#1094957 firefox-esr: Message encourages user to download browser from Mozilla repository

Package:
firefox-esr
Source:
firefox-esr
Description:
Mozilla Firefox web browser - Extended Support Release (ESR)
Submitter:
Leandro Cunha
Date:
2025-02-01 21:39:02 UTC
Severity:
normal
#1094957#5
Date:
2025-02-01 20:39:43 UTC
From:
To:
Dear Maintainer,

Showing a warning with the text "some of Firefox's security features
may offer less protection on your current operating system", with the
link below[1] recommending downloading from the Mozilla repository
claiming that this way I would have more protection? Firefox is
distributed in RPM, distributed in DEB and even Arch distributes it in
its official repositories like Debian. This information may encourage
users with less knowledge to follow what would be mentioned in the
link below. I believe that this message is also not true regarding the
security issue and I trust the work of those who have maintained it
for so many years. See screenshot.

This message is not relevant, but you can create a patch to remove it
and precisely to prevent more lay users from avoiding using Firefox
ESR (for example) offered by Debian.
This with the idea that such security problems would be fixed.

[1] https://support.mozilla.org/en-US/kb/install-firefox-linux

#1094957#10
Date:
2025-02-01 21:24:34 UTC
From:
To:
The message *is* relevant, and the link, while misleading, is kind of
right, but it doesn't bring you to the relevant part of the page, which
is at the end, under "Security features warning".

The link should probably be changed to

https://support.mozilla.org/en-US/kb/install-firefox-linux#w_security-features-warning

But I'd argue it should have its own separate support page.

Mike

#1094957#17
Date:
2025-02-01 21:38:04 UTC
From:
To:
"The sandbox in Firefox makes use of unprivileged user namespaces when
creating new processes for enforcing more security. This can be
considered a security risk, therefore some Linux distributions have
started to restrict its usage and only allow it to work where there is
an AppArmor profile."

Interesting, but the question would be that I need to configure
Firefox ESR for this as a security enhancement? I agree that it is
directed to a page that covers the topic very broadly and it would be
interesting if it were separate.

I would be unaware of this issue if it weren't for this message, if it
addresses what you mentioned it would be a useful message indeed.