News: 1605710590

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

HTTPS-only mode arrives in Firefox 83 as Mozilla finds new home for Rust-y Servo engine

(2020/11/18)


Mozilla has released Firefox 83, including up to 15 per cent faster JavaScript and an optional HTTPS-only mode. The company has also found a new home for its Rust-based Servo project, which has been adopted by the Linux Foundation.

The adoption by Mozilla of a four-week release schedule for Firefox means that some builds are light on few features, but version 83 packs in more than most. Introduced this time round is HTTPS-only mode, off by default. If enabled, navigating to an HTTP site automatically redirects to HTTPS, and if no secure connection is available, a warning comes up with an option to continue. Insecure resources such as images loaded over HTTP are blocked. HTTPS-only can be disabled for specific sites.

Most traffic on the web is now encrypted. Google [1]reports that between 80 and 98 per cent of pages are loaded over HTTPS in Chrome, with figures varying by platform (Linux is the lowest at 71 per cent). In 2015 it was under 50 per cent.

[2]

Firefox 83 promises to 'upgrade all connections to HTTPS', though in reality it will block and warn users when only an insecure connection is available

The increase has been driven in part by the security advantages, in part by Google ranking HTTP sites lower in search results, and in part by the availability of free SSL certificates from Let's Encrypt. If a site never asks for a login or passwords, does it need to be encrypted? Arguably not, though there is still a risk from spoofing. The case for SSL everywhere has been won.

The SpiderMonkey JavaScript engine has been updated and Mozilla [3]claims up to 15 per cent improved page load performance and memory usage reduced by up to 8 per cent. Our casual tests suggest that Chrome's V8 engine outperforms SpiderMonkey on the JavaScript benchmarks we tried, but these may not be accurate predictors of real-world use.

Pinch to zoom, a much-requested feature, is now supported on Windows touchscreens and touchpads, as well as macOS touchpads. There is also better desktop performance on older versions of Windows, with an optimised WebRender architecture, already available for Windows 10, now coming to Windows 7, Windows 8, and macOS 10.12-15 (but not Big Sur yet).

Mozilla is moving towards making a native Firefox build for Apple Silicon, the new Arm-based chips for macOS. Version 83 requires Rosetta 2 emulation but a [4]nightly build for ARM64 is available for testing.

[5]

Firefox 83 supports conic gradients, a CSS feature for graphical effects

Developers will find new support for conic gradients in Firefox 83, a CSS feature for graphical effects. Chromium and WebKit-based browsers already have this but support in Firefox will help adoption.

Servo adopted by Linux Foundation

There is some good news for fans of [6]Servo , a web browser engine coded in Rust that shares some code with Firefox, including WebRender. At the KubeCon North America virtual event, the Linux Foundation stated that it will host Servo. The future of Servo has been clouded since August, [7]when Mozilla's headcount was reduced by 250 with layoffs apparently including Servo developers. Servo is designed to be embedded in other applications and runs on Windows, macOS, and Linux.

We asked about the implications for the funding of Servo development. Chris Aniszczyk, veep of strategic and dev programs at the Linux Foundation, told us: "As part of the move to the Linux Foundation, the Servo project is establishing a funding charter and will be funded by member organisations in the near future, similar to other Linux Foundation efforts."

The move means a change in governance for the project, which will now have a board and a technical steering committee (TSC). Currently the TSC has 19 members, at least eight of whom introduced themselves as "ex-Mozilla". There are some clues about the direction in the [8]initial minutes . What will be the relationship with Firefox? "We share some components that are co-maintained and nothing will change there," said Manish Goregaokar, ex-Mozilla. What is Servo trying to make? "A browser engine," said chair Alan Jeffrey, former Mozilla Research Engineer, though not a browser. "I don't see Servo competing in the same space [as Firefox]," he added.

Hosting within the Linux Foundation is better news for the Servo project than languishing with little funding at Mozilla. But questions remain about the extent of interest and how long it will take for Servo to become production-ready as an embeddable component. It is good for web standards that the Servo implementation exists, and Rust has advantages for secure coding, but it has formidable competition from Chromium. ®

Get our [9]Tech Resources



[1] https://transparencyreport.google.com/https/overview?hl=en

[2] https://regmedia.co.uk/2020/11/18/https.png

[3] https://www.mozilla.org/en-US/firefox/83.0/releasenotes/

[4] https://bugzilla.mozilla.org/show_bug.cgi?id=1648496#c2

[5] https://regmedia.co.uk/2020/11/18/conic-gradient.png

[6] https://servo.org/

[7] https://www.theregister.com/2020/08/11/mozilla_staff_layoffs_products_revenue/

[8] https://github.com/servo/project/blob/master/governance/tsc/tsc-2020-10-09.md

[9] https://whitepapers.theregister.com/

Hubert Cumberdale

Well, that means I can remove HTTPS Everywhere now. It's surprising how many sites are still holding out on HTTPS – there really is no excuse these days.

Ben Tasker

> If a site never asks for a login or passwords, does it need to be encrypted? Arguably not, though there is still a risk from spoofing.

I don't think there's any valid argument against encryption.

It's not just about protecting credentials, it's about ensuring that what the client receives is what they were supposed to receive, and not in fact something that their ISP, or someone else on the network path has injected (cough.... ads).

It's also about ensuring a modicum of privacy. If you visit Reddit and follow a link out to a plain HTTP only site, then network observers can see you browse /r/goatporn (Reddit, of course could prevent this by returning a Referrer-Policy header, but they don't because.... there isn't really a good reason). Watch those long enough and we can start to build what might be an interesting profile of you.

It also helps guard against [1]leaky services like LinkedIn . Side note, that post was 5 years ago now, and half the capabilities discussed are still possible because various sites don't use HTTPS.

I have, in the past, flagged up use-cases on mailing lists where using HTTPS might not be as "duh it's easy" as some assume, but the average website doesn't encounter those, being much more of an issue for people delivering certain content types at scale.

[1] https://www.bentasker.co.uk/documentation/security/313-ipb-nothing-to-hide-and-nothing-to-fear-but-you-can-still-nob-off#LinkedIn

"it's about ensuring that what the client receives is what they were supposed to receive"

Mike 137

Not realistically, in this age of cut price self-signed certificates that actually certify Bu**er all.

I actually believe that decisions like this should be left to the user. Having some external self-appointed nanny decide on our behalf what content we can see in our browsers seems a bit too much like loss of independence (yet again being Gooooooglefied).

Add to that a "four week update cycle" and the user has effectively handed away any control they might once have had.

Doesn't work all the time

AlanSh

I just tried it on my Synology server - Firefox just flashes and restarts. HTTPS is enabled and is my normal usage mode. But there's obviously some coflict somewhere.

Eggs and baskets

Jamie Jones

Is Lets Encrypt the only provider of free certificates?

We should be seeing a push to DANE acceptance before further forcing https.

[1]https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities

[1] https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities

Re: Eggs and baskets

IGotOut

There are plenty of free certs.

Feel free to search for them.

Alliance, n.:
In international politics, the union of two thieves who have
their hands so deeply inserted in each other's pocket that they cannot
separately plunder a third.
-- Ambrose Bierce, "The Devil's Dictionary"