Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

691–700 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#691
post #494

Earlier quoted context omitted.

I feel you. I saw this kind of thing coming back in 2010, when Firefox started copying Chrome blow for blow. I saw Google's influence on Mozilla and knew it could only turn out poorly. By the way, what can you say about that?

Maybe before talking about this he\she should provide any kind of proof of ever working at Mozilla at all?

(I work for Mozilla)

I'm guessing the poster is legitimately former staff. It's not hard to find disgruntled people in any organization (especially if you look at those who have left.) And they'll often have legitimate reasons.

But the question is really whether there's a consistent pattern of problems - actual rot, so to speak. I haven't seen much, but then i know that some parts of the org are very different than others. I can say that I have publicly complained about a number of things in the last several years, and never felt any repercussions as a result. That includes comments made directly to the CEO during All-Hands sessions, so I'm not just talking hypothetically.

Yet I have also heard about a handful of cases where people have been treated unfairly as a result of public comments or actions, including a couple of friends of mine. So shit happens here, it's definitely not perfect and the problems aren't all in the past. But overall, I still feel like Mozilla is substantially better than most similar companies.

Just my perspective.

Re: All extensions disabled due to expiration of intermediate signing cert

#692

Earlier quoted context omitted.

I too use Debian's Firefox ESR. I noticed the "Allow Firefox to install and run studies" option in Privacy & Security Preferences a long time ago. It was unchecked and greyed out (i.e., unclickable), and a label below it says "Data reporting is disabled for this build configuration", so I gave it no further thought. This morning I woke up and launched Firefox, noticed this headline, and then noticed my extensions wer…

I had mine disabled. So let's think about this for a second. If I disable a security hole that you can drive a semi-truck through, I remain foobar'd. If I run my "secure" firefox configuration, with the security hole enabled, then they un-foobar me first. Before anyone else. So I could effectively get rewarded, for always keeping a security hole open. But I didn't keep it open, so... yeah... they'll get around to me…

[deleted]

Re: All extensions disabled due to expiration of intermediate signing cert

#693
post #604

Earlier quoted context omitted.

I've been through all of Firefox `about:config` a few times in the past, fixing preferences to, e.g., try to disable umpteen different services that leak info or create potential vulnerabilities gratuitously, but this is the first I recall hearing of Normandy. Apparently I missed `app.normandy.enabled`, because I think I would've remembered a name with connotations of a bloody massive surprise attack. Incidentally, `…

I too use Debian's Firefox ESR. I noticed the "Allow Firefox to install and run studies" option in Privacy & Security Preferences a long time ago. It was unchecked and greyed out (i.e., unclickable), and a label below it says "Data reporting is disabled for this build configuration", so I gave it no further thought. This morning I woke up and launched Firefox, noticed this headline, and then noticed my extensions wer…

> noticed my extensions were still running.

Reportedly, Firefox only checks the date once per day, so if it hasn’t yet checked for you today, this will be the result.

> I looked in about:config and lo and behold, app.normandy.enabled=default [true].

I would assume that the config setting only has any effect if the feature is available in the build. Which it isn’t in Debian.

Re: All extensions disabled due to expiration of intermediate signing cert

#694
post #657

Earlier quoted context omitted.

Yes, that's right, if you install software that had a bug, then if you give someone permission to modify your software, you can get a bug fixes faster.

There are already channels for bug fixes, and some of the friction on those channels is intentional, such as for visibility and oversight/approval.

Exactly.

Why even have an official channel, providing visibility and official oversight, if when it comes down to it, you're just gonna push remote code updates through the same side channel a potential hacker would use?

People are saying it's for convenience. OK, but then they have to understand that doing things in that fashion is a really bad look. And now your users are set up to believe that, at least some of the updates coming from the side channel are "trust"-able.

Re: All extensions disabled due to expiration of intermediate signing cert

#695

Earlier quoted context omitted.

I too use Debian's Firefox ESR. I noticed the "Allow Firefox to install and run studies" option in Privacy & Security Preferences a long time ago. It was unchecked and greyed out (i.e., unclickable), and a label below it says "Data reporting is disabled for this build configuration", so I gave it no further thought. This morning I woke up and launched Firefox, noticed this headline, and then noticed my extensions wer…

I had mine disabled. So let's think about this for a second. If I disable a security hole that you can drive a semi-truck through, I remain foobar'd. If I run my "secure" firefox configuration, with the security hole enabled, then they un-foobar me first. Before anyone else. So I could effectively get rewarded, for always keeping a security hole open. But I didn't keep it open, so... yeah... they'll get around to me…

>If I disable a security hole that you can drive a semi-truck through, I remain foobar'd. If I run my "secure" firefox configuration, with the security hole enabled, then they un-foobar me first. Before anyone else. So I could effectively get rewarded, for always keeping a security hole open. But I didn't keep it open, so... yeah... they'll get around to me sometime.

That's needless drama. They will be rolling out the fix in a point release. Whatever way you use to update your browser will install that and get the fix. So the worst case is just going back to the old days where you'd have the issue until your distro issued a new package or you manually updated the browser version on Windows or OSX. What exactly would you expect that's not exactly what's happening?

Re: All extensions disabled due to expiration of intermediate signing cert

#696

Earlier quoted context omitted.

Why does Mozilla do this? Same with removing the option to not update. Why not let users choose (in the case of update maybe with an about config setting)?

Because they don't want trojans to hijack the browser. If the user can change the signing preference, any application can.

Yes, the sibling comment and thread already brought that up.

Re: All extensions disabled due to expiration of intermediate signing cert

#697
This is a shocking display of not just incompetence and bad practices but of brazen undisclosed covert control. Why should your local browser depend in this fragile way on some muckup in Mozilla HQ? And people line up to defend this?

Where does it explicitly say Mozilla can disable my addons remotely? When did I give them this power? And this from a so called 'open source privacy focused' browser. This is a mockery of privacy and open source and they shouldn't trade on this goodwill to gain users.

There can be no bigger security hole yet security fear mongers preach exactly this abusive model. This kind of centralized remote power is a far greater security threat that anything they keep on harping about, 'good intentions' and 'good faith' are not remotely something anyone should have to depend on. Why should Mozilla babysit my installation? Shouldn't they be using their resources to do something productive?

There is something rotten in SV culture and we urgently need to think of alternatives that are not infused in this 'know it all' abusive surveillance culture as even after such an egregious abuse of peoples trust and faith all you will get is hand waving, normalization, apologism and snarky entitled comments that trivialize people's concerns and choices made on the goodwill of open source.

Re: All extensions disabled due to expiration of intermediate signing cert

#698

Earlier quoted context omitted.

I too use Debian's Firefox ESR. I noticed the "Allow Firefox to install and run studies" option in Privacy & Security Preferences a long time ago. It was unchecked and greyed out (i.e., unclickable), and a label below it says "Data reporting is disabled for this build configuration", so I gave it no further thought. This morning I woke up and launched Firefox, noticed this headline, and then noticed my extensions wer…

I had mine disabled. So let's think about this for a second. If I disable a security hole that you can drive a semi-truck through, I remain foobar'd. If I run my "secure" firefox configuration, with the security hole enabled, then they un-foobar me first. Before anyone else. So I could effectively get rewarded, for always keeping a security hole open. But I didn't keep it open, so... yeah... they'll get around to me…

Automatic updates aren't a security hole. They are a security enhancement

Re: All extensions disabled due to expiration of intermediate signing cert

#699
post #669

Earlier quoted context omitted.

I updated my previous comment. They say there exist crapware installers that use elevated privileges that do inject stuff into the browser and that's why we can't have nice things, yes. But I disagree with their value tradeoffs. They want to add a little "protection" - which is really flimsy since there is no privilege separation - for users who already compromised their systems with adware at the expense of the free…

I'm totally fine with software already running on my machine being able to install addons into my browser. It can also already install a keylogger and record the screen, what's the big deal?

Are you fine with calling “editing of crypto certs” a study? And do you endorse all Orwellian doublespeak, or just this instance?

Re: All extensions disabled due to expiration of intermediate signing cert

#700
post #597
post #590

Earlier quoted context omitted.

So search elsewhere if you want more info. All code is available.

Users shouldn't have to search and then be able to understand the code found for such a feature. When a remote capability such as this exists it is Mozilla's responsibility to document how the feature works and the exact capabilities it gives them. Instead of doing so they have produced a wiki entry which appears to falsely describe the capabilities of this remote feature by stating it is used to change default prefe…

Hacker News

I think people here can be expected to read some code if they are interested in how something works.

Post reply on HN