Release of Firefox 135

The release of the Firefox 135 web browser has taken place, and updates for previous long-term support branches — 115.20.0 and 128.7.0 — have been finalized. The Firefox 136 branch has entered the beta testing phase, with a release scheduled for March 4.

Key innovations in Firefox 135:

  • The built-in translator now supports translation into Russian (previously, translation from Russian to other languages was available, but not the other way around), as well as translation from Korean, Japanese, and simplified Chinese. The quality of translation has been improved, for example, situations where the AI model substituted invented words have been eliminated. The translation system built into Firefox performs translations on the user's local system without accessing external cloud services. The system is based on the open-source Bergamot engine, which is a wrapper over the Marian machine translation framework, employing recurrent neural networks (RNN) and transformer-based language models.
    Release of Firefox 135
  • A built-in AI chatbot is available for all users, utilizing large language models for natural language interaction. The chatbot is displayed in the sidebar and can operate through services such as Anthropic Claude, ChatGPT, Google Gemini, HuggingChat (Hugging Face), and Le Chat Mistral. Users can switch between services at their discretion. Registration is required for each supported service (a web application for each service opens in the panel). In addition to chat, a button labeled “Ask ...” has been added to the context menu, allowing users to pass selected text on the page to the chatbot, for example, to create a brief summary of the content or explain the essence in simple terms. To add custom language models running on the local system, users can utilize the llamafile toolkit.
    Release of Firefox 135
    Release of Firefox 135
  • For users from all countries where the Mozilla Stories recommendation service is available, a new layout is included for the page shown when opening a new tab. In the previous release, this new layout was only offered to users in the USA and Canada. The new version features a search bar and a list of recommended pages, as well as changes to the design of the section for frequently visited and pinned sites, which are now displayed in a single row instead of a grid. The number of columns with content is chosen based on the width of the window, allowing for effective use of all available screen space.
    Release of Firefox 135
  • All users have been given the support for automatic remembering and filling of credit card numbers in web forms. The CVV code is not remembered, and card numbers are stored in a secure vault, for which a separate password can be set for access.
  • Mandatory verification has been enabled for TLS certificates Web servers in public Certificate Transparency logs are intended to identify certificates created outside the standard workflows of a certificate authority (e.g., hidden certificate creation due to employee abuse or compromise of the certificate authority). The certificate authority sends information about all new certificates to several independent Certificate Transparency logs, which allow for the auditing of all changes. If a certificate that is not reflected in the log is used when accessing a website, that certificate will be marked as unsafe by the browser.

    Logs accompany various unrelated organizations. To protect against data tampering retroactively in data storage, a tree structure called 'Merkle Tree' is used, where each branch verifies all underlying branches and nodes through tree hashing. Having a final hash allows the user to verify the correctness of the entire history of operations and the accuracy of past states of the database.

  • To accelerate the verification of TLS certificate reviews, a CRLite mechanism is employed, operating on the user's system. A user-side database containing certificate information is periodically synchronized with the external Mozilla database. To reduce the database size, cascading Bloom filters are used — a probabilistic structure that allows for false identification of a missing element, but excludes the possibility of missing an existing one. For example, data on 100 million certificates is packed into a structure approximately 1 MB in size.

    Compared to querying a certification authority using the OCSP (Online Certificate Status Protocol), employing CRLite not only eliminates delays from sending network requests but also enhances privacy (when using OCSP, the browser sends a request with every visit to a site, effectively transmitting to the certification authority data about which sites are being accessed) and removes dependence on the availability of OCSP servers (an attacker can launch a DDoS attack on an OCSP server to block processing of requests).

  • Protection against manipulations that hinder navigation using the "back" and "forward" buttons has been added, due to cluttering of browsing history with fake records created via the History API. The essence of the protection is to ignore records unrelated to user actions when processing presses on the "back" and "forward" buttons.
  • The builds for Linux and macOS have added the option to close only the current tab, rather than all tabs, after pressing the keyboard combination to exit the application (Alt + F4).
  • The option to send websites the HTTP header "Do Not Track" ("DNT") has been removed from the privacy settings page (about:preferences#privacy). The DNT header informs websites of the user's desire not to share information that could be used for tracking movements and preferences. The DNT header is optional and is ignored by many websites. Instead of DNT, it is recommended to use the Global Privacy Control (GPC) mechanism, which informs websites about the prohibition of selling personal data and using data for tracking user behavior or movements. Unlike DNT, adherence to GPC requirements is mandatory under the current California Consumer Privacy Act (CCPA).
  • The context menu operation "Copy Without Site Tracking" has been renamed to "Copy Clean Link" and expanded to support bare URLs in text (without hyperlinks). This operation allows you to copy the URL of the selected link to the clipboard, cutting out the parameters used for tracking transitions between websites.
  • The address bar has implemented the ability to search for tab group names and navigate to the found groups. The search encompasses closed and saved groups among others.
  • To compress Firefox builds for the Linux platform, the XZ format has been utilized, which has reduced the size of the data downloaded by an average of 25% compared to the bz2 format and has cut unpacking time by more than half.
  • Support for the hybrid key exchange algorithm "mlkem768x25519" has been added for HTTP/3, which is resistant to brute-force attacks on quantum computers and combines X25519 ECDH with the ML-KEM (CRYSTALS-Kyber) algorithm, standardized last year by the U.S. National Institute of Standards and Technology (NIST). ML-KEM uses cryptographic methods based on solving lattice theory problems, taking the same time to solve on both classical and quantum computers.
  • In the attributes of the PointerEvent interface, which define pointer coordinates, the transmission of non-integer values has been implemented. This change allows for handling events with greater accuracy in situations where the target element has been transformed via CSS or when the visible area (viewport) has been zoomed.
  • The behavior of the mouseenter, mouseleave, pointerenter, and pointerleave events has been changed to comply with the specification.
  • The API WebAuthn has added the method getClientCapabilities().
  • The web development tools now provide a warning when using the 'content-visibility' property with elements that do not have size constraints.
  • A new command '$$$' has been added to the web console to search across pages considering the content of the shadow DOM.
  • Debugging capabilities for WebExtension add-ons have been expanded: breakpoints are now functional in content scripts, and Workers are displayed when selecting a context in the Console panel.
  • The Android version now includes an option that enables automatic submission of crash reports to Mozilla without user confirmation.

In addition to new features and bug fixes, Firefox 135 has addressed 19 vulnerabilities. Thirteen of these vulnerabilities, marked as critical, stem from memory management issues such as buffer overflows and accessing already freed memory areas. These issues may potentially allow for the execution of malicious code when opening specially crafted pages.

In the beta version of Firefox 136 for Linux builds, hardware acceleration for video decoding on AMD GPU systems has been implemented. The HTTPS-First mode is enabled by default, which replaces requests to 'http://' with 'https://', both when following a link and when loading sub-resources like images, scripts, and stylesheets. Support for sending and receiving video in AV1 format via WebRTC has also been added.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster