Live data from Hacker News

All extensions disabled due to expiration of intermediate signing cert

bugzilla.mozilla.org

711–720 of 955 posts

Re: All extensions disabled due to expiration of intermediate signing cert

#711
post #704
post #592

Earlier quoted context omitted.

JSON response from the `normandy` API here: https://xor.cat/assets/other/random/2019-05-04/normandy_sign... hotfix-update-xpi-signing-intermediate-bug-1548973: https://storage.googleapis.com/moz-fx-normandy-prod-addons/e... From the looks, it installs the above plugin, and changes `app.update.lastUpdateTime.xpi-signature-verification` to `1556945257` I can't get it to work in ESR 60 though. Getting file not found on…

Hey, if you just click on that storage.googleapis.com link it installs the hotfix directly without having to enable normandy ;)

This should be sticky comment somewhere on the top of the comments. It bought all the addons back for me.

Re: All extensions disabled due to expiration of intermediate signing cert

#712
post #681

Earlier quoted context omitted.

Can we get a clarification: Unchecking "Allow Firefox to install and run studies" in the UI does not change "app.normandy.enabled" to "false". Then, does unchecking "Allow Firefox to install and run studies" really disable Normandy, or not?

As explained on Normandy's wiki page, they are related but two different things: > Preference rollout is meant for permanent changes that we are sure of. Shield is meant for testing variations and figuring out what, if anything, is the best thing to do. https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout#...

"Explained" is perhaps too generous a word. I'm a software engineer and I found that page to be confusing. It seems to be written for internal Mozilla employees, not for the general public.

Re: All extensions disabled due to expiration of intermediate signing cert

#713
I've had normandy disabled in my user.js for a while, but this was only after thoroughly perusing documentation and some firefox "hardening" projects. Point being, no end user should have to do what I did. Sane defaults, and transparency about things that should be opt-in, are sorely needed. Regardless, I still stand by Firefox, and am thankful there are chromium alternatives. The web is what it is, though I dream of a simpler one.

Re: All extensions disabled due to expiration of intermediate signing cert

#714
post #681

Earlier quoted context omitted.

Can we get a clarification: Unchecking "Allow Firefox to install and run studies" in the UI does not change "app.normandy.enabled" to "false". Then, does unchecking "Allow Firefox to install and run studies" really disable Normandy, or not?

As explained on Normandy's wiki page, they are related but two different things: > Preference rollout is meant for permanent changes that we are sure of. Shield is meant for testing variations and figuring out what, if anything, is the best thing to do. https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout#...

Except as we have learned "preference rollout" is also "installing extensions". So this is much the same as studies, but studies was disgraced, so now this is studies 2.0, no option to disable this time around.

And if you look at the big normandy JSON, hey, it's all the same Pocket and heartbeat shit we've seen from studies.

Re: All extensions disabled due to expiration of intermediate signing cert

#715
post #226
post #66

Earlier quoted context omitted.

> Still, this type of oversight seems all too common even in large companies. (...) Has anyone developed a tool designed specifically to avoid certificate expiry disasters? LetsEncrypt renewal is supposed to be automated. [1] I know of a company that hosted blogs for thousands of customers. They used LetsEncrypt, but the CTO considered automatic renewals a possible security risk, so they did it manually. Problem is,…

Just curious, are you talking about Webflow? Because I had to hunt down and make sure our Let's Encrypt auto renewal was working until I realized the certificate was served by them. They wait until the last 12 hours to renew the certificate. I have no idea what type of rationalization would lead to that decision.

Not webflow. We auto renew way before LE expires the cert.

Re: All extensions disabled due to expiration of intermediate signing cert

#716
post #208

Earlier quoted context omitted.

protecting 99.999% of the users It is horribly paternalistic to advocate for keeping users ignorant, unlearning, and --- dare I say it --- easily manipulated. I will refrain from mentioning again that infamous Franklin quote. I am frankly very fucking pissed off by this authoritarian walled-garden trend, and vehemently oppose anyone who helps this industry put the nooses around the necks of others as well as their ow…

Most people do not know what a manifest.json is or what sort of permissions they're handing to a random WebExtension. If you want your freedom from reviewed extensions: fine, get an unbranded Firefox, or Developer edition, and you get that.

A Developer Edition is unstable, so I wouldn’t want to use that.

If you can recommend an fork that allows extension sideloading but is kept up to date, please do so, I’ve been looking...

Re: All extensions disabled due to expiration of intermediate signing cert

#717
I don't get why an expiring cert disables the extensions. Shouldn't the browser be checking the cert expiry date against the date the extension was installed, not against current time? As long as there's no way to manipulate the extension installation date that would be fine, wouldn't it?

edit: or even why the browser is checking this at run-time. As long as it checked the cert when the extension was installed, isn't that enough?

Re: All extensions disabled due to expiration of intermediate signing cert

#718

Earlier quoted context omitted.

pushed it out to users via Normandy (this should be most users) Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? What about a UI knob to disable it?

I have spent ~10 years using Firefox daily, tweaking the config and getting the addons set up the way I want. I was a professional web developer for most of those years. This is the first I have heard of Firefox changing my config settings invisibly in the background. This is obscene. Who on earth thought this was a good idea? The security ramifications are limitless. I understand all too well that most companies hav…

>>This is the first I have heard of Firefox changing my config settings invisibly in the background.

you must not have been paying attention the last 3 or so years

Mozilla is doing all kinds of, IMO, unethical things with FireFox that goes against the core value of the mission statement of the Mozilla Foundation.

They are too busy trying to replicate Chrome to care about privacy, security, or basic user rights

Re: All extensions disabled due to expiration of intermediate signing cert

#719
post #557

Earlier quoted context omitted.

> Is the existence of a back door method of updating Firefox preferences something that will be disclosed to users? It will even be documented for them: https://wiki.mozilla.org/Firefox/Normandy/PreferenceRollout > What about a UI knob to disable it? app.normandy.enabled

The UI knob is Options -> Privacy & Security > Allow Firefox to install and run studies They're using the studies system to push this hotfix faster for those that have it enabled. Edit: Source: See: https://discourse.mozilla.org/t/certificate-issue-causing-ad... > In order to be able to provide this fix on short notice, we are using the Studies system. You can check if you have studies enabled by going to Firefox Pre…

They are using the Studies system in a complete violation of the way they said they would use the studies system for when it was announced. This is not surprising since Mozilla is becoming about as Trust Worthily as Google or Facebook

Re: All extensions disabled due to expiration of intermediate signing cert

#720
post #704
post #592

Earlier quoted context omitted.

JSON response from the `normandy` API here: https://xor.cat/assets/other/random/2019-05-04/normandy_sign... hotfix-update-xpi-signing-intermediate-bug-1548973: https://storage.googleapis.com/moz-fx-normandy-prod-addons/e... From the looks, it installs the above plugin, and changes `app.update.lastUpdateTime.xpi-signature-verification` to `1556945257` I can't get it to work in ESR 60 though. Getting file not found on…

Hey, if you just click on that storage.googleapis.com link it installs the hotfix directly without having to enable normandy ;)

It does, but it didn't fix anything for me. All my extensions are still gone. :(
Post reply on HN