First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.
Why does someone need to be fired? Does some blood spilled really make it better? Have some compassion.
All extensions disabled due to expiration of intermediate signing cert
61–70 of 955 posts
Re: All extensions disabled due to expiration of intermediate signing cert
#62First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.
The fundamental problem here is the system (code signing.) It's a political thing with security being the excuse. They want control of a platform for business reasons.
Re: All extensions disabled due to expiration of intermediate signing cert
#63Earlier quoted context omitted.
> Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? The issue is that if you leave any sort of lever that reduces security, it will be abused by bad actors. This is why browsers are having ever decreasing ways to bypass security and have full access. It is annoying, but at the end of the day, protecting 99.999% of the users trumps what us power users want.
protecting 99.999% of the users It is horribly paternalistic to advocate for keeping users ignorant, unlearning, and --- dare I say it --- easily manipulated. I will refrain from mentioning again that infamous Franklin quote. I am frankly very fucking pissed off by this authoritarian walled-garden trend, and vehemently oppose anyone who helps this industry put the nooses around the necks of others as well as their ow…
I still don’t want to have to understand everything I ever touch, even if I could.
Re: All extensions disabled due to expiration of intermediate signing cert
#64This is why users need to be in control of their own computers. Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? Mistakes happen, it's okay. But users should be empowered to work around them.
> Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? The issue is that if you leave any sort of lever that reduces security, it will be abused by bad actors. This is why browsers are having ever decreasing ways to bypass security and have full access. It is annoying, but at the end of the day, protecting 99.999% of the users trumps what us power users want.
Re: All extensions disabled due to expiration of intermediate signing cert
#65First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.
No one needs to be fired for a single instance of a particular mistake. If this happened multiple times, then I would be on board with firing someone.
Re: All extensions disabled due to expiration of intermediate signing cert
#66I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…
LetsEncrypt renewal is supposed to be automated. [1]
I know of a company that hosted blogs for thousands of customers. They used LetsEncrypt, but the CTO considered automatic renewals a possible security risk, so they did it manually. Problem is, the expiration happened in a weekend and they "forgot" to update the certificates before that. Suffice to say that the next Monday wasn't pleasant. They automated after that.
Re: All extensions disabled due to expiration of intermediate signing cert
#67Earlier quoted context omitted.
protecting 99.999% of the users It is horribly paternalistic to advocate for keeping users ignorant, unlearning, and --- dare I say it --- easily manipulated. I will refrain from mentioning again that infamous Franklin quote. I am frankly very fucking pissed off by this authoritarian walled-garden trend, and vehemently oppose anyone who helps this industry put the nooses around the necks of others as well as their ow…
I’ve been in software development and operations for 25 years. I still don’t want to have to understand everything I ever touch, even if I could.
I do think that in the future, it will be imperative for everyone to have some level of technological literacy above what is currently the average. And I'd like to work to get to that point, instead of taking all the tools away because they're too dangerous.
Also, sensible defaults are good! Hiding dangerous settings is also good! What's not okay is making those settings completely unavailable. At least in Firefox's case you have the option to recompile the source code, but that should not be the only recourse...
Re: All extensions disabled due to expiration of intermediate signing cert
#68Re: All extensions disabled due to expiration of intermediate signing cert
#69Is it perhaps a good time to remind folks that the same thing could happen to all your "secure" HTTPS websites that are completely unavailable via HTTP, where the only thing served over HTTP are the 301 Moved redirects, even for sites that don't collect any user information at all, and only serve static and public content, which really hardly benefit from the mandatory encryption? Or is HTTPS / LetsEncrypt too big to…
This is just plain bad.
Re: All extensions disabled due to expiration of intermediate signing cert
#70Earlier quoted context omitted.
Why does someone need to be fired? Does some blood spilled really make it better? Have some compassion.
I'm generally not a fan of firing people for making mistakes. This one is so monumental it may require it though. This breaks most FF installations.
Or you fire the scapegoat because of a broken system that allowed one person to make a mistake?