Feeds

Firefox 4 beta gets hard on Windows

Drops 60s psychedelia API

Choosing a cloud hosting partner with confidence

Mozilla has released a fifth Firefox 4 beta, offering graphics hardware acceleration on Windows and a new API that lets site developers code pages that visually display audio data inside the browser.

"The latest update to Firefox 4 Beta brings super fast graphics and incredible new audio capabilities to the Web," reads a blog post from Firefox development head Mike Beltzner.

The new beta also includes HTTP Strict Transport Security (HSTS), which lets websites demand that Firefox always use a secure connection when visiting. "Firefox 4 Beta now remembers what sites use the HSTS protocol and will only connect to those sites using SSL (Secure Sockets Layer) in the future, helping to prevent 'man in the middle' attacks," Beltzner says.

If you're running Windows Vista or Windows 7 and your graphics card is DirectX 10–compatible, Mozilla's beta will automatically accelerate graphics via Microsoft's Direct2D rendering system. Previously, the beta — and the Firefox 4 alpha — offered such hardware acceleration as an option, but it's now turned on by default.

In a separate post, Mozilla man Bas Schouten said that although there's nothing analogous to Direct2D from other OSes, Mozilla is also "working hard on alternative approaches to use hardware acceleration on other platforms."

The browser's new audio data API — dubbed Audio Data API — exposes raw audio data housed in HTML5's <audio> and <video> tags. With the API, coders can read and write audio data within the browser, building pages in Javascript that seek to turn a piece of sound into an animated graphic. "In December, a few of us...had an idea," reads a blog post from Seneca College professor and Mozilla contributor David Humphrey. "What if we could visualize sound data coming out of an <audio> or <video> element? My colleagues were good at thinking in terms of 'how can we make what we have now work?' But I had another idea: 'Let’s try and teach Firefox how to do this.'"

Clearly, this is the ideal tool for those looking to build an homage to late-60s psychedelia:

Last year, Mozilla began work on a project called ForceTLS that would allow sites to force a secure connection. "The main idea was simple, yet powerful: allow sites a way to say 'in the future, ALWAYS load me via HTTPS,'" said security maven Sid Stamm. The idea has now been added to the Firefox beta using the HTTP Strict Transport Security (HSTS) protocol.

"If Firefox knows your host is an HSTS one, it will automatically establish a secure connection to your server without even trying an insecure one," Stamm says in a new post. "This way, if I am surfing the 'net in my favorite cafe and a hacker is playing MITM [man in the middle] with paypal.com (intercepting http requests for paypal.com and then forwarding them on to the real site), either I'll thwart the attacker by getting an encrypted connection to paypal.com immediately, or the attack will be detected by HSTS and the connection won't work at all."

Stamm adds that work on the project is not completely finished. The team also aims to include an interface that lets you remove the HSTS default for a server on your own.

The Firefox 4 beta 5 can be downloaded here. And you can leave feedback here. A complete, stable version of Firefox 4 is scheduled for arrival in November. ®

Internet Security Threat Report 2014

More from The Register

next story
Preview redux: Microsoft ships new Windows 10 build with 7,000 changes
Latest bleeding-edge bits borrow Action Center from Windows Phone
Google opens Inbox – email for people too thick to handle email
Print this article out and give it to someone tech-y if you get stuck
Microsoft promises Windows 10 will mean two-factor auth for all
Sneak peek at security features Redmond's baking into new OS
UNIX greybeards threaten Debian fork over systemd plan
'Veteran Unix Admins' fear desktop emphasis is betraying open source
Entity Framework goes 'code first' as Microsoft pulls visual design tool
Visual Studio database diagramming's out the window
Google+ goes TITSUP. But WHO knew? How long? Anyone ... Hello ...
Wobbly Gmail, Contacts, Calendar on the other hand ...
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
Ubuntu 14.10 tries pulling a Steve Ballmer on cloudy offerings
Oi, Windows, centOS and openSUSE – behave, we're all friends here
prev story

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.