Earlier quoted context omitted.
JSON response from the `normandy` API here: https://xor.cat/assets/other/random/2019-05-04/normandy_sign... hotfix-update-xpi-signing-intermediate-bug-1548973: https://storage.googleapis.com/moz-fx-normandy-prod-addons/e... From the looks, it installs the above plugin, and changes `app.update.lastUpdateTime.xpi-signature-verification` to `1556945257` I can't get it to work in ESR 60 though. Getting file not found on…
Hey, if you just click on that storage.googleapis.com link it installs the hotfix directly without having to enable normandy ;)
All extensions disabled due to expiration of intermediate signing cert
711–720 of 955 posts
Re: All extensions disabled due to expiration of intermediate signing cert
#712Earlier quoted context omitted.
Can we get a clarification: Unchecking "Allow Firefox to install and run studies" in the UI does not change "app.normandy.enabled" to "false". Then, does unchecking "Allow Firefox to install and run studies" really disable Normandy, or not?
As explained on Normandy's wiki page, they are related but two different things: > Preference rollout is meant for permanent changes that we are sure of. Shield is meant for testing variations and figuring out what, if anything, is the best thing to do. https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout#...
Re: All extensions disabled due to expiration of intermediate signing cert
#713Re: All extensions disabled due to expiration of intermediate signing cert
#714Earlier quoted context omitted.
Can we get a clarification: Unchecking "Allow Firefox to install and run studies" in the UI does not change "app.normandy.enabled" to "false". Then, does unchecking "Allow Firefox to install and run studies" really disable Normandy, or not?
As explained on Normandy's wiki page, they are related but two different things: > Preference rollout is meant for permanent changes that we are sure of. Shield is meant for testing variations and figuring out what, if anything, is the best thing to do. https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout#...
And if you look at the big normandy JSON, hey, it's all the same Pocket and heartbeat shit we've seen from studies.
Re: All extensions disabled due to expiration of intermediate signing cert
#715Earlier quoted context omitted.
> Still, this type of oversight seems all too common even in large companies. (...) Has anyone developed a tool designed specifically to avoid certificate expiry disasters? LetsEncrypt renewal is supposed to be automated. [1] I know of a company that hosted blogs for thousands of customers. They used LetsEncrypt, but the CTO considered automatic renewals a possible security risk, so they did it manually. Problem is,…
Just curious, are you talking about Webflow? Because I had to hunt down and make sure our Let's Encrypt auto renewal was working until I realized the certificate was served by them. They wait until the last 12 hours to renew the certificate. I have no idea what type of rationalization would lead to that decision.
Re: All extensions disabled due to expiration of intermediate signing cert
#716Earlier quoted context omitted.
protecting 99.999% of the users It is horribly paternalistic to advocate for keeping users ignorant, unlearning, and --- dare I say it --- easily manipulated. I will refrain from mentioning again that infamous Franklin quote. I am frankly very fucking pissed off by this authoritarian walled-garden trend, and vehemently oppose anyone who helps this industry put the nooses around the necks of others as well as their ow…
Most people do not know what a manifest.json is or what sort of permissions they're handing to a random WebExtension. If you want your freedom from reviewed extensions: fine, get an unbranded Firefox, or Developer edition, and you get that.
If you can recommend an fork that allows extension sideloading but is kept up to date, please do so, I’ve been looking...
Re: All extensions disabled due to expiration of intermediate signing cert
#717edit: or even why the browser is checking this at run-time. As long as it checked the cert when the extension was installed, isn't that enough?
Re: All extensions disabled due to expiration of intermediate signing cert
#718Earlier quoted context omitted.
pushed it out to users via Normandy (this should be most users) Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? What about a UI knob to disable it?
I have spent ~10 years using Firefox daily, tweaking the config and getting the addons set up the way I want. I was a professional web developer for most of those years. This is the first I have heard of Firefox changing my config settings invisibly in the background. This is obscene. Who on earth thought this was a good idea? The security ramifications are limitless. I understand all too well that most companies hav…
you must not have been paying attention the last 3 or so years
Mozilla is doing all kinds of, IMO, unethical things with FireFox that goes against the core value of the mission statement of the Mozilla Foundation.
They are too busy trying to replicate Chrome to care about privacy, security, or basic user rights
Re: All extensions disabled due to expiration of intermediate signing cert
#719Earlier quoted context omitted.
> Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? It will even be documented for them: https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout > What about a UI knob to disable it? app.normandy.enabled
The UI knob is Options -> Privacy & Security > Allow Firefox to install and run studies They're using the studies system to push this hotfix faster for those that have it enabled. Edit: Source: See: https://discourse.mozilla.org/t/certificate-issue-causing-ad... > In order to be able to provide this fix on short notice, we are using the Studies system. You can check if you have studies enabled by going to Firefox Pre…
Re: All extensions disabled due to expiration of intermediate signing cert
#720Earlier quoted context omitted.
JSON response from the `normandy` API here: https://xor.cat/assets/other/random/2019-05-04/normandy_sign... hotfix-update-xpi-signing-intermediate-bug-1548973: https://storage.googleapis.com/moz-fx-normandy-prod-addons/e... From the looks, it installs the above plugin, and changes `app.update.lastUpdateTime.xpi-signature-verification` to `1556945257` I can't get it to work in ESR 60 though. Getting file not found on…
Hey, if you just click on that storage.googleapis.com link it installs the hotfix directly without having to enable normandy ;)