Taboo: Safari multi-tab close confirmation dialog

From the macosxhints Pick Of The Week department: Taboo – Prevent tab closing stupidity in Safari. “The macosxhints Rating:[Score: 10 out of 10], Developer: Obsessive Compulsive Development, Price: Free

“A simple PotW this week, as it really only does one thing. Taboo is a plug-in for Safari that warns you if you hit the red…” more.

I cannot tell you how many times I have screamed “No!” as I mean to close a tab or another document and inadvertently closed a dozen precious tabs in Safari. This is a must-have!

Yet another IE exploit…

Slashdot posting: Several Critical MSIE Flaws Uncovered. An anonymous reader writes “Several flaws have been uncovered by security firm eEye in Microsoft’s Internet Explorer. The flaws allow remote compromise of computers running Windows Operating Systems and affect IE, Outlook and possibly other MS software. With the next MS Windows security bulletin release scheduled for June 14, 2005 news sources are reporting that in comparison with the Mozilla Foundation’s prompt fix for the recently reported Mozilla 1.0.3 vulnerabilities MS appear to be leaving a large window for the possible malicious exploitation of these flaws.”

Of course, if Microsoft can come up with a patch, successfully test it against the many configurations it supports, and feels the threat of the exploit actually appear in the wild, I would expect them to release it. With Mozilla having delivered several quick turn-arounds on security patches, Microsoft has their work cut out for it: a quick response is required, but an admission of insecurity, and a huge liability if it fails (imagine a patch the brings down a large number of machines). If the release is not quickly forthcoming, Microsoft has an opportunity to downplay the threat, especially if it is more theoretical than something actually found in the wild. Playing the numbers game, if the release can beat out the exploit, Microsoft gets to claim they are taking care of their customers their best One Microsoft Way. But… if the exploit hits the street… if the exploit is nasty enough… another mess like Melissa or SQL Slammer will cost their customers millions of dollars of clean-up. Their customers have spent these millions before, and they will likely spend them again. But Microsoft plays a very dangerous game in dealing with security as a PR management process rather than a security issue to be dealt with out delay. Looking forward to learning more details on this problem, and watching Microsoft’s response.

Firefox updated to 1.0.4

A Slashdot post notes Firefox Updated to 1.0.4. Exstatica writes “Firefox has been updated to 1.0.4 and they have fixed a few critical security holes, all javascript vulnerabilities. The Mozilla Foundation announced these vulnerabilities May 7th. ‘There are currently no known active exploits of these vulnerabilities although a proof of concept has been reported.” You don’t have to upgrade, but it’s recommended.’” We’ve reported on these vulnerabilities previously.”

Roof! Roof!

Getting a new roof this week, and a new chimney. Our wound-up little dogs are not pleased. Needless to say, neither are Laura nor I. It’s pandemonium this week. Hope to blog more once I’ve regained my sanity.