LandzDown Forum

Security => Security Alerts & Briefings => Topic started by: Corrine on March 17, 2022, 07:34:58 PM

Title: Pale Moon Version 30 Released with Security Updates and Return to Firefox's GUID
Post by: Corrine on March 17, 2022, 07:34:58 PM
Pale Moon has been updated to version 30.0.0.  In addition to security fixes as well as extensive internal changes, of note is the following:

Quote
"Pale Moon is abandoning its own GUID (globally-unique identifier) and adopting Firefox's GUID instead to provide maximum compatibility with old and unmaintained Firefox extensions alongside those that are maintained on our add-ons site."

Most notable user-facing/implementation changes:
Bugfixes, stability and security:
*DiD This means that a fix is "Defense-in-Depth": It is a fix that does not apply to a (potentially) actively exploitable vulnerability in Pale Moon, but prevents future vulnerabilities caused by the same code, e.g. when surrounding code changes, exposing the problem, or when new attack vectors are discovered.
Pale Moon includes both 32- and 64-bit versions for Windows:  Pale Moon for Windows downloads (http://'https://www.palemoon.org/download.shtml?fbclid=IwAR2YsYQ2YAbSVgyFl_bk5GfMJyNy1FfvPYK9MYSCSanIHmx9U7ZspxJeImo').
Update
To get the update now, select "Help" from the Pale Moon menu at the upper left of the browser window.  Select About Pale Moon > Check for Updates.

Release Notes (https://www.palemoon.org/releasenotes.shtml)
Release Cycle]https://developer.palemoon.org/docs/release-engineering/]Release Cycle (https://developer.palemoon.org/docs/release-engineering/)
Title: Re: Pale Moon Version 30 Released with Security Updates and Return to Firefox's GUID
Post by: Forlorn on March 19, 2022, 12:49:26 PM
Glad to see that Pale Moon is still letting us use NoScript
Title: Re: Pale Moon Version 30 Released with Security Updates and Return to Firefox's GUID
Post by: Corrine on March 20, 2022, 03:08:09 PM
Unplanned outage (https://forum.palemoon.org/viewtopic.php?f=1&t=28006) by Moonchild:

Quote
As you may have noticed there has been an unplanned outage of all palemoon.org sites and services.
Unfortunately this was caused by foul play at the hands of one of our own. I'll do a proper write-up of everything later, when I've gathered all the necessary data to make a coherent post explaining what happened.

The additional result of the referenced "foul play" is that the website hosting the Pale Moon Add-on's page with extensions, themes, language packs, plugins and more is not available, having been removed by the former member of the Pale Moon team.
Title: Outage post-mortem, and apologies
Post by: Corrine on March 21, 2022, 05:58:00 PM
Moonchild has provided information about the outage and extensions website in a long post at Outage post-mortem, and apologies (https://forum.palemoon.org/viewtopic.php?f=1&t=28044).
Title: Re: Pale Moon Version 30 Released with Security Updates and Return to Firefox's GUID
Post by: v_v on March 21, 2022, 10:23:47 PM
What a mess!  I remember that this Tobin fellow was also one of the major voices forcing the discontinuation of the XP-oriented MyPal browser (which was essentially a clone of PaleMoon tweaked to work on Windows XP).

I actually had held off updating until today.  Unfortunately I updated this morning before Moonchild posted all of the news.  Fortunately before updating I copied and relocated the MoonChild/PaleMoon folders from my users/appdata/roaming folders as a just in case.  This was because version 30 was supposed to make irreversible changes to the profile which is kept in the roaming folder.  So depending on how Moonchild decides to carry out the

Quote. . . rollback of the milestone and security update to 29.4 as I'm not confident this can be solved immediately on v30 in a satisfactory way

I may need to delete everything related to PaleMoon and reinstall using one of the earlier versions, and then reinstall the profile folder.

Oh well, just another day on the internet!

v_v

Title: Re: Pale Moon Version 30 Released with Security Updates and Return to Firefox's GUID
Post by: Corrine on March 22, 2022, 02:02:09 AM
At this point, version 30 has been removed from the Pale Moon download site.
Title: Re: Pale Moon Version 30 Released with Security Updates and Return to Firefox's GUID
Post by: plodr on March 22, 2022, 01:24:52 PM
I had a year old version of PM (29.1) on my desktop computer which I never used. I finally used Revo to uninstall it and I won't be reinstalling it.

Moonchild's idea to keep the old addon/extension system of FF was a good idea. Then he decided to use his own system. I decided then to go back to FF which has more choices for addons and extensions than PM ever had.

There is also a thread on the PM forum about the problem with saving passwords. Apparently it saves them but never fills them in so you have to type in each time. That's not the behavior I want from a browser.

I replaced PM with the Brave browser which is based on chrome. I decided rather than learning how to deal with the new PM, I'd figure out how to deal with Brave.