I manage over 400 servers, all of these have a built in remote kvm functions, 70-80% of these servers requires java to use and they not all the same vendor either, some are HP, some are different and some also use a 3rd party kvm device.
I picked on chrome as I see rapid updates, automatic background updating and auto silently block out of date pkugins as bad features, chrome also isnt very tunable (unless I am missing something) eg. cant tune the connection limits, timeouts, keepalive etc. Its hard to even install it to a non standard location, use a ramdisk for temp files and so on. In that respect its a very dumbed down app compared to firefox, after chrome started getting a good userbase firefox dev's have very clearly been copying it on policies, and I consider firefox to have gone downhill since then.
The latest java even on IE now needs click approval, IE supports click to play by itself as well (just not enabled by default) by removing the * from approved sites, then that will generate a prompt for every site not yet approved, as well as IE10 on windows 8 supporting a higher security mode.
There is security and then there is going too far silently blocking apps that can be crucial without warning and then with no working upgrade/workaround path in place is just silly and it shows that firefox devs have lost touch with their userbase. If you googled the issue you will find dozens and dozens of hits of people making posts on various sites complaining of the same issue, its one of those things where they scared of some bad PR so took draconian measures.
You of all people should know security is a layered approach, just because someone might have a slightly vulnerable piece in place it doesnt mean they are then suddenly likely to get compromised.
BT Infinity 2 Since Dec 2012 - Estimate 65.9/20 - Attainable peak 110/36 - Current Sync 71/20
Edited by Chrysalis (Wed 30-Jan-13 18:21:39)