This is a goddamned disaster. I'm just thankful that I use an offline password manager, but even still ... I like FF, don't get me wrong, but this is going to absolutely fucking destroy user trust in Mozilla. This kind of incompetence, on a browser scale , is breathtaking.
All extensions disabled due to expiration of intermediate signing cert
91–100 of 955 posts
Re: All extensions disabled due to expiration of intermediate signing cert
#92Why do my personal extensions need to be hooked into some third party service that can go out at anytime?
Re: All extensions disabled due to expiration of intermediate signing cert
#93Earlier quoted context omitted.
ACME / Let's Encrypt go in the direction of making expiry happen so often that renewal gets automated, rather than a being a rare manual process that can be forgotten about. Not sure that's viable for a signing certificate like this, but that's the way to solve it for the web PKI.
This is just abusive to the vast majority of users who do not care but still want to use SSL for their servers, frankly. I should be allowed to choose a near unlimited lifetime for my server's certificate if I don't care about the risks that may present.
Re: All extensions disabled due to expiration of intermediate signing cert
#94First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.
What I'd like to see is a post-mortem, followed by an explanation of how they'll prevent the mistake from being made again in future.
Re: All extensions disabled due to expiration of intermediate signing cert
#95This is why users need to be in control of their own computers. Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? Mistakes happen, it's okay. But users should be empowered to work around them.
> Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? The issue is that if you leave any sort of lever that reduces security, it will be abused by bad actors. This is why browsers are having ever decreasing ways to bypass security and have full access. It is annoying, but at the end of the day, protecting 99.999% of the users trumps what us power users want.
If we're going to assume that software is right and the user is wrong 100% of the time, then the software needs to actually be right 100% of the time. Unfortunately, our software isn't that robust, and it never will be.
Re: All extensions disabled due to expiration of intermediate signing cert
#96My extensions are still running. I even restarted Firefox a few moments ago. So it’s not everyone?
Re: All extensions disabled due to expiration of intermediate signing cert
#97Does it only occur after a restart or?
Re: All extensions disabled due to expiration of intermediate signing cert
#98I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…
ACME / Let's Encrypt go in the direction of making expiry happen so often that renewal gets automated, rather than a being a rare manual process that can be forgotten about. Not sure that's viable for a signing certificate like this, but that's the way to solve it for the web PKI.
Re: All extensions disabled due to expiration of intermediate signing cert
#99Earlier quoted context omitted.
> Still, this type of oversight seems all too common even in large companies. (...) Has anyone developed a tool designed specifically to avoid certificate expiry disasters? LetsEncrypt renewal is supposed to be automated. [1] I know of a company that hosted blogs for thousands of customers. They used LetsEncrypt, but the CTO considered automatic renewals a possible security risk, so they did it manually. Problem is,…
So did they conclude it wasn’t a security concern or did they conclude the security risk was worth the uptime?
Re: All extensions disabled due to expiration of intermediate signing cert
#100First they force code signing on everyone without a way to disable it then they break it. This is an extreme level of incompetence I didn't expect from Mozilla. They'd better have the best post mortum ever, possibly with someone being fired.
This has probably happened to every major cloud provider and countless companies at least once. Certs are hard.
Should Mozilla have had monitoring on their cert expiration? Yes. Will they after this? Probably. Is any one person ever at fault for something like this? No.
Firefox is an open source project. You're welcome to contribute and make things better.