Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Chrome Firefox Java Security Software Upgrades IT

Ask Slashdot: Options After Google Chrome Discontinues NPAPI Support? 208

An anonymous reader writes: I've been using Google Chrome almost exclusively for more than 3 years. I stopped using Mozilla Firefox because it was becoming bloated and slow, and I migrated all my bookmarks etc. to Chrome. Now Chrome plans to end NPAPI support — which means that I will not be able to access any sites that use Java, and I need this for work. I tried going back to Firefox for a couple of days but it still seems slow — starting it takes time, even the time taken to load a page seems more than Chrome. So what are my options now? Export all my bookmarks and go back to Mozilla Firefox and just learn to live with the performance drop? Or can I tweak Firefox performance in any way? FWIW, I am on a Windows 7 machine at work.
Have a question for Slashdot's readers? Take a look at other recent questions first to see if someone else has had a similar question. And if not, ask away! The more details and context you include, the more likely your question will be selected.
This discussion has been archived. No new comments can be posted.

Ask Slashdot: Options After Google Chrome Discontinues NPAPI Support?

Comments Filter:
  • by faragon ( 789704 ) on Friday June 05, 2015 @06:56PM (#49852829) Homepage
    It is a mistake to discontinue the NPAPI: there are *lots* of commercial/corporate/etc. plugins using it (!)
    • Re: (Score:2, Interesting)

      by Anonymous Coward

      they'll get on board in a year or two once it's gone. And then everybody is better off. But right now, a few of us are going to have to take 1 for the team and fire up internet explorer or firefox until they follow suite as well.

    • Comment removed (Score:5, Insightful)

      by account_deleted ( 4530225 ) on Friday June 05, 2015 @07:27PM (#49853071)
      Comment removed based on user account deletion
      • Re: (Score:3, Interesting)

        Google created a much better replacement, Pepper.

        But the assholes at the Mozilla Foundation won't implement it because they prefer shitty insecure APIs like NPAPI. Microsoft won't implement it (which is probably a good thing, they'd just fuck it up like everything else they do).

        Mozilla created NPAPI BTW, Netscape Plugin API.

      • Re: (Score:2, Insightful)

        by Anonymous Coward

        Microsoft will be killing the same plugins in I believe the next version of IE, these plugins are security holes, removing them makes browsers significantly more secure.

        this is a good move for all browser creators to take, anyone with old plugins no longer supported will just have to re-write them, in the case of many Java apps they should have been full blown applications in the first place, not plugins in a web browser.

      • by AmiMoJo ( 196126 )

        Chrome's native plugin API is called NaCL.

  • by tlambert ( 566799 ) on Friday June 05, 2015 @06:57PM (#49852835)

    Keep an older copy of Chrome around?

    Manual installs always offer this as an option, if you have disabled the autoupdate (which sucks a ton of bandwidth anyway).

    • by rwa2 ( 4391 ) *

      Yep, this. Same way that you need your IE6 around in a VM so you can do your mandatory training.
      Throw one of these puppies in a VM and leave a snapshot.

      https://chromium.googlesource.... [googlesource.com]

      • Re: (Score:3, Informative)

        Use Seamonkey.. It looks old, and it's at least as fast as Firefox, and with better security options. It has an email client, and an HTML editor, it'll play all the latest videos, and make popcorn. It's the browser that does everything, and it only weighs a few meg more than Firefox. It's a *Full Figured* browser.

        • by AmiMoJo ( 196126 )

          How about Pale Moon? It's forked from an older version of Firefox. Still runs old plugins. Has a reasonable selection of add-ons. Faster than Firefox. Developers are very responsive and helpful.

    • by binarylarry ( 1338699 ) on Friday June 05, 2015 @07:02PM (#49852885)

      On behalf of all the black hats and script kiddies out there: I applaud your advice, sir.

      • Re: (Score:3, Insightful)

        I've never coded in Java before so I can't comment on the language itself, but I am always seeing security vulnerabilities related to it all the time. Furthermore, new versions of Java seem to break older applications (for example, when I was taking a CCNA Security course, we had to use Cisco SDM, which broke with newer versions of Java, and required that we install insecure and older copies (which in itself is a major chore as they are often hard to find and in many cases refuse to install properly.)

        That s

        • all those years of "write once, run anywhere" bullshit and here we are with seven different installations of java from 1.5 to 1.8 just to run a web application and a database.

          and yeah, i agree, like flash java needs to die, fed up of the weekly security exploits.

        • It's not the language that's the problem, it's the plug-in runtime environment.

          It's like blaming notepad in windows for the OS crashing.

      • On behalf of all the black hats and script kiddies out there: I applaud your advice, sir.

        Give me a break!

        The guy has already said he's going to be using it to run Java, so whatever bugs are in an older versions of Chrome, kept around to be used exclusively to run the Java plugin, are no worse than the fact that he's using Java in the first place. He obviously doesn't care about security, if the Java lumps I've analyzed being downloaded from pirate video sites are any example, since I've counted no less than 17 unpatched Java plugin exploits being used (before I gave up and quit counting).

        But i

        • No, give me a break. (Score:5, Interesting)

          by Gazzonyx ( 982402 ) <scott.lovenberg@gm a i l.com> on Saturday June 06, 2015 @01:57AM (#49854721)

          You did get the part where he's talking about using Java for work, in a secure environment, yes? You aren't seriously claiming that everyone that uses SuperMicro servers doesn't care about security because their IPMI interface is a Java webstart application, are you?

          I mean, for my own part, I have two choices when doing hardware tests of our appliance builds: I can drive across the Twin Cities from my home office and stand at the R&D rack in a cold and noisy staging area for several kickstart/chef bootstrap/chef converge cycles. Conversely I, as a professional, can assume the risk of using a Java IPMI interface to access a server I physically took from a box and placed in the rack of a secured staging room over a secured subnet accessed over a secured VPN connection on my development VM (with a weekly maintenance snapshot, taken every Monday morning, which I don't hesitate reverting to 'cause SystemD, but that's another story), using HTTPS with the SSL cert from that box I physically placed in the rack.

          If you are somehow cracking past all those barriers into the imaging subnet of our R&D department's subnet, you've already got half a dozen usernames and passwords and have changed a cert that lives on a box whose OS has an average lifespan on the order of an hour (that is, owning that box isn't incredibly useful in and of itself). Even at that point, the new SSL cert is going to tip me off. But if somehow you managed to get past all that, with all that knowledge just to infect my desktop VM, it seems to me that you already have the keys to the kingdom, so to speak.

          That is all to say, just because someone has, or even chooses, to use Java doesn't mean they don't care about security. I'm sure I don't need to explain to you of all people (I read your username and it immediately rang a bell; a quick Google search confirmed my suspicion - I run a lot of code you wrote, and most likely vice versa but to a much lesser degree)that security is about defense in layers, attack surface, vectors and risk/reward. I'm sure there are plenty of other people that use Java in their professional lives that understand and accept the risk of how and where they use it.

          • Conversely I, as a professional, can assume the risk of using IE as the browser that hosts the NPAPI Java applet he wants and not going all fanboi over using a particular tool for all tasks because its the one he likes best.

            I applaud your common sense attitude to using these tools in as safe a manner as appropriate, too bad too many have attitudes that prefer the tool over the tool's use.

          • You aren't seriously claiming that everyone that uses SuperMicro servers doesn't care about security because their IPMI interface is a Java webstart application, are you?

            IMO anyone who knowingly chose to deploy new Java-requiring things in the last many years was not thinking straight, nor were any vendors developing new Java plugins or refusing to work on replacements for the ones they already had. It's not like the fact that the Java plugin is a huge piece of shit is news to anyone.

            If someone was putting out new stuff that still required Windows XP or IE6 you'd rightfully call them incompetent. I believe Java is in the same category. It needs to go away and anyone who'

    • by mysidia ( 191772 )

      Chromium is open source.... why not fork it and create your own version that doesn't disable NPAPI ?

  • by mattventura ( 1408229 ) on Friday June 05, 2015 @06:58PM (#49852847) Homepage
    If your Firefox install and profile are reasonably old, you'll probably have a bunch of cruft. Start fresh (reinstall and start a new profile), import bookmarks, install only the addons you need. Should be plenty fast after that.

    Only problem is that it seems for every new version that comes out, you have to install more and more addons just to keep the browser the same. You could always just use Firefox only when accessing a site that requires java, and use another browser for everything else.
    • Using BarTab Heavy and the other BarTab addons to load and unload tabs in the background makes a huge difference to performance. So does using uBlock Origin instead of ABP. (And NoScript of course).

  • auto-disable and minute long startup times, I haven't seen a java web page in years.
    It's interesting to note that while CS departments are pushing ever more extreme forms of static typing, javascript has won in the most used platform. They never seem to notice that.

    • Re: (Score:2, Insightful)

      by Alomex ( 148003 )

      Actual industrial scale applications require static typing. Scripting which is done by kiddies doesn't.

      Is Golang typed? How about Swift? Or Rust?

      See the difference?

      • Static typing doesn't make an application more or less secure.

        • by Alomex ( 148003 ) on Friday June 05, 2015 @07:12PM (#49852969) Homepage

          This is demonstrably false. While one can write good/bad applications in any language, the set of insecure programs in an untyped language is a superset of the set of insecure programs in a typed language of similar syntax.

          • You say something? Citation maybe? Studies from some well known experts on the subject? No? The NPAPI thing was all about some strongly typed language and its sandbox. Oh yeah, that was Java right? Sure hackers will go for easy targets, the sandbox for example and other things. That means there's architectural deficiencies, not deficiencies with the language or if it's strongly typed or not. Both have their place and their uses. If you don't believe me I have some nice CGI I'd like to deploy on you

            • by Alomex ( 148003 )

              Some statements are so obviously true that they wouldn't appear in a paper. Like 134+56=190. The way to confirm them is to spend a minute thinking about what they claim and saying... gee that's right.

              • by narcc ( 412956 )

                Well, that's one way to defend folk wisdom...

                It sure is easier than doing actual research.

          • by Cafe Alpha ( 891670 ) on Friday June 05, 2015 @07:40PM (#49853163) Journal

            This is demonstrably false. While one can write good/bad applications in any language, the set of insecure programs in an untyped language is a superset of the set of insecure programs in a typed language of similar syntax.

            You really have to be a math nerd to think you've just said anything meaningful about software engineering. You haven't. My God, you haven't!

          • While one can write good/bad applications in any language, the set of insecure programs in an untyped language is a superset of the set of insecure programs in a typed language of similar syntax.

            You're confusing "untyped" with "statically typed". Static typing is about whether type information is available at compile time. C is statically typed, but it has lots of type system loopholes that cause no end of security headaches. In contrast, many dynamically typed languages have no type loopholes at all.

            In fa

      • by Cafe Alpha ( 891670 ) on Friday June 05, 2015 @07:38PM (#49853157) Journal

        There are uses for static typing and other S&M limitations on programming.
        If I had a medical appliance or anything my life depends on, I'd prefer it not even do any memory management - all memory should be pre-assigned.

        In academia they're emphasizing proofs of correctness too - they're all mathematicians not engineers.

        And a language like Java that not only lacks dynamic types but also lacks all abstraction that could obscure what code does, such as macros or templates or overloading - it's horrible to program in, but it saves companies from the effects of having truly stupid engineers and even more incompetent managers who don't allow programmers to document their code let alone require it.

        So horrible Java code has the advantage that it never does anything that can't be understood by reading the code long enough...

        It's the "I can't hire competent people to save my life" department's friend. But a good programmer can accomplish a lot more in a more powerful language.

        On the positive side Java and .net have better garbage collection, more scalable gc more scaleable multithread support than their competition, so there's a niche in hugeness.

        • by Alomex ( 148003 )

          Dude, Java was developed in industry, while most dynamically typed languages (as well as funcitonal languages) have been developed in academia.

  • by present_arms ( 848116 ) on Friday June 05, 2015 @07:00PM (#49852865) Homepage
    http://lifehacker.com/turn-on-... [lifehacker.com] I've noticed a speed bump doing that, and the usual addons for ad blocking etc.
    • Firefox's problem is not page load times. Firefox itself appears bloated and slow. Even after a fresh install after a long time (which prompted the nuking of my profile and resetting all settings) I get graphic hangs when tabbing between pages, slow program loads, etc.

      Notice I didn't say anything about high memory usage, but in reality I think Firefox performed better back in the high memory usage days than it does now.

      • Codger's Law -- any programming scheme, no matter how simple and elegant the initial framework, will eventually be extended and improved into near total unusability.

  • While it's a good idea to push the discontinuation of NPAPI, I think Google are being too aggressive in their phase out. There are a tremendous number of websites that will be disabled if NPAPI is dropped altogether. It's going to take a long time for them to all be brought up to modern standards, especially if they're not well funded.

    It's important to push the conversation and give developers motivation to do the necessary work but if they push too hard, the web will push back and they'll end up shooting

    • While it's a good idea to push the discontinuation of NPAPI, I think Google are being too aggressive in their phase out. ... and they'll end up shooting themselves in the foot.

      Hasn't stopped them before. Google could give a shit really about what the developers and customers want with Chrome. Just like the BS they introduced with the walled garden approach. Thousands of "don't do it's" were ignored.

      • Good point. They'll probably just charge forward without caring who they leave behind.

        But things like this is why corporate IT is still clinging to Windows XP and IE8 in droves. They'd rather stick with what's installed and working than spending the time and money to upgrade.

    • by Henrik Gullaksen ( 2878597 ) on Friday June 05, 2015 @07:13PM (#49852981)

      Google announced in September 2013 that it would phase out NPAPI support in Chrome during 2014.
      NPAPI support is disabled by default since April 2015 (version 42) for Windows and OS X, but can be turned on in the settings.
      Google plans to drop Chrome NPAPI support from all platforms in September 2015.

      I wont call 2 years warning aggressive. I would call it more then a fair warning.
      And if web-apps or plug-in's are not up to modern standards by now. Then extending to time they have to fix it wont help. Because the only things that's not updated by now wont be as long as they do not have to.
      Now they are being forced to do it. And it comes as a chock for some that they only got 2 years warning.

      • No one is being "forced" to do anything. All this is doing is making one more type of incompatibility that further drives a wedge between the modern web and corporate IT because I guarantee that the companies that haven't upgraded from XP/IE8 won't be phased by this new incompatibility.
        • How about users of enterprise software, managed switches, Cisco gear, and embedded appliances for whom their shiny Windows 7/8/10 (for those corps that would run 8 or 10 - I'm sure they exist somewhere), Fedora 22, Mac OSX-latest still can't access said software, hardware, appliances? You do understand that I didn't write SuperMicro's Java interface and I'm not at will to upgrade to software that doesn't exist on something I didn't make regardless of how shiny my frakkin' operating system is, right?

          You are

  • Googles Answer... (Score:5, Informative)

    by Anonymous Coward on Friday June 05, 2015 @07:06PM (#49852923)

    From the Chromium Blog:
    In April 2015 NPAPI support will be disabled by default in Chrome and we will unpublish extensions requiring NPAPI plugins from the Chrome Web Store. Although plugin vendors are working hard to move to alternate technologies, a small number of users still rely on plugins that haven’t completed the transition yet. We will provide an override for advanced users (via chrome://flags/#enable-npapi) and enterprises (via Enterprise Policy) to temporarily re-enable NPAPI while they wait for mission-critical plugins to make the transition.

  • by dwywit ( 1109409 ) on Friday June 05, 2015 @07:10PM (#49852961)

    Tweak firefox with:

    new tab, type "about:config" into the address bar.

    find "network.http.pipelining" and set it to "true"
    find "network.http.pipelining.max-optimistic-requests" and set it to 8
    find "network.http.pipelining.max.requests" and set it to 32 if it isn't that already. Don't take this one too high.

    • Or, tweak Chrome with:

      new tab, type "chrome://flags"

      find "enable-npapi" and set it to "true"

      It will be possible to enable NPAPI in Chrome for some time yet. The reason for disabling it by default is to push plugin vendors to port to better approaches that don't leave your system security at the mercy of whatever web page you happen to hit.

      • It will be possible to enable NPAPI in Chrome for some time yet. The reason for disabling it by default is to push plugin vendors to port to better approaches that don't leave your system security at the mercy of whatever web page you happen to hit.

        According to this https://www.chromium.org/developers/npapi-deprecation [chromium.org] they plan to completely disable NPAPI by September 2015. Your workaround buys him about 4 months.

  • Too bad you don't have enough storage space to have multiple browsers installed. I use Opera, but can also use IE, Firefox or Chrome if I run into any compatibility issues. How hard is it to copy/paste a URL?
  • What slows down firefox are the nested javascript ads and sometimes the pointless ad movies that are in the corners of screens.

    Use NoScript and make a point of only having javascript enabled for domains that you WANT to run javascript from.

    And then firefox is actually quite fast. Added bonus... less bullshit cluttering up your pages.

    • Too much of a pain to do all of that, at least for me. I simply route the various ad hosts I find annoying to 0.0.0.0 in my hosts file, and enjoy.

      • You find it easier to actively manage your host file than to install one bit of software and spend perhaps a minute managing every now and again?

        Okay.

  • Don't believe me?

    Go to peacemaker benchmarks? Firefox uses less ram and cpu bloat. On my atom surface chrome is twice as slow and borderline unusable.

    FYI you could ... gulp use IE for your work sites? You won't continue your cpu with that filth of IE 6. IE 11 is bug free and us ok. Not awesome but usable and standards compliant now.

    EDGE in Windows 10 will be the best browser from what I see so far so if you're willing to upgrade next year that may solve your problem

    • I dont have a problem with Chrome on Surface 3 (128GB/4GB). How many tabs are you opening? Do you have the 64GB/2 GB RAM version?
    • I take issue with your benchmarks and claims. I don't care what it says on the benchmarks, the latest version of Firefox complete with profile reset at the end feels slow. The interface that is. Page load times are fine, memory usage I don't care about (Firefox has used less RAM than Chrome for about the past 2 years already), but the browser is slow to use.

  • by grilled-cheese ( 889107 ) on Friday June 05, 2015 @07:17PM (#49853011)
    Per the Java support site [java.com], go here: chrome://flags/#enable-npapi [chrome]

    They probably won't support enabling it forever, but for now it's a workaround.
  • Use 2 Browsers (Score:2, Insightful)

    by Anonymous Coward

    This is only a problem because you insist that everything happen in one piece of software. That is not a requirement, or at least not one you shared with us.

    If you want to complete a task that requires a particular piece of software, use the required software for that task. Then use whatever software you want for all other tasks. This will not only let you use the browser you want for most things, but will let you optimize the NPAPI browser for that particular use without worrying about security and updates

  • Available for advanced / enterprise users.
  • why do you have to use just one browser for everything?

    there's nothing stopping you from using chrome for most sites, and firefox (or whatever) for the handful of sites that require java.

    in fact, IMO, you're better off using multiple browsers to minimise the tracking that can be done of you. e.g. i have one browser (midori) that i use ONLY for facebook and nothing else; my main general purpose browser is iceweasel with adblock plus and noscript and other privacy-enhancing plugins; i use chrome to view yout

    • How true. My work has authorized Chrome, and I'm testing the 12 or so distinct internal sites to see how terrible they function with it. Most internal sites work best with IE8, but IE9 is usable, and IE10 manageable. Our most secure site no longer functions correctly with IE for internal users, but Firefox is an excellent option, and Chrome is functional. I have not reinstalled Firefox since my last upgrade.

      But, our users for the site I primarily support use IE8,9,10, Firefox, Safari, and Chrome. Safar

  • Really sounds like some major whining for the minor annoyance of free stuff screwing you, and not being able tolerate a slight slow down in using your other free program.

  • You have to accept the security issues of java, while installing it, Now if javascript would lose it's following.

    I'd suggest giving Opera a try but it will update itself with no warning it will or has.

  • the work site.

    There is a REASON browsers are slowly eliminating support for this sort of crap.

  • Visit: http://www.saveie6.com/ [saveie6.com]

    Enjoy the freedom and speed!

  • Okay, I'm saying this with almost no knowledge of the fundamental differences between npapi and pepper, but wouldn't it be possible to write a pepper plugin that implement npapi, and can load "legacy" plugins?
    Sure, it might be some work, but I have the feeling that a handful of people would be hapy to help maintain this. Of course, the best solution would be to move on and adopt a new standard, but that won't happen as long as there is a possibility to use another browser/use an old version of the browser

"Protozoa are small, and bacteria are small, but viruses are smaller than the both put together."

Working...