Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

651–660 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#651

Earlier quoted context omitted.

I actually did read that story but I don't understand what that has to do with anything being discussed here. Yes, Youtube put up a banner asking IE6 users to move to a more modern browser 10 years ago. How is that in any way related to Firefox pushing a hotfix in 2019 to fix a certificate issue? Are you worried there is a big evil conspiracy to use this mechanism to uninstall Internet Explorer from peoples' computer…

Okay, so, youtube targets a small subset of users, and changes their experience capriciously, and to suit their own purposes. Firefox, it turns out, has a built-in telemetry system that defaults to enable exactly the same behavior: changing your system, to suit their desires. You’re words “ a big evil conspiracy to use this mechanism to uninstall Internet Explorer from peoples' computer ” are misleading. No one would…

> Firefox, it turns out, has a built-in telemetry system that defaults to enable exactly the same behavior: changing your system, to suit their desires.

An example of the typical use of this system: say Mozilla wants to enable video hardware acceleration in Firefox but they don't know if bugs in video drivers or in Firefox will make crashing more frequent. So they enable hardware acceleration for 1% of users instead of 100% and compare the reported crash rate between the two to determine if it's ready to be pushed out universally.

Re: All extensions disabled due to expiration of intermediate signing cert

#652

Earlier quoted context omitted.

So is that a backdoor into my prefs? How can I check if Normandy is active on my installation?

Type about:config in the address bar and search for 'app.normandy.enabled' flag.

Not so in Firefox for Android. No normandy to find.

Re: All extensions disabled due to expiration of intermediate signing cert

#653
post #648

Earlier quoted context omitted.

Because (stable) users are dumb, are easily manipulated and can't be trusted. Thus the mothership has to be in control for the greater good. They also argue that enduser computers are already effectively "compromised" from a mozilla perspective because adware runs installers with admin privs and thus could insert things into the program folders. Thus anything the user can do adware could do too and therefore they can…

I get the ostensible justification, but attacking this way requires the user to dig into the obscure dev settings and load an xpi from outside the browser[1]. Is there even one case of a user compromised that way? [1] or at least they could have allowed that as a compromise

I updated my previous comment. They say there exist crapware installers that use elevated privileges that do inject stuff into the browser and that's why we can't have nice things, yes.

But I disagree with their value tradeoffs. They want to add a little "protection" - which is really flimsy since there is no privilege separation - for users who already compromised their systems with adware at the expense of the freedom of everyone else.

Re: All extensions disabled due to expiration of intermediate signing cert

#654

Earlier quoted context omitted.

I too use Debian's Firefox ESR. I noticed the "Allow Firefox to install and run studies" option in Privacy & Security Preferences a long time ago. It was unchecked and greyed out (i.e., unclickable), and a label below it says "Data reporting is disabled for this build configuration", so I gave it no further thought. This morning I woke up and launched Firefox, noticed this headline, and then noticed my extensions wer…

I had mine disabled. So let's think about this for a second. If I disable a security hole that you can drive a semi-truck through, I remain foobar'd. If I run my "secure" firefox configuration, with the security hole enabled, then they un-foobar me first. Before anyone else. So I could effectively get rewarded, for always keeping a security hole open. But I didn't keep it open, so... yeah... they'll get around to me…

Yes, that's right, if you install software that had a bug, then if you give someone permission to modify your software, you can get a bug fixes faster.

Re: All extensions disabled due to expiration of intermediate signing cert

#655
So let's say I'm the IT department in my company. I've already got my root cert on every employee's PC(including Firefox because they can't browse otherwise). Can I act like the Normandy endpoint and let's say remotely disable the ability to install any extension including those pesky VPN ones and also do a lot of other such things I would like, you get my drift? Am I right? Am I right?

Please tell me I'm wrong.

Re: All extensions disabled due to expiration of intermediate signing cert

#656

Earlier quoted context omitted.

> Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? It will even be documented for them: https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout > What about a UI knob to disable it? app.normandy.enabled

app.normandy.enabled That is not what I meant by a UI knob, and I sure hope you knew that. By UI knob I mean something easily discoverable and self-explanatory. Rooting around a gated (with a mighty strong warning, I should add) config section for something called "normandy" is not intuitive, and it's not self-explanatory. And I sure hope that by disclosed to users I did not mean some Hitchhiker's Guide-esque disclai…

I'm sorry to break it to you, but a fuckton is not actually part of the metric system...

Re: All extensions disabled due to expiration of intermediate signing cert

#657

Earlier quoted context omitted.

I had mine disabled. So let's think about this for a second. If I disable a security hole that you can drive a semi-truck through, I remain foobar'd. If I run my "secure" firefox configuration, with the security hole enabled, then they un-foobar me first. Before anyone else. So I could effectively get rewarded, for always keeping a security hole open. But I didn't keep it open, so... yeah... they'll get around to me…

Yes, that's right, if you install software that had a bug, then if you give someone permission to modify your software, you can get a bug fixes faster.

There are already channels for bug fixes, and some of the friction on those channels is intentional, such as for visibility and oversight/approval.

Re: All extensions disabled due to expiration of intermediate signing cert

#659

Just discovered the same message in the Tor browser, and it seems that NoScript got disabled. So people running Tor are a lot more vulnerable right now. Also, wow, the web has a ton of ads. I've been running uBlock origin so long I forgot how bad it had gotten :(

Considering that JavaScript has been used in the past to unmask Tor users, this is a frightening security bug and is not "fail-safe" behavior. The extension should remain enabled, but with a warning.

It is doubtful that Mozilla will change this behavior, as they will likely consider it a niche case, but the Tor browser should probably look into alternate means of changing the behavior (patching).

Edit: apparently the packaged versions of NoScript and HTTPS Everywhere were not affected. See thread here https://old.reddit.com/r/TOR/comments/bkg7vf/due_to_a_bug_in...

Post reply on HN