Update: We have rolled out a partial fix for this issue. We generated a new intermediate certificate with the same name/key but an updated validity window and pushed it out to users via Normandy (this should be most users). Users who have Normandy on should see their add-ons start working over the next few hours. We are continuing to work on packaging up the new certificate for users who have Normandy disabled.
How do you enable Normandy on Firefox For Android? There's no Normandy in the about:config.
This is such a gigantic mess, even for a very loyal Firefox user it's to swallow.
> There's no obvious way to disable the Normandy back door. ??? It's a publicly documented feature with a publicly documented way to disable it.
With an obscure name and no correlation to all the other spying and backdoor ING Mozilla are doing. Is this really the best option tog etaprivacy focused browser? I think this is all very worrying.
Can you elaborate on what 'other spying' Mozilla does? Do you mean their telemetry?
I too use Debian's Firefox ESR. I noticed the "Allow Firefox to install and run studies" option in Privacy & Security Preferences a long time ago. It was unchecked and greyed out (i.e., unclickable), and a label below it says "Data reporting is disabled for this build configuration", so I gave it no further thought. This morning I woke up and launched Firefox, noticed this headline, and then noticed my extensions wer…
I had mine disabled. So let's think about this for a second. If I disable a security hole that you can drive a semi-truck through, I remain foobar'd. If I run my "secure" firefox configuration, with the security hole enabled, then they un-foobar me first. Before anyone else. So I could effectively get rewarded, for always keeping a security hole open. But I didn't keep it open, so... yeah... they'll get around to me…
> I'm just getting old and curmudgeonly maybe?
You're not. You just have standards.
We need people with standards in this industry, because that's the only source we have of market signals that prevent the market from going full user-hostile.
I actually did read that story but I don't understand what that has to do with anything being discussed here. Yes, Youtube put up a banner asking IE6 users to move to a more modern browser 10 years ago. How is that in any way related to Firefox pushing a hotfix in 2019 to fix a certificate issue? Are you worried there is a big evil conspiracy to use this mechanism to uninstall Internet Explorer from peoples' computer…
Okay, so, youtube targets a small subset of users, and changes their experience capriciously, and to suit their own purposes. Firefox, it turns out, has a built-in telemetry system that defaults to enable exactly the same behavior: changing your system, to suit their desires. You’re words “ a big evil conspiracy to use this mechanism to uninstall Internet Explorer from peoples' computer ” are misleading. No one would…
> Okay, so, youtube targets a small subset of users, and changes their experience capriciously, and to suit their own purposes.
They added a dismissable banner. That falls far short of "changing their experience", in my mind.
The UI knob is Options -> Privacy & Security > Allow Firefox to install and run studies They're using the studies system to push this hotfix faster for those that have it enabled. Edit: Source: See: https://discourse.mozilla.org/t/certificate-issue-causing-ad... > In order to be able to provide this fix on short notice, we are using the Studies system. You can check if you have studies enabled by going to Firefox Pre…
Why is it supposed to be reassuring that their “studies” can override the cryptographic infrastructure? Edit: rephrase for clarity
If you don't trust your software provider, "studies" don't matter. The same but could come through a regular update. If you don't want to be on bleeding edge, that's fine, and if the UI for Normandy is bad, that's an issue, but it's nonsense to accept updates and then say you don't want updates.
Update: We have rolled out a partial fix for this issue. We generated a new intermediate certificate with the same name/key but an updated validity window and pushed it out to users via Normandy (this should be most users). Users who have Normandy on should see their add-ons start working over the next few hours. We are continuing to work on packaging up the new certificate for users who have Normandy disabled.
pushed it out to users via Normandy (this should be most users) Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? What about a UI knob to disable it?
One result of this, when I use firefox from now on, I'll be disabling "Normandy"
> There's no obvious way to disable the Normandy back door. ??? It's a publicly documented feature with a publicly documented way to disable it.
With an obscure name and no correlation to all the other spying and backdoor ING Mozilla are doing. Is this really the best option tog etaprivacy focused browser? I think this is all very worrying.
It's named after a world famous beachhead of an invasion. The name isn't that obscure for a feature that invades the userbase with a takeover.
So let's say I'm the IT department in my company. I've already got my root cert on every employee's PC(including Firefox because they can't browse otherwise). Can I act like the Normandy endpoint and let's say remotely disable the ability to install any extension including those pesky VPN ones and also do a lot of other such things I would like, you get my drift? Am I right? Am I right? Please tell me I'm wrong.
You are wondering if an IT admin can admin machines in its network? Yes, an IT admin can admin machines in it's network.
I get the ostensible justification, but attacking this way requires the user to dig into the obscure dev settings and load an xpi from outside the browser[1]. Is there even one case of a user compromised that way? [1] or at least they could have allowed that as a compromise
I updated my previous comment. They say there exist crapware installers that use elevated privileges that do inject stuff into the browser and that's why we can't have nice things, yes. But I disagree with their value tradeoffs. They want to add a little "protection" - which is really flimsy since there is no privilege separation - for users who already compromised their systems with adware at the expense of the free…
I'm totally fine with software already running on my machine being able to install addons into my browser. It can also already install a keylogger and record the screen, what's the big deal?
Firefox stopped respecting the signature-required setting in the mainline version in 2016. I know because I got burned by it and made a Hitler parody. https://youtube.com/watch?v=taGARf8K5J8 And frankly, this an extra absurdity on top of that. If you’re going to require signatures for all extensions, regardless of user preference, shouldn’t you be keeping an eye on the signing process?
Why does Mozilla do this? Same with removing the option to not update. Why not let users choose (in the case of update maybe with an about config setting)?
Because they don't want trojans to hijack the browser. If the user can change the signing preference, any application can.