Next release, ipc library and Firefox 2
Hello everybody,
As we now know that not using an xpcom is a relay bad idea (before I think it’s was only a bad), we have to make a new release of firegpg, quickly…
Problem is : it’s dosen’t works for firefox 2. It’s works only for windows and linux (32 bits).
So we will have to stop the support of Firefox2, and the ‘support’ for Mac OS (and *BSD btw). Notice it’s possible to build the ipc library for MacOS (and *BSD), so if you have to tools to build it, you can.
Anyways, if someone is ready to make a donation of an old mac (intel architecture) with shipping to Morocco or Switzerland, you know our email ;)
Release will come as soon as possible (~2 weeks).
Comments
We made it voluntary, to remove most of old version with security issues in production.
Maximilien Cuony [The_glu] , 2008-10-21 19:29:49
You should specify in the xpi file that the extension requires Firefox 3 so that Firefox 2 users won’t get an upgrade notification for the new version.
John, 2008-10-21 19:27:03
Could you clarify that? I updated my FireGPG before I knew that it would fail, is there a way to recover the old, insecure version? Is there any page explaining what the problem was (i.e. why is not using an xpcom a really bad idea)?
Adam, 2008-10-21 22:35:29
We let’s user update as firegpg may doesn’t works anymore, but there is no more security problem.
See install page for old version.
http://packetstormsecurity.org/0810-advisories/firegpg-cleartext.txt for the problem.
Maximilien Cuony [The_glu] , 2008-10-21 22:38:02
What was the previous version? Current version is 0.6.1, but 0.6.0 doesn’t seem to be there.
Adam, 2008-10-21 22:51:19