Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

291–300 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#291

Earlier quoted context omitted.

If it failed open, anyone unlucky enough to update their extensions could end up having a malicious version installed. It also would have taken longer to notice.

So why not just disable extension updates instead of disabling the extensions themselves?

Presumably because how would it differentiate between a legit "already installed" extension with a signature that cannot be verified, and an extension installed by malware that also cannot be verified?

Re: All extensions disabled due to expiration of intermediate signing cert

#292
post #12

I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…

> Still, this type of oversight seems all too common even in large companies.

The npm self-signed certificate fiasco of early 2014 springs immediately to mind.

Re: All extensions disabled due to expiration of intermediate signing cert

#294

Tomorrow (or whenever this gets fixed), ad companies are going to have some great data about what the world would look like if adblock didn't exist. I really home someome does a blog post about it. Yikes, I hope it doesn't play out like a shark smelling chum.

Firefox has anti-tracking features that are enough to freak out reCaptcha regardless of adblockers, so that might not be as good for them as it seems. Be careful not to confuse hiding ads from view with preventing user tracking.

Re: All extensions disabled due to expiration of intermediate signing cert

#296
Mozilla doesn't seem to have communicated the issue well. I could imagine a lot of unsavvy users have tried some wild things in an attempt to fix the problem, and maybe made a mess in the process. Doesn't Mozilla have a mechanism for blasting out a message to all Firefox browsers? Also I have a Firefox account, why haven't I been inboxed about this?

Otherwise I'm not bothered. I won't be switching as long as this gets resolved within the next few days.

Re: All extensions disabled due to expiration of intermediate signing cert

#297

This is a goddamned disaster. I'm just thankful that I use an offline password manager, but even still ... I like FF, don't get me wrong, but this is going to absolutely fucking destroy user trust in Mozilla. This kind of incompetence, on a browser scale , is breathtaking.

I dunno. I’m a typical Firefox user, and I’d rather jump off a bridge than switch to a different browser because of a fuckup like this. People make mistakes, but Mozilla still stands for things that certain other browser vendors don’t, last time I checked.

Sadly, what they "stand for" and what they actually do are two different things. This is exactly the kind of centralization that a company supporting a "free and open internet" (to use their words) should be against on principle, let alone pushing in their only product of note.

This should not be possible.

Worse, had they not taken the paternalistic, nanny-like stance that you can't even disable the signing checks, I could roll out a script that would make this a non-issue for my users. But no, thanks Mozilla for ruining my Monday.

Might not be the most substantive comment I could possibly make in the circumstances, but I'm pissed. The only appropriate response feels like a string of infuriated profanity directed at their incompetence and decision-making.

Re: All extensions disabled due to expiration of intermediate signing cert

#299

Earlier quoted context omitted.

So why not just disable extension updates instead of disabling the extensions themselves?

Presumably because how would it differentiate between a legit "already installed" extension with a signature that cannot be verified, and an extension installed by malware that also cannot be verified?

Personally I despise the idea of the software already on my pc being dependent on signatures stored on a remote server. I installed it and Mozilla can fuck right off. It's my responsibility to police what software is on my computer, not theirs.

Re: All extensions disabled due to expiration of intermediate signing cert

#300
post #163
post #12

I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…

> I’ll still keep using Firefox since I recognize the importance of browser diversity Also, Chrome is not immune to "crashes for everyone at the same time" bugs. Like that time when the start of daylight saving time made it crash for a full day (a quick search tells me it probably was https://bugs.chromium.org/p/chromium/issues/detail?id=287821 ).

That bug seems to have affected only users on Android versions earlier than 4.3 and in Brazil or Chile.
Post reply on HN