为提升您的使用体验,本站正在维护,部分功能暂时无法使用。如果本站文章无法解决您的问题,您想要向社区提问的话,请到 Twitter 上的 @FirefoxSupport 或 Reddit 上的 /r/firefox 提问,我们的支持社区将会很快回复您的疑问。

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

Do I need to change now from 56.0.2 (64-bit) to the latest update for security?

more options

I haven't upgraded to 57 because apparently some (many) things I utilize will no longer function (perhaps they've updated by now).

But with the security vulnerability, do I have the same vulnerability with my present version as I would if I was using 57?

So I need to finally update to the latest version? Or can I continue with 56?

Windows 10 Home.

I haven't upgraded to 57 because apparently some (many) things I utilize will no longer function (perhaps they've updated by now). But with the security vulnerability, do I have the same vulnerability with my present version as I would if I was using 57? So I need to finally update to the latest version? Or can I continue with 56? Windows 10 Home.

所有回复 (3)

more options

56 already has a number of vulnerabilities that have been fixed in 57+.

more options

If you leave a window unlocked, on average, you usually don't have a break-in, but your risk varies depending on your neighborhood.

Similarly, if you are using software with a known vulnerability, but you avoid sites with suspicious content and block everything unnecessary, you may not encounter a site exploiting that vulnerability.

But I suspect everyone's luck runs out at some point, and you never know when that will be.

Security -- physical or digital -- is not black and white, all or nothing. It's gradations of risk that require a little personal reflection.

How would we feel if our browser was taken over to steal all our computer data or lock it away from us? If we have good backups and/or we can afford to lose some stuff, and we don't have a lot of sensitive data to grab, we can take more risk than people who would be out of business or personally devastated by an attack.

Is some risk worth taking? You have to weigh the value of the extensions you can run on Firefox 56 that you can't run on Firefox 57. They may be very important to your use and enjoyment of the web.

So no one can tell you what to do, it's your call.

more options

Also, you can turn off one of the features (SharedArrayBuffer) that can be used for a timing attack:

(1) In a new tab, type or paste about:config in the address bar and press Enter/Return. Click the button promising to be careful or accepting the risk.

(2) In the search box above the list, type or paste shared and pause while the list is filtered

(3) If the javascript.options.shared_memory preference is true, double-click it to flip the value to false

There's no fix for the performance.now() issue for Firefox 56.