Earlier quoted context omitted.
I've deleted my extensions thinking it was the extensions' issue. I'm trying to download again but it's telling me I don't have internet connection. Any work-arounds?
https://www.reddit.com/r/firefox/comments/bkcjoa/all_of_my_a...
All extensions disabled due to expiration of intermediate signing cert
641–650 of 955 posts
Re: All extensions disabled due to expiration of intermediate signing cert
#642Earlier quoted context omitted.
No, it's not. This Normandy nonsense and stories are two separate, yet creepy features. I've already disabled stories but it looks like Mozilla still retains control of my preferences (without disclosing it).
I sure wonder how people so suspicious of Mozilla dare use their browser .
I guess "easier" isn't the word really, because Chrome can't really ever be locked down. It's pretty much always, effectively, an open book to Google.
You can lock down everything in Firefox. The drawback being, of course, times like this, when you can't get the fix unless you leave Normandy enabled. (Which I didn't.)
>:-(
Grrrr.
Re: All extensions disabled due to expiration of intermediate signing cert
#643Earlier quoted context omitted.
Most popular ACME (Let's Encrypt) clients allow you to provide a CSR instead of generating the keys themselves. That means a bunch more work for you, but if you're worried about this, that's what you should do. Have your safe (even manual if you insist) process make keys, make CSRs for the keys, and put those somewhere readable. The ACME client will hand them over to the CA saying "I want certs corresponding to these…
That does mean you aren't automatically rotating keys anymore.
If you don't trust it your automation, you rotate the keys manually, as you would normally.
There are no valid reasons to throw the baby away with the bathwater.
Re: All extensions disabled due to expiration of intermediate signing cert
#644To re-enable all disabled non-system addons you can do the following. I am not responsible if this fucks up your install: Open the browser console by hitting ctrl-shift-j Copy and paste the following code, hit enter. Until mozilla fixes the problem you will need to redo this once every 24 hours: // Re-enable *all* extensions async function set_addons_as_signed() { Components.utils.import("resource://gre/modules/addon…
Re: All extensions disabled due to expiration of intermediate signing cert
#645Earlier quoted context omitted.
Firefox stopped respecting the signature-required setting in the mainline version in 2016. I know because I got burned by it and made a Hitler parody. https://youtube.com/watch?v=taGARf8K5J8 And frankly, this an extra absurdity on top of that. If you’re going to require signatures for all extensions, regardless of user preference, shouldn’t you be keeping an eye on the signing process?
Why does Mozilla do this? Same with removing the option to not update. Why not let users choose (in the case of update maybe with an about config setting)?
They put it in nicer words though.
To their credit, you can opt out but only if you switch to dev edition, nightly or custom builds, which either is a one-way road since downgrades corrupt profiles or tedious because you don't receive auto-updates.
But what they should really have done is allowing additional signing roots. Even secure boot does that.
Re: All extensions disabled due to expiration of intermediate signing cert
#646Hello Chromium again...
Re: All extensions disabled due to expiration of intermediate signing cert
#647Earlier quoted context omitted.
Why is it supposed to be reassuring that their “studies” can override the cryptographic infrastructure? Edit: rephrase for clarity
Thank you. I happen to be one of the users with Normandy disabled, so I'm foobar'd anyway. That said, the reason I disabled it is because it is a security hole you could drive a semi-truck through. And now they want us to enable it to provide a "fix" for the secure way in? I thought I was the only one who saw a problem with that. Your post is evidence that I'm not completely off in my thinking.
Re: All extensions disabled due to expiration of intermediate signing cert
#648Earlier quoted context omitted.
Why does Mozilla do this? Same with removing the option to not update. Why not let users choose (in the case of update maybe with an about config setting)?
Because (stable) users are dumb, are easily manipulated and can't be trusted. Thus the mothership has to be in control for the greater good. They also argue that enduser computers are already effectively "compromised" from a mozilla perspective because adware runs installers with admin privs and thus could insert things into the program folders. Thus anything the user can do adware could do too and therefore they can…
[1] or at least they could have allowed that as a compromise
Re: All extensions disabled due to expiration of intermediate signing cert
#649Just discovered the same message in the Tor browser, and it seems that NoScript got disabled. So people running Tor are a lot more vulnerable right now. Also, wow, the web has a ton of ads. I've been running uBlock origin so long I forgot how bad it had gotten :(
The more people who use adblocker, the more ads websites need to make the same amount of money. It's been brought up that many twitch streamers don't receive ad revenue from more than half their viewers. I can only find a source right now for YouTube, but they're out there for twitch too. [1] https://www.vg247.com/2015/10/30/around-40-of-pewdiepies-aud...
No one can stop actual ads - this comment was brought to you by Pepsi, Pepsi for the love of it. See? Everyone had to read the last sentence even if they had adblock on.
Re: All extensions disabled due to expiration of intermediate signing cert
#650Earlier quoted context omitted.
I've been through all of Firefox `about:config` a few times in the past, fixing preferences to, e.g., try to disable umpteen different services that leak info or create potential vulnerabilities gratuitously, but this is the first I recall hearing of Normandy. Apparently I missed `app.normandy.enabled`, because I think I would've remembered a name with connotations of a bloody massive surprise attack. Incidentally, `…
I too use Debian's Firefox ESR. I noticed the "Allow Firefox to install and run studies" option in Privacy & Security Preferences a long time ago. It was unchecked and greyed out (i.e., unclickable), and a label below it says "Data reporting is disabled for this build configuration", so I gave it no further thought. This morning I woke up and launched Firefox, noticed this headline, and then noticed my extensions wer…
?
>:-(
Grrr.
I'm just getting old and curmudgeonly maybe? I've decided though, I'm starting an animated security blog to show people the ludicrousness of all this kind of stuff in plain language. I'll be Statler, and I just need someone to be Waldorf. Because this stuff really is getting Statler and Waldorf level ridiculous.