Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

211–220 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#211
post #79

Earlier quoted context omitted.

I use firefox and am probably affected by this but don't even really notice atm. This doesn't even register on my user trust spectrum when the only other option is the browser that defines surveillance capitalism. I think we'll all live. No need for the chicken little act.

I'm not sure the GP is overstating things. For technical folks with technical reasons to be using Firefox: yeah, a mass exodus is unlikely purely because there aren't any good alternatives. What are you going to jump to? Chrome, and knuckle under to the Goog? Unbranded FF forks and be weeks behind on patches? Doubtful. My concern is around non-technical users (the group, mind you, that Firefox has been spending marke…

platitudes about surveillance and muh freedoms don't count for shit when your grandma just wants to get rid of the ads on the local newspaper site

Very much this. People are often too quick to forget who their customers are and what they really want.

Re: All extensions disabled due to expiration of intermediate signing cert

#212
post #2

Looks like all extensions have been disabled for all Firefox users. I think this fail-closed behavior is more of a security issue than the one it is trying to solve. All of my security add-ons - Privacy Badger, NoScript, Decentraleyes, and many more were disabled. Even worse, it happened without notice to the user. One moment I was browsing the internet (just barely) secured by these add-ons, and the next moment, all…

It wasn't quite all for me, it left 3 of the 20ish I have installed.

Re: All extensions disabled due to expiration of intermediate signing cert

#213

As a temporary fix, go to about:debugging, and click "load temporary addon", then paste in the download link of the missing add-on. Then just try and not restart Firefox until they fix the broken cert.

That's most likely the easiest way to temporarily fix the issue until it is resolved.

Re: All extensions disabled due to expiration of intermediate signing cert

#214

They have acknowledged the defect and are working on a fix. While this is a severe impact, I am still with Firefox. The are enough alternative browsers to tide over the problem for now. The fact that alternatives exist is the reason why we should support projects like Firefox.

Just curious, should we expect that the fix (issuing a new signing cert and re-signing all the addons and whatnot) will result in the addons being automatically updated and re-enabled? They certainly seem to have streamlined disabling the addons, I wonder if it is equally simple from a users perspective to bring them back. Also now wondering just how hard their network/CDN is going to get slammed when those new re-signed addons go live and every user automatically redownloads them.

Re: All extensions disabled due to expiration of intermediate signing cert

#215

Earlier quoted context omitted.

> Why can't I tell my copy of Firefox to ignore the certificate? Why can't I sign my own extensions? The issue is that if you leave any sort of lever that reduces security, it will be abused by bad actors. This is why browsers are having ever decreasing ways to bypass security and have full access. It is annoying, but at the end of the day, protecting 99.999% of the users trumps what us power users want.

Consider the recent news stories about the Boeing 737 Max. Boeing added an automatic system to an airplane, and then didn't give users (the pilots) a way to disable that system. This worked out great while the automatic system is working properly. When the system broke, well, we all know what happened. If we're going to assume that software is right and the user is wrong 100% of the time, then the software needs to a…

It doesn't have to actually be right 100% of the time. The balance of downsides and upsides of any chosen solution just have to be more palatable than those of whatever alternate implementation you're considering, with a tradeoff between 100% correctness and ability to be implemented before the heat death of the universe being one of the axes to be considered, as well as the level of benefit provided over your whole user base.

In this case, dropping the extra control/ignoring power users is probably saving a lot of non-power users from shooting themselves in the foot in the vast majority of cases. Pilots (should be) 100% power users. The average operator of a browser is somewhere on the opposite end of the spectrum.

Any real system will have things go horribly wrong for some subset of users on a regular basis. It's impossible to be all things for all people for all situations, so you have to choose your battles.

Re: All extensions disabled due to expiration of intermediate signing cert

#216

So why is this taking so long to fix? From https://github.com/mozilla/addons/issues/978 > diox commented 2 hours ago > I'm locking this like I did in #851 because no new information is being added. We're aware and we're working on it. I mean, two hours? WTF.

I am going to guess its more than just getting the new cert. They need to get the new cert, they need to resign all addons and then they some how need a way to force everyones browser to re-enable them. This could go on for quite some time if they have no plan in place to handle this sort of thing.

And if they were good at planning, this would not have happened in the first place. At least give us a button or something for "I don't give a shit if it isn't signed, enable it"

Re: All extensions disabled due to expiration of intermediate signing cert

#217

They have acknowledged the defect and are working on a fix. While this is a severe impact, I am still with Firefox. The are enough alternative browsers to tide over the problem for now. The fact that alternatives exist is the reason why we should support projects like Firefox.

>I am still with Firefox

that's kinda the problem. there's plenty of reasons to be "with" firefox still, but you shouldn't need reasons other than it's the best browser. when it starts requiring loyalty to be a user, that's a big problem.

Re: All extensions disabled due to expiration of intermediate signing cert

#218

This is a goddamned disaster. I'm just thankful that I use an offline password manager, but even still ... I like FF, don't get me wrong, but this is going to absolutely fucking destroy user trust in Mozilla. This kind of incompetence, on a browser scale , is breathtaking.

I dunno. I’m a typical Firefox user, and I’d rather jump off a bridge than switch to a different browser because of a fuckup like this. People make mistakes, but Mozilla still stands for things that certain other browser vendors don’t, last time I checked.

That's my thinking too. I went back to Firefox a few months ago and it is back to being a fantastic browser now, and it feels good to use something that is also a force for good. I'm hoping they resolve this quickly and that it all turns out ok.

Re: All extensions disabled due to expiration of intermediate signing cert

#219
post #195

Earlier quoted context omitted.

Some shared hosting like Bluehost now provide LetsEncrypt by default for all their sites with auto-renewal (But I don't recommend Bluehost shared plans for anything even closer to serious hobby due to absurd downtimes like most other shared hosting). I used manual renewal for LetsEncrypt for about 4 websites on other shared hosts & renewing them every 3 months was a pain; had to keep reminders and schedules just not…

Another option is using a Web Server/Reverse Proxy that supports Let's Encrypt automatically, like Caddy [1]. I believe Apache HTTPD has partial support [2], too. [1] https://caddyserver.com [2] https://httpd.apache.org/docs/2.4/mod/mod_md.html

Nginx works well and there's a tool that automates most of the extra config stuff for you.

Re: All extensions disabled due to expiration of intermediate signing cert

#220

Earlier quoted context omitted.

That's a great question. I've never seen a bulletproof solution for organizational tasks that need to be done yearly. If someone's in charge... and both they and their manager happen to leave in the same year... and whatever system they had in place to remember (probably their personal calendars) is gone... and the manager's manager has 1,000 other things to remember... ...how does an organization ensure the task sti…

"...how does an organization ensure the task still gets done?" With something almost stupidly simple and low-tech: checklists. (I'm reading "The Checklist Manifesto" right now, and the points it makes seem to fit perfectly with everything you mention.)

An year is enough time for everybody that knows about the checklist to leave.
Post reply on HN