Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

541–550 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#541

Update: We have rolled out a partial fix for this issue. We generated a new intermediate certificate with the same name/key but an updated validity window and pushed it out to users via Normandy (this should be most users). Users who have Normandy on should see their add-ons start working over the next few hours. We are continuing to work on packaging up the new certificate for users who have Normandy disabled.

pushed it out to users via Normandy (this should be most users)

Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? What about a UI knob to disable it?

Re: All extensions disabled due to expiration of intermediate signing cert

#542
post #55

DAMN! That's quite something! For a piece of open source software you really have very little control with firefox. It really sucks that the alternatives are worse. This, likely for almost all of their users, creates more of a security problem than signature checking actually solves. For me noscript no longer works which is (IMO) a critically important extension (between mozilla taking away the disable javascript but…

OTOH, it's opensource, and you can re-compile it in like 20-30 minutes with whatever changes you desire. So you have the control. You can probably even add some hacked up support for multiple signing certificates (and add yours there), if you tried.

It's just that it's more work than having what you want implmeneted and maintained by others.

Re: All extensions disabled due to expiration of intermediate signing cert

#544

Update: We have rolled out a partial fix for this issue. We generated a new intermediate certificate with the same name/key but an updated validity window and pushed it out to users via Normandy (this should be most users). Users who have Normandy on should see their add-ons start working over the next few hours. We are continuing to work on packaging up the new certificate for users who have Normandy disabled.

pushed it out to users via Normandy (this should be most users) Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? What about a UI knob to disable it?

Agree with this concern.

Re: All extensions disabled due to expiration of intermediate signing cert

#545

Update: We have rolled out a partial fix for this issue. We generated a new intermediate certificate with the same name/key but an updated validity window and pushed it out to users via Normandy (this should be most users). Users who have Normandy on should see their add-ons start working over the next few hours. We are continuing to work on packaging up the new certificate for users who have Normandy disabled.

pushed it out to users via Normandy (this should be most users) Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? What about a UI knob to disable it?

> Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users?

It will even be documented for them: https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout

> What about a UI knob to disable it?

app.normandy.enabled

Re: All extensions disabled due to expiration of intermediate signing cert

#546
post #484
post #259

Earlier quoted context omitted.

Assuming you mean that half second looking at the ad: Name a better alternative for funding the internet. Paywalls at every website?

An open, transparent, convenient, anonymous protocol for micro payments, with good cost contol build into browsers.

It is coming :) https://lightningjoule.com/

Re: All extensions disabled due to expiration of intermediate signing cert

#547
post #524

Earlier quoted context omitted.

https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout

So is that a backdoor into my prefs? How can I check if Normandy is active on my installation?

Something with a public wiki page describing what it does exactly is hardly a backdoor.

Also here's the code for the server: https://github.com/mozilla/normandy

Re: All extensions disabled due to expiration of intermediate signing cert

#548

Update: We have rolled out a partial fix for this issue. We generated a new intermediate certificate with the same name/key but an updated validity window and pushed it out to users via Normandy (this should be most users). Users who have Normandy on should see their add-ons start working over the next few hours. We are continuing to work on packaging up the new certificate for users who have Normandy disabled.

I read at https://discourse.mozilla.org/t/certificate-issue-causing-ad...

>12:50 p.m. UTC / 03:50 a.m. PDT: We rolled-out a fix for release, beta and nightly users. The fix will be automatically applied in the background within the next few hours, you don’t need to take active steps.

>In order to be able to provide this fix on short notice, we are using the Studies system. You can check if you have studies enabled by going to Firefox Preferences -> Privacy & Security -> Allow Firefox to install and run studies.

>You can disable studies again after your add-ons have been re-enabled.

>We are working on a general fix that doesn’t need to rely on this and will keep you updated.

I refuse to enable studies, even temporarily. This comes very close after the IE6 conspiracy revelation, where ends justifies the means.

Please provide a link to the certificate file, and step by step instructions for installing it, without enabling and conflating with mozilla studies...

Re: All extensions disabled due to expiration of intermediate signing cert

#549

Update: We have rolled out a partial fix for this issue. We generated a new intermediate certificate with the same name/key but an updated validity window and pushed it out to users via Normandy (this should be most users). Users who have Normandy on should see their add-ons start working over the next few hours. We are continuing to work on packaging up the new certificate for users who have Normandy disabled.

pushed it out to users via Normandy (this should be most users) Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? What about a UI knob to disable it?

This is the first I hear about Normandy[1]. Firefox has been my main browser for a long time, only because I could use uBlock origin. Now, all of a sudden that is disabled, and with the recent version they got rid of my ability to always prevent autoplaying of videos.

Apparently, there is no one associated with browsers can be trusted in the least.

[1]: https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout

Re: All extensions disabled due to expiration of intermediate signing cert

#550

They have acknowledged the defect and are working on a fix. While this is a severe impact, I am still with Firefox. The are enough alternative browsers to tide over the problem for now. The fact that alternatives exist is the reason why we should support projects like Firefox.

Just curious, should we expect that the fix (issuing a new signing cert and re-signing all the addons and whatnot) will result in the addons being automatically updated and re-enabled? They certainly seem to have streamlined disabling the addons, I wonder if it is equally simple from a users perspective to bring them back. Also now wondering just how hard their network/CDN is going to get slammed when those new re-si…

It looks like they have a hotfix to automatically re-enable the addons: https://twitter.com/mozamo/status/1124627930301255680
Post reply on HN