Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

51–60 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#51
post #4

An article that mentions a timeframe of “the next few hours”, but doesn't have any timestamp besides a date without a timezone.

Poor communication with zero accountability. A few hours could be 2, it could be 12.

“I (name the individual accountable) will give you an update at 12:00 PT (name a time) as an update to this post (name the communication channel) with the current status and latest information on this issue (don’t promise time to resolution, just time to info).”

Simple, clear, concrete, and unambiguous. I had hoped that Firefox had better communication procedures in the event of global-impact P1 issues.

Re: Update Regarding Add-Ons in Firefox

#52
post #18

Instead of enabling studies just click on this link. It installs that specific "study" (hotfix) without installing anything else. https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

How do I uninstall this? It doesn't show up anywhere after installation.

Re: Update Regarding Add-Ons in Firefox

#53
post #18

Instead of enabling studies just click on this link. It installs that specific "study" (hotfix) without installing anything else. https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

You would think they could have linked to that in their blog post, since people who have disabled "studies" have probably done so for a reason. Telemetry is bad enough; even without the "Mr. Robot" thing, there's no way I would let Mozilla randomly push changes to my browser just to see what happens.

Re: Update Regarding Add-Ons in Firefox

#54

Earlier quoted context omitted.

That doesn’t make money which kinda is required to work on Firefox.

But they have money to trow at Antifa fascists.

> Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tangents.

https://news.ycombinator.com/newsguidelines.html

Re: Update Regarding Add-Ons in Firefox

#55
post #48

Earlier quoted context omitted.

Hold up there. Before people start clicking and installing random add-on links, how about linking to something official (either from a FF dev, or in a soure repository) that references this URL?

This is true. However it is signed by moz and looking at the source it seems safe enough (the cert is legit). It's just a normal wrapper with the following code added: // first inject the new cert try { let intermediate = "MIIHLTCCBRWgAwIBAgIDEAAIMA0GCSqGSIb3DQEBDAUAMH0xCzAJBgNVBAYTAlVTMRwwGgYDVQQKExNNb3ppbGxhIENvcnBvcmF0aW9uMS8wLQYDVQQLEyZNb3ppbGxhIEFNTyBQcm9kdWN0aW9uIFNpZ25pbmcgU2VydmljZTEfMB0GA1UEAxMWcm9vdC1jYS1wc…

Out of interest, what's special about this add-on that allows it to install intermediate certificates like this vs. an add-on that any random dev could write?

Re: Update Regarding Add-Ons in Firefox

#56
post #4

An article that mentions a timeframe of “the next few hours”, but doesn't have any timestamp besides a date without a timezone.

You can hover the date to see the full timestamp, it's 2019-05-04 07:01:35 UTC-7.

Not available on all clients, notably mobile.

Re: Update Regarding Add-Ons in Firefox

#57

Mobile's still broken. Which is a browser Mozilla has apparently abandoned the userbase of in favor of focusing all their mobile effort on some silly pointless separate browser that caters to millenials more somehow or some other nonsense, instead of just working on the browser they already have. Really fed up with Mozilla at this point and considering switching to a fork or something.

> Mobile's still broken.

The hotfix xpi link mentioned elsewhere in this thread works on mobile.

Re: Update Regarding Add-Ons in Firefox

#58

Earlier quoted context omitted.

Servo was a silly pointless separate browser once

I still hold that the multithreaded performance benefit was nowhere near worth wiping away so many of hours of developer time and ripping so many good extensions out of users' hands with no replacement for so much of the lost functionality.

As a regular user, it was worth it. Firefox was honestly pretty shit on (at least on Windows) pre-e10s. Before, I had to kill firefox every few days because CPU usage would climb for no reason. Since then, the only restarts I do are for updates.

As a browser, it works much better, and as an extension developer as well, I'm glad I can write one extension that works in most browsers now.

Yeah, it sucks they removed the level of customization they used to have, but overall that changes are welcome.

That said, this whole thing is a huge weakness to me: having some organization decide what I can put onto my own computer is a frustrating tradeoff, but now it's gone from a nuisance to a real fucking problem.

I'm not an imbecile. I can manage my own browser plugins. Give me a switch to install XPIs without having some authority sign them, or at least verify once on install and piss off after that. I don't like my devices phoning home every 30s to make sure I'm "safe."

Re: Update Regarding Add-Ons in Firefox

#60
post #18

Instead of enabling studies just click on this link. It installs that specific "study" (hotfix) without installing anything else. https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

Hold up there. Before people start clicking and installing random add-on links, how about linking to something official (either from a FF dev, or in a soure repository) that references this URL?

The blog post linked by this HN post is the official URL for the patch. Any installation method not described there is unofficial DIY, no matter how Mozilla-signed any given version of the XPI is.
Post reply on HN