Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

61–70 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#61
post #45

First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.

Why does someone need to be fired? Does some blood spilled really make it better? Have some compassion.

I'm generally not a fan of firing people for making mistakes. This one is so monumental it may require it though. This breaks most FF installations.

Re: All extensions disabled due to expiration of intermediate signing cert

#62

First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.

I was with you up until you said someone should be fired.

The fundamental problem here is the system (code signing.) It's a political thing with security being the excuse. They want control of a platform for business reasons.

Re: All extensions disabled due to expiration of intermediate signing cert

#63

Earlier quoted context omitted.

> Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? The issue is that if you leave any sort of lever that reduces security, it will be abused by bad actors. This is why browsers are having ever decreasing ways to bypass security and have full access. It is annoying, but at the end of the day, protecting 99.999% of the users trumps what us power users want.

protecting 99.999% of the users It is horribly paternalistic to advocate for keeping users ignorant, unlearning, and --- dare I say it --- easily manipulated. I will refrain from mentioning again that infamous Franklin quote. I am frankly very fucking pissed off by this authoritarian walled-garden trend, and vehemently oppose anyone who helps this industry put the nooses around the necks of others as well as their ow…

I’ve been in software development and operations for 25 years.

I still don’t want to have to understand everything I ever touch, even if I could.

Re: All extensions disabled due to expiration of intermediate signing cert

#64

This is why users need to be in control of their own computers. Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? Mistakes happen, it's okay. But users should be empowered to work around them.

> Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? The issue is that if you leave any sort of lever that reduces security, it will be abused by bad actors. This is why browsers are having ever decreasing ways to bypass security and have full access. It is annoying, but at the end of the day, protecting 99.999% of the users trumps what us power users want.

[deleted]

Re: All extensions disabled due to expiration of intermediate signing cert

#65

First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.

Come on, people make mistakes. Things fall through cracks. Shit happens, etc.

No one needs to be fired for a single instance of a particular mistake. If this happened multiple times, then I would be on board with firing someone.

Re: All extensions disabled due to expiration of intermediate signing cert

#66
post #12

I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…

> Still, this type of oversight seems all too common even in large companies. (...) Has anyone developed a tool designed specifically to avoid certificate expiry disasters?

LetsEncrypt renewal is supposed to be automated. [1]

I know of a company that hosted blogs for thousands of customers. They used LetsEncrypt, but the CTO considered automatic renewals a possible security risk, so they did it manually. Problem is, the expiration happened in a weekend and they "forgot" to update the certificates before that. Suffice to say that the next Monday wasn't pleasant. They automated after that.

[1] https://letsencrypt.org/about/

Re: All extensions disabled due to expiration of intermediate signing cert

#67

Earlier quoted context omitted.

protecting 99.999% of the users It is horribly paternalistic to advocate for keeping users ignorant, unlearning, and --- dare I say it --- easily manipulated. I will refrain from mentioning again that infamous Franklin quote. I am frankly very fucking pissed off by this authoritarian walled-garden trend, and vehemently oppose anyone who helps this industry put the nooses around the necks of others as well as their ow…

I’ve been in software development and operations for 25 years. I still don’t want to have to understand everything I ever touch, even if I could.

I'm not understanding the relationship. Of course users aren't going to understand all the underpinnings of how software works.

I do think that in the future, it will be imperative for everyone to have some level of technological literacy above what is currently the average. And I'd like to work to get to that point, instead of taking all the tools away because they're too dangerous.

Also, sensible defaults are good! Hiding dangerous settings is also good! What's not okay is making those settings completely unavailable. At least in Firefox's case you have the option to recompile the source code, but that should not be the only recourse...

Re: All extensions disabled due to expiration of intermediate signing cert

#69
post #51

Is it perhaps a good time to remind folks that the same thing could happen to all your "secure" HTTPS websites that are completely unavailable via HTTP, where the only thing served over HTTP are the 301 Moved redirects, even for sites that don't collect any user information at all, and only serve static and public content, which really hardly benefit from the mandatory encryption? Or is HTTPS / LetsEncrypt too big to…

But it's easy to override broken https certificates. Worst case you have trust on first contact style security.

This is just plain bad.

Re: All extensions disabled due to expiration of intermediate signing cert

#70
post #45

Earlier quoted context omitted.

Why does someone need to be fired? Does some blood spilled really make it better? Have some compassion.

I'm generally not a fan of firing people for making mistakes. This one is so monumental it may require it though. This breaks most FF installations.

You didn't answer my question. What does firing achieve? You fire a person who learnt their lesson and will never make the mistake again? And then hire someone new?

Or you fire the scapegoat because of a broken system that allowed one person to make a mistake?

Post reply on HN