Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

571–580 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#571
post #563
post #557

Earlier quoted context omitted.

The UI knob is Options -> Privacy & Security > Allow Firefox to install and run studies They're using the studies system to push this hotfix faster for those that have it enabled. Edit: Source: See: https://discourse.mozilla.org/t/certificate-issue-causing-ad... > In order to be able to provide this fix on short notice, we are using the Studies system. You can check if you have studies enabled by going to Firefox Pre…

> The UI knob is > Options -> Privacy & Security > Allow Firefox to install and run studies That is not true. I've had that disabled forever Despite that, when I went into about:config, app.normandy.enabled was set to true, and app.normandy.user_id was defined. So, overnight Firefox decides it won't let me use uBlock Origin any more and now I find out all my browsing history has been logged to Firefox servers. All of…

I'm nearly certain Normandy does not log all of your browsing history for what it's worth.

I agree Mozilla approach to stuff like this is... less than ideal.

Re: All extensions disabled due to expiration of intermediate signing cert

#572
post #66
post #12

I’ll still keep using Firefox since I recognize the importance of browser diversity and the hazards of a Chrome monoculture (that and vertical tabs), but, yikes. Still, this type of oversight seems all too common even in large companies. I remember several cases from Fortune 500 companies in the past few years alone. What would be a good way to automate checking for them? Has anyone developed a tool designed specific…

> Still, this type of oversight seems all too common even in large companies. (...) Has anyone developed a tool designed specifically to avoid certificate expiry disasters? LetsEncrypt renewal is supposed to be automated. [1] I know of a company that hosted blogs for thousands of customers. They used LetsEncrypt, but the CTO considered automatic renewals a possible security risk, so they did it manually. Problem is,…

We update automatically AND manually check periodically to make sure the update took place. That company must be overly fond of drama...

Re: All extensions disabled due to expiration of intermediate signing cert

#573

It's pathetic to see the attitude demonstrated by Mozilla support on this. diox commented 4 hours ago I'm locking this like I did in #851 because no new information is being added. We're aware and we're working on it. This conversation has been locked as spam and limited to collaborators. [1] Bug 1548973 (armagadd-on-2.0) All extensions disabled due to expiration of intermediate signing cert NEW Unassigned (Needinfo…

You know that for every comment someone posts the developers get an email? It’s not useful if you get 500 emails that state a user is deeply inconvenienced by this bug. That only leads to people filtering mail into the trash.

Re: All extensions disabled due to expiration of intermediate signing cert

#575

Earlier quoted context omitted.

That doesn't sound right. What about all the other websites with ads, like recipe sites, guitar chords, porn, diy, etc.? or apps on the Google play store with ads?

I run sites that don't have ads. I don't make any money off of them. I still run them. Seems like a lot of people in software development think similarly.

This is the web that I like. Hobbyists and volunteers running low-fi websites for common interests. I'm not against commercial sites like Netflix but don't think every last blog should be monetised.

Re: All extensions disabled due to expiration of intermediate signing cert

#576

Earlier quoted context omitted.

pushed it out to users via Normandy (this should be most users) Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? What about a UI knob to disable it?

> Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? It will even be documented for them: https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout > What about a UI knob to disable it? app.normandy.enabled

From the wiki entry.

> Normandy Pref Rollout is a feature that allows Mozilla to change the default value of a preference for a targeted set of users, without deploying an update to Firefox.

Rolling out a new certificate goes beyond changing the default value of a preference which rightly raises questions about what else Normandy allows which is not documented.

Re: All extensions disabled due to expiration of intermediate signing cert

#577

Earlier quoted context omitted.

Type about:config in the address bar and search for 'app.normandy.enabled' flag.

Well that's interesting. I see Normandy enabled, but if I go to the "Privacy and Security" section of the preferences page I see all the data collection and use stuff disabled. There's no obvious way to disable the Normandy back door. Oh well, at least we don't have another season of Mr Robot spam to look forward to.

> There's no obvious way to disable the Normandy back door.

???

It's a publicly documented feature with a publicly documented way to disable it.

Re: All extensions disabled due to expiration of intermediate signing cert

#578
post #225

Just discovered the same message in the Tor browser, and it seems that NoScript got disabled. So people running Tor are a lot more vulnerable right now. Also, wow, the web has a ton of ads. I've been running uBlock origin so long I forgot how bad it had gotten :(

> Also, wow, the web has a ton of ads. I've been running uBlock origin so long I forgot how bad it had gotten :( Try turning it off. I got rid of ublock after arstechnica complained about a lot of their users blocking ads years ago and it honestly isn't that bad. Every once in a while I do back out of a page for maxing out one of my cpu cores but otherwise, nothing ever bad happens. With ads: either it takes me half…

The alternative is those websites not using third party ads with third party trackers on it. Adblockers already do not block those (cause they're indistinguishable from image links). If they really just want my eyeballs they know how they can get them.

But they really want to track me. And I'm not having that. The moment they stop tracking their users through third party ad networks, most adblockers stop blocking (because there's no AI involved and they wouldn't know what to block except images in general).

It's in their hands, really. If they want to show me ads they can do it in a normal and decent manner.

News websites should in fact be the first to adapt this model, because it's exactly the same thing as ads in print media. But they chose to get those disgusting third party tracking networks involved. And not just one or two.

I don't have to put up with that, but I really don't see why there would be an action required on my site to stop blocking those tracking ads.

Re: All extensions disabled due to expiration of intermediate signing cert

#579

Earlier quoted context omitted.

Well that's interesting. I see Normandy enabled, but if I go to the "Privacy and Security" section of the preferences page I see all the data collection and use stuff disabled. There's no obvious way to disable the Normandy back door. Oh well, at least we don't have another season of Mr Robot spam to look forward to.

> There's no obvious way to disable the Normandy back door. ??? It's a publicly documented feature with a publicly documented way to disable it.

With an obscure name and no correlation to all the other spying and backdoor ING Mozilla are doing. Is this really the best option tog etaprivacy focused browser? I think this is all very worrying.

Re: All extensions disabled due to expiration of intermediate signing cert

#580
post #259
post #251

Earlier quoted context omitted.

>nothing ever bad happens. With ads: either it takes me half a second to tell I'm not interested in an ad, or I actually am interested and i follow the ad because I am interested and I want to support the website. You just described something bad.

Assuming you mean that half second looking at the ad: Name a better alternative for funding the internet. Paywalls at every website?

You really seem to care a lot about this, let me guess, you work in adtech?
Post reply on HN