
I will say this. Gimp can't replace Photoshop. Not at this time. If you are used to photoshop then it will take some time to get used to Gimp. Further Gimp is missing some things photoshop has and vice versa. It also depends on what you are creating for. Gimp is awesome for web design. But for print Photoshop is still the widest used. Personally I use Gimp on all my systems and don't actually have photoshop installed at the moment.
scharfis_brain
7th December 2004, 23:22
if I downsample the thegimp.png from 977 to 256 colors using photoshoips save for web and resave it with irfanview (compression=9) its size is haved, too! like the size of the gif-file!
KpeX
8th December 2004, 03:37
I think everyone has that attitude at first about the gimp, especially when you're used to other tools like photoshop. I know I did, anyways. The interface improved dramatically in 2.x versions, however - if you think that interface is bad, don't go anywhere near GIMP 1.x.
After I got used to GIMP's interface, however, I find it to be faster, more intuitive, and far superior for what I do to photoshop or anything else. The variety of filters for image rendering is outstanding (just play with some of the effects in the 'Filters' menu, like supernova, flame, etc.) Also it seems to me that most of the tools are more configurable than in photoshop. But a photo editing program is greatly a matter of opinion - there are a lot of different uses for such a program.
dragongodz
8th December 2004, 05:19
since this has expanded a bit to include software used for making web pages(well PNG's anyway :) ) may i slip this in for those interested.
http://www.nvu.com/
multi-OS ,open source web authoring based on Mozilla's Composer. pre-release 1.0 beta is available to download.
Mug Funky
8th December 2004, 06:24
thanks for the link, dragongodz!
i love any opportunity to ditch proprietary software. it's just a shame cinelerra is linux only (although it's an extremely good reason to upgrade to linux) and i haven't had a chance to make the change yet - i'm not the only user of my machine, and it's hard to make big changes to the system without freaking anyone out.
dragongodz
8th December 2004, 06:42
i'm not the only user of my machine, and it's hard to make big changes to the system without freaking anyone out.
tell me about it. if i changed over to linux my wife would freak. as it is she knows ow to get online, read and send emails, browse a few sites that i have bookmarked for her. when i need to do something with linux i generally use a livecd such as knoppix. :)
Cyberman
8th December 2004, 10:39
Originally posted by Neo Neko
Not a bad omen at all. Remember that unless one of the Gimp devs happens to be good at HTML and web page design and thus aware of such concerns how are they to know that people might be up in arms over 5Kb.
Itīs not a question of web design, rather a question of common sense. Itīs not the 5K, itīs the 50%.
IMO, it should be no question that a website should try to use the smallest possible files - as long as there is no loss in quality, which isnīt.
Especially when itīs the website of a grahics progam, Iīd expect them to know how to get small files.
Mug Funky
8th December 2004, 12:20
it's not really a big deal though...
you'd be surprised how many multimedia design graduates can't make an efficient web site to save themselves...
mostly due to the inefficiency of programs like photoshop and fireworks. it'll change, of course, but as bandwidth increases it becomes less important.
whenever i make a website (guh... i hate the things!), i make the pics as small as possible, but usually people are just worried about getting the site finished, pleasing their (usually bone-headed n00b) clients, and getting paid :)
dragongodz
8th December 2004, 13:21
if I downsample the thegimp.png from 977 to 256 colors using photoshoips save for web and resave it with irfanview (compression=9) its size is haved, too! like the size of the gif-file!
Itīs not the 5K, itīs the 50%.
should try to use the smallest possible files - as long as there is no loss in quality, which isnīt.
hmm or maybe for them they could see a difference with nearly 400% more colours and decided a 50% size increase was ok. who know ?
it really is clutching at straws though to think their decisions on what pictures to use on the web page reflects on how well the program works. the 2 are not related.
OK, I tried. Quite frankly, I didnīt like this program from the beginning. The interface is terrible, and I donīt want to spend time learning it.
fair enough but also consider the cost of photoshop to the gimp. not everyone can afford, or even if they could wants, to buy photoshop for some occasional image processing etc.
Cyberman
8th December 2004, 19:41
Originally posted by Mug Funky
it's not really a big deal though...
Not this time, no.
Itīs a matter of principle, though I guess Iīm very biased in that respect, as the server my sites lies on is very slow, so I have to use the smallest possible files, or make loading the site inaceptable long.
mostly due to the inefficiency of programs like photoshop and fireworks.
Even these programs offer enough options to compare - photoshop even tells you the resulting filesize before you save - and shows you the colors used.
it'll change, of course, but as bandwidth increases it becomes less important.
I hear that quite often. Yet I fail to see it.
Of course bandwith increases - but so do the filesizes. With ever more bandwith, site owners tend to say "What the heck, thereīs plenty bandwith" - resulting in ever more needless traffic.
Just like many programs think "512MB of RAM is standard by now, so I can use every bit of it", ignoring that there are other programs needing memory too...
but usually people are just worried about getting the site finished, pleasing their (usually bone-headed n00b) clients, and getting paid :)
I understand that - but someone has to make a start. The bone-headed n00bs wont, so the duty lies within the other side...
Originally posted by dragongodz
hmm or maybe for them they could see a difference with nearly 400% more colours and decided a 50% size increase was ok. who know ?
Now that I rechecked the pictures, I have to admit there is a slight color change. I had to upsize the picture and increase brightness and contrast of my monitor, though. Even then itīs merely two shades of blue.
fair enough but also consider the cost of photoshop to the gimp. not everyone can afford, or even if they could wants, to buy photoshop for some occasional image processing etc.
Good point.
Atamido
9th December 2004, 08:58
35) Ability to enable/disable very specific features.
Or whatever number we are up to. Just discovered that if you go to "about:config" in the address bar and filter for dom.disable_window_ you get some fun options that you can disable in javascript. move_resize will disable the ability for javascript to resize the window. open_feature.location will turn off javascript's ability to remove the address bar. You can also change lots of other things that it is annoying for javascript to make changes to on a page. But you can leave the rest of javascript on.
sysKin
9th December 2004, 13:28
Originally posted by Pamel
35) Ability to enable/disable very specific features.
Or whatever number we are up to. Just discovered that if you go to "about:config" in the address bar and filter for dom.disable_window_ you get some fun options that you can disable in javascript. move_resize will disable the ability for javascript to resize the window. open_feature.location will turn off javascript's ability to remove the address bar. You can also change lots of other things that it is annoying for javascript to make changes to on a page. But you can leave the rest of javascript on.
Six of them are also available in options->web features->javascript->advanced. I always disable all of them but the last one. I'm always wondering why they aren't disabled by default :) as the "take back the web" part of firefox mostly consists of them being off.
ukb008
6th March 2005, 03:32
Is that a full download or upgrade ? What I mean is, do I uninstall my 1.0 and then install that or what ?
Regards.
sysKin
6th March 2005, 03:41
Originally posted by ukb008
Is that a full download or upgrade ? What I mean is, do I uninstall my 1.0 and then install that or what ?
Regards. It's full download it if download it manually - it's probably better to uninstall first, but I don't think it's necessary.
It's an upgrade if you get it by program's automatic upgrades.
cypher_soundz
7th March 2005, 02:22
Originally posted by ukb007
Hi.
Doom9 informs us that he finds Mozilla Firefox 1.0 better than IE. An opinion from him counts. We'd like to make this paradigm shift in browsing (at least I do).
I'd appreciate (many others will, too, I'm sure) a list of reasons why Mozilla Firefox 1.0 is better than IE.
Regards.
http://people.zeelandnet.nl/marco/pimpzilla/
need i say more :D
Regards
cyph
KpeX
7th April 2005, 17:24
[OT] Getting back to the GIMP vs. PhotoShop interface problem, there is now a modified interface to the gimp made to look just like photoshop - GimpShop (http://plasticbugs.com/index.php?p=241) (another link (http://codemills.com/blog/?p=4)). Although I haven't seen a windows build yet that might be a good alternative if you're really that attached to the photoshop UI.
shevegen
8th April 2005, 03:52
pimpzilla is a funny idea :)
personally though, i like things simple and not distracting. but hopefully fancy ideas like that one revolve-bounce for long !
leonvictor2012
2nd June 2012, 12:12
I wouldnt depend on that. Generally, IE is faster than other browser. Firefox providing some anti-spyware protection and enough of a user base to be targeted. Its still safer than any version of IE.
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.