Slashdot Log In
Mozilla CEO Objects To Safari Auto Install
Posted by
CmdrTaco
on Sat Mar 22, 2008 11:19 AM
from the hey-wait-a-minute dept.
from the hey-wait-a-minute dept.
hairyfeet writes "Do you use iTunes on Windows? If so you may be getting the gift of Safari from Apple whether you want it or not, and Mozilla CEO John Lilly is not happy about it. After his daughter was offered Safari as a 'bonus update' with a recent update to her iTunes software, Mr. Lilly says on his blog, 'What Apple is doing now with their Apple Software Update on Windows is wrong. It undermines the trust relationship great companies have with their customers, and that's bad — not just for Apple, but for the security of the whole Web.' He also pointed out the check box is already clicked when you go to update meaning you have to opt out, not in and that it lists Safari as getting an update even if you don't have it installed." Update: 03/21 21:44 GMT by KD : Corrected the name of the Mozilla CEO; also linked directly to his blog.
Related Stories
[+]
Apple: Safari 3.1 For Windows Violates Its Own EULA, Vulnerable To Hacks 368 comments
recoiledsnake writes "The new Safari 3.1 for Windows has been hit with two 'highly critical'(as rated by Secunia) vulnerabilities that can result in execution of arbitrary code. The first is due to an improper handling of the buffer for long filenames of files being downloaded, and the second can result in successful spoofing of websites and phishing. This comes close on the heels of criticism of Apple for offering Safari as a update for approximately 500 million users of iTunes on Windows by default, and reports of crashes. There are currently no patches or workarounds available except the advice to stay clear of 'untrusted' sites." Further, Wormfan writes "The latest version of Safari for Windows makes a mockery of end user licensing agreements by only allowing the installation of Safari for Windows on Apple labeled hardware, thereby excluding most Windows PCs." Update: 03/27 17:23 GMT by Z : Dave Schroeder writes with the note that the license has been updated to correct this mistake.
This discussion has been archived.
No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.
Obligatory (Score:5, Interesting)
Re:Obligatory (Score:5, Informative)
They kind of already do...and there have been...but the reason Apple won't face any lawsuits for this is because they are breaking into the Windows browser market, not dominating it. If they ever gained control of that market, then lawsuits may crop up (even still, you can always uninstall iTunes and use the iPod with one of a number of other programs, something Apple would be sure to point out).
Parent
Re:Obligatory (Score:5, Funny)
Parent
Re:Obligatory (Score:5, Informative)
So, in essence, Apple is doing the exact same thing. They are leveraging their monopoly in MP3 players to break into a new market - browsers.
Parent
Re:Obligatory (Score:5, Insightful)
I completely agree with you. Many times people say "If Microsoft did this... blah blah" and most of the time the comparison is completely silly. But this time it's spot on. And Apple is just as wrong to do it as Microsoft was (and is).
Parent
Re:Obligatory (Score:5, Interesting)
Actually, I'd say it's even a little worse than that. Microsoft back in the day made the argument that people were starting to expect web browsing to be part of the "basic functionality" of a computer and that it made sense to ship IE as part of Windows. While their dirty pool in the browser wars is now a matter of public record, that piece of it at least did make sense.
There's really no way you can argue that people expect to get a new web browser with an update of iTunes, though.
Parent
Re:Obligatory (Score:5, Insightful)
Parent
Re:Obligatory (Score:5, Informative)
Parent
Re:Obligatory (Score:5, Informative)
As good as Apple is at making iPods, there are clones galore out there that work "just as well", are cheaper, and are selling tons of product.
Comparing the Apple and the iPod to Microsoft and Windows is quite absurd.
(all that said, I think an automatic install of safari with itunes upgrades sounds sleazy. Unfortunately being sleazy isn't illegal...)
Parent
Re:Obligatory (Score:5, Insightful)
Well, I sort of disagree with some of what you're saying, but you shouldn't really have written:
Vista is highly unpopular and generally unwelcome, yet pretty much every major PC manufacturer except Apple is bundling it with their mainstream PCs. And when their mainstream PCs are offered with an option that isn't Vista, it's XP. So Microsoft is still dominating the desktop.
When Dell, HP, etc, start bundling Ubuntu or Mac OS X or Syllable, or AmigaOS, or OpenVMS, etc (heh) with most of their mainstream, as in "you can walk into Circuit City, Best Buy, Office Depot, Office Max, Staples, Wal Mart, etc, and see these PCs on display running that OS", PCs then we can reasonably say Microsoft has lost its monopoly power. At this stage though, no it hasn't. It's just not doing well persuading people to like its newest product.
Parent
Re:Obligatory (Score:5, Insightful)
That makes no sense. If a copy of Office 2008 for OSX installed Windows Media Player to fight off iTunes then slashdot would melt from the outrage. When Apple does it, slashdotters bend over bankwards to rationalize it.
The enemy of your enemy is not your friend.
Parent
Re:Obligatory (Score:5, Informative)
Not quite:
The user can easily opt-out of getting the browser, and Apple is in no way preventing users from using another product. I don't agree with this move by Apple, but I can safely say that it isn't product tying.
Parent
Re:Obligatory (Score:5, Informative)
Parent
Re:Obligatory (Score:5, Insightful)
And it's not just Safari. It's iTunes as well. If you have QuickTime or Safari (it's been in beta on Windows since last summer), but not iTunes, the updater will offer you iTunes -- preselected -- every time a new version comes out, and call it an update. It's only become an issue now because most people using Apple Software Update on Windows were using it for iTunes. Since Safari was in beta until recently, the only things the updater offered were iTunes and QuickTime -- things that were already on most users' machines.
Parent
Re:Obligatory (Score:5, Insightful)
Sketchy tactics are sketchy.
Parent
Re: Obligatory (not) (Score:5, Insightful)
>begins), is the installation of Safari being checked by default.
>
>If they unchecked that box Apple would be golden from the moral
>side of things and there would be no problem at all.
I disagree. By mixing up "new stuff you may or may not want" with "stuff you really, really, really need to install immediately to keep your already installed software safe from exploits" is just a bad, bad idea.
When my software update mechanism comes up with a critical security update and I have to spend time trying to work out whether or not I should check or uncheck or install or not install, it creates confusion and leads to some percentage of people not opting in for the right parts.
If Apple wants to use the same infrastructure to advertise new products, fine by me, but don't mix them in with real updates for software I already have installed. Make it clearly a different interaction.
But they won't do that. They don't want to create an advertising mechanism here, they want to create a situation where users feel like they "need" to install this new software by associating it in every way possible with critical security updates.
It's not enough to simply uncheck the box. There needs to be a clear distinction that most users will understand between "update what I've already got on my system so that I can stay safe and secure" and "offer me new stuff that i may or may not want."
- A
Parent
Not only Safari but iTunes too... (Score:5, Informative)
Parent
Re:Obligatory (Score:5, Interesting)
This happens with Bonjour too. If you install Bonjour for Windows (something that ought to be installed on every Windows box, IMO), you'll be offered iTunes and QuickTime as "updates" later.
Calling installation of a new unrelated application an "update" is pretty underhanded.
Parent
it gets worse (Score:5, Informative)
Now, Safari might be nice, I don't know I've never used it. But, I do know it is insecure compared to Opera and Mozilla. It also lacks a lot of privacy features, script blocking, deep cookie management, password wands, etc. The irony is that Opera while being the most innovative browser is only the most secure web browser right now because it is unpopular, they lack managed script blocking. You can turn off scripts but no one in their right mind does that. We need to have whitelists so we only allow what we know we need. Blacklists don't work because you can't keep them up to date fast enough and disabling entirely isn't reasonable because there are many situations where scripting/cookies are absolutely necessary. The same goes for Internet Explorer and Safari, they lack this what should be by now, mandatory functionality. And, really, this should be built directly into Firefox itself, but has not been because a majority of people would simply be confused why their websites aren't working correctly. It has to be informed decision to install and try the plugin and understand what it is doing. I suspect this is the reason that other browsers have just completely ignored this functionality altogether.
In addition, I'd like to point out that Mozilla's AdBlock plugin, although bad for the advertising business, is a benediction for security as well. Too often now banners are being used to inject malicious arbitrary code into end user's computers. Even on Microsoft's own Hotmail email service!
Mozilla actually out innovates Opera in features when you look at the plugins, but the main browser itself does not. Until recently Opera has been the fastest and most compliant browser in the world, though it historically has had trouble rendering some websites. It has greasemonkey-like functionality built in which is a nice plus. With the advent of Firefox 3 coming out though, Opera and Safari lose the speed crown and also cannot compete with the plugins, privacy, or security. You can bet Apple knows this and wanted to pull this stunt before Firefox 3 became mainstream, because after that it is game over.
Mr. Wilcox has every right to be afraid for global security because of this new tactic by Apple.
Parent
Re:Obligatory (Score:5, Insightful)
As far as the iPod monopoly goes--it doesn't. iTunes (and Apple software) isn't the only way to manage your iPod, and Apple doesn't intentionally make it hard for other software to compete. iPods themselves aren't a monopoly, despite a fairly high marketshare, and they certainly aren't anticompetitive, as other music stores are able to compete just fine. iTMS could be considered anticompetitive, except that they're trying to move away from DRM on their music.
Your post sounds like a knee-jerk reaction to Apple fanboys.
Parent
Re:Obligatory (Score:5, Insightful)
>even then, only to a fairly small subset of people.
>It's a move that makes me look up and wish that Apple
>were a friendlier company, but uproars? That's a
>bit much, I think.
It's much worse than annoying. Users today mostly feel comfortable clicking OK on software update dialogs because software update keeps their *installed* programs secure. It's the best method a vendor and a user have to ensure that the software isn't going to be exploited.
When *installers* bundle extra programs and install them by default (opt out rather than opt in) it's *annoying*. When *updaters* bundle extra programs and install them by default (opt out rather than opt in) it's damaging to the trust relationship that users and vendors have relied on to keep software safe and secure.
That's much worse than annoying.
- A
Parent
Re:Obligatory (Score:5, Insightful)
br>
Oh yes, as if adding a hash to stop third-party applications isn't "intentionally making it hard" http://apple.slashdot.org/article.pl?sid=07/09/14/1831236 [slashdot.org] I don't know what is. Now granted that, has been broken but still it is no excuse for Apple to decide to block third-party applications from using the iPod.
Parent
Re:Obligatory (Score:4, Insightful)
Yes, Apple could be more explicit about the Safari download, but you still give permission to install it (yes, the box is checked by default; no, there is no reason why you can't uncheck it). iTunes won't stop working without it. Your OS won't stop working without it (note that even under OSX there is no reason you can't uninstall Safari).
Parent
I'm amazed you were modded up... (Score:5, Insightful)
But all that is completely beside the point, because the real issue is other products being pushed out by default through the software update for an unrelated product by the same company. Which is what Apple Software Updater is doing.
Firefox's update by comparison *cannot* download another product that you don't have installed, not only that, but it doesn't suggest any other products, or even mention that they exist.
Your point was that Firefox "offers" their products, where they do not, they simply provide links in their browser to their site where if you wish, you can choose to go and search for their products. Your other point was that Apple is simply "offering" their products, but it isn't doing that either, it is selecting them for you, and choosing to download them to you if you don't specifically deny them every time there is a product updated.
These are two completely different things.
Parent
Re:Obligatory (Score:5, Insightful)
>to download Adobe Reader only to have it auto-install the
>Google / Yahoo (whoever's paying them that month) IE toolbar
>unless you opt out?
Yes, but this is apples and oranges. Installers are one thing. Software updaters are another. With an Installer, you haven't installed the software yet and you are free to chose options (or not, I really don't want to defend crappy installers) but with an updater, you've installed the software and you should be able to trust it to simply update itself, not to transform into an installer for other software and to mix in those other offers with security updates for the piece of software you did install.
Installers and updaters are not the same thing. Abusing updaters is really, really bad for everyone because it causes people to lose trust in the updaters and that means lots of people less secure in the long run.
>Basically, when I install something -- no matter WHAT I'm
>Installing -- I don't want any other software auto-installed
>without an opt-in. Heck I even hate all the little
>auto-update craplets that get installed with every software
>package out there from Sun Java to iTunes to Reader
Again, installers are not updaters and I don't hold them to the same standard. That being the case, I agree with you. Installers mostly suck (We try hard not to suck with Mozilla Firefox's installer and I think we're doing a pretty good job) and users should complain. But bad acting installers are not even in the same category as updaters for installed software.
- A
Parent
quicktime also (Score:5, Informative)
Re:quicktime also (Score:5, Informative)
Parent
WHY are Apple doing this? (Score:5, Insightful)
Has any company ever entered better light from including unrelated junk in their installers?
If iTunes doesn't require Safari (and I pray to god it doesn't because that would be horrible design to require a specific web browser -- they'd enter Microsoft territory in that case), then Safari shouldn't be part of the install. If people want Safari, they'll install Safari. If something doesn't need Safari, fuck that shit.
Please don't look at Microsoft as a good role model, Apple. They aren't.
Re:WHY are Apple doing this? (Score:5, Insightful)
So what are the "half a hundred things" that are bundled, assuming you mean applications, not default preferences (which, to me, are very different things). If you download Firefox from mozilla.com, you get Firefox, that's it.
If you don't want the update page to show up after a successful upgrade, just set the value for browser.startup.homepage_override.mstone [mozillazine.org] to "ignore".
Parent
iTunes? Ycuk! (Score:5, Funny)
He should listen to his own advice (Score:4, Interesting)
Re:He should listen to his own advice (Score:4, Insightful)
Paying $4 million for a open source project and pushing your anti phishing framework while dozens of other alternatives exist already makes some people concerned.
Parent
Re:He should listen to his own advice (Score:5, Informative)
Firefox, if you get it from Mozilla (Mozilla is the vendor that creates and maintains Firefox) doesn't come bundled with Google software. Firefox does come with features that integrate web services from several vendors including Google, but there's just no "Google software" "bundled" with Firefox when you get it from Mozilla.
- A
Parent
We need a new title for this (Score:5, Interesting)
installware: software that installs other products that the user would not expect to be installed as a default option. This includes any 3rd pary addons or 1st party products that are unrelated to the current install.
something that would lable products that instal browser bars too. We know some products work hard to not get listed as spyware or adware. Its time to expand it to include this other crap.
Easy Solution: Unchecked and Labeled (Score:5, Insightful)
1. Make all not-yet-installed software unchecked by default, so you have to opt into it (keeping actual updates checked by default)
2. Clearly label, probably by putting a separator and header in the middle of that list, which software is an update to what's on your machine and which software is another offering that Apple wants you to install.
That, and make it possible to ignore a product, instead of just a particular install. My Windows box at work has Safari and QuickTime for web development purposes, but it keeps telling me to "update" iTunes. I can tell it to ignore the item, but every time a new iTunes version comes along, it asks again.
Re:Easy Solution: Unchecked and Labeled (Score:4, Insightful)
At least "Internet Explorer" is reasonably named. How does the name "Firefox" or "Safari" relate to web surfing? Your average safari is held pretty far from the ocean.
Parent
I feel your pain (Score:5, Funny)
Link to John Lilly's actual blog post ... (Score:5, Informative)
http://john.jubjubs.net/2008/03/21/apple-software-update/ [jubjubs.net]
get over it (Score:4, Insightful)
Oh, please. Apple is as evil as Microsoft, and Mozilla is right to complain about them.
Claiming that open source and Apple have some kind of common interests is fiction.
Parent
Re:Fake fight, Slashdot has been trolled hard. (Score:4, Insightful)
You are absolutely right. Apple is hardly forcing Safari on people since it asks first and they can decline the download. I decline downloads offered from Apple and MS all the time. This is a complete non-issue brought up by someone wanting free press.
The Mozilla folks are whining because there is some chance that a significant portion of Firefox users will switch to Safari. I have used Firefox since beta on Windows machines, but I will switch to Safari if it is faster. Firefox is dog-slow on a Mac, and I don't even consider it on that platform.
Parent
Re:Fake fight, Slashdot has been trolled hard. (Score:5, Insightful)
>so it still fulfills Mozilla's dream of a standards-based web,
>even if actual Mozilla software isn't being used.
It's not about Safari being used. I'm all for a healthy, competetive browser market where users can chose between several great standards compliant browsers. That's a big piece of what Mozilla is all about.
The problem here is not that Safari may get more users. The problem is that they have used "software update" to install a *new* piece of software. Safari is not a software update for QuickTime and it's not a software update for iTunes. It's an entirely new piece of software being pushed by Apple as if it was an update when it's clearly not.
This is a problem because it waters down the meaning of "software update" -- something that vendors depend on to keep users safe and secure and that users should be able to trust. Users shouldn't second guess themselves when clicking "OK" on a software update dialog. If they're afraid of software update services, it'll be impossible for vendors to keep them safe with security and stability updates.
It's this trust relationship being abused by Apple that's the problem, not that more people may end up with Safari.
- A
Parent
Re:Fake fight, Slashdot has been trolled hard. (Score:5, Insightful)
I'd have more issues if Microsoft decided to force a download of (say) Visual Studio Express as an "upgrade" to Windows (or any other component that's not a part of Windows). Or if they made the Silverlight update enabled by default (as of today, they offer it as an optional download (it's disabled by default)). Heck Microsoft doesn't even include Office products in Windows Update (you have to opt into the Microsoft Update version to get non Windows products offered in Windows update).
Apple's doing one of two things: either they're (a) leveraging their iTunes monopoly to push Safari or (b) using their security holes as opportunities to upsell iTunes and Safari (since you need to use Apple Update to get fixes for the Quicktime security hole of the week)
Neither of these are OK in my opinion. Software update should be for updating existing software to fix bugs in the software you chose to install.
I don't have any problems with the Apple updater offering other products, I do have issues with the updater offering those products by default.
Parent
However bad this is (Score:5, Insightful)
We've seen more problems with "my IE is crashing" lately, and every time it's that Google Crapbar that slipped in because the users didn't even get the chance to know it was coming in.
Parent
Re:Who modded this down? (Score:5, Informative)
I don't trust Apple installing ANY Windows software. I have yet to successfully install iTunes without the stupid mandatory Quicktime installation taking over most of my media file associations, no matter how hard I try to disable them. It even tries to display JPEGs in Quicktime instead of inline in IE. Apple obviously knows about this, because everyone I know who has tried this has had the same experience.
Parent
Re:Who modded this down? (Score:4, Interesting)
Parent
Re:Yes, this is spin but it's not mine. (Score:5, Insightful)
I think a lot more of Apple than I do of MSFT, but then I'd rather catch rabies than AIDS....
Parent
Re:Apple == MS$? (Score:5, Funny)
1997.
Parent
Re:Also, QuickTime tries to install iTunes. (Score:5, Informative)
Parent
Re:Bullshit! (Score:5, Insightful)
>I did not have a choice. Apple offered me Safari and I
>turned them down.
Microsoft didn't Force IE 8 on anyone. It's not even included in their Software Update system. It's a standalone download that you have to seek out on the web.
Perhaps you meant IE 7 which was offered as an update through their SOftware Update system. Well, guess what. IE 7 *is* an update to IE 6 -- a critical one for very legitimate security issues. You can opt out but you'll be doing yourself a security and safety disservice.
Safari 3.1 is *not* an *update* to iTunes or to QuickTime and calling it an update is misleading at best and predatory at worst. Not only that, but it weakens the trust relationship between vendors and users when it comes to software update systems.
Software update systems should be *update* systems and users should feel comfortable clicking "OK, keep me up to date, safe, and secure". When *update* systems are abused like this, people trust them less and it's more difficult for vendors to keep those users safe.
- A
Parent
Re:Windows Behavior? (Score:4, Informative)
>get other companies to bundle their toolbar
>and hard-wire or at least default their browser
>searches to Google as well (Safari and Firefox).
Google didn't try to get Firefox to bundle its toolbar or hardwire it as the default search. Firefox (and Mozilla before Firefox) had Google as a built in option going back to 1999 or 2000, it was made the default in 2002 or early 2003 (replacing Netscape search, which was just a rebranded Google search) and there was no relationship with Google until late 2004.
We put Google there because people wanted it and it was extremely useful. We also made sure that you could change the default easily and add as many additional search services as you want (Today we ship Yahoo, Ebay, Wikipedia, Amazon, and others as selectable options and there are more than 10,000 additional services available at mycroft.mozdev.org.)
- A
Parent