Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

91–100 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#91

I'm interested in the general writeup what went wrong that they missed this certificate expiring. That's a structural problem. Also why it took 6 hrs to assign P1 to the bug

> Also why it took 6 hrs to assign P1 to the bug

Because people were staying up until the wee hours of the morning working on fixing it instead of toggling priorities in Bugzilla. This was treated as a five-alarm fire.

Re: Update Regarding Add-Ons in Firefox

#92
post #88
post #18

Instead of enabling studies just click on this link. It installs that specific "study" (hotfix) without installing anything else. https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

OMG. "Don't trust Mozilla to install something on your machine. Click this link instead!" Has the "privacy" community finally jumped the shark?

To be perfectly clear I trust Mozilla... this link is a link to code signed by Mozilla that I personally didn't even bother to audit because it was signed by Mozilla.

I just don't want to enable shield studies, because it looks to me like they haven't disabled the other shield studies while distributing this fix, and I don't want to install the other shield studies.

Re: Update Regarding Add-Ons in Firefox

#93
post #67

I have a bunch of privacy-enhancing addons installed, which have now all been disabled. If I hadn't read HN this morning, I wouldn't even have known why. Until now, I had no idea that it was even possible to remotely disable my addons. And now Mozilla are saying that the "fix" is to allow them to install & run "studies" on my machine? What are they smoking? I'm having a hard time trusting a company that randomly & re…

They have not remotely disabled addons. The certificate expired and the addons did the correct thing when connection couldn’t be established. Nobody triggered a switch to disable addons.

If you can disable all my addons by having a certificate expire, you can effectively remotely disable all my addons. And that's exactly what happened. The fact that this was (presumably?) not intentional is irrelevant. The switch may not be an actual switch, but it's there nevertheless. And it shouldn't be.

Re: Update Regarding Add-Ons in Firefox

#94

Earlier quoted context omitted.

As a regular user, it was worth it. Firefox was honestly pretty shit on (at least on Windows) pre-e10s. Before, I had to kill firefox every few days because CPU usage would climb for no reason. Since then, the only restarts I do are for updates. As a browser, it works much better, and as an extension developer as well, I'm glad I can write one extension that works in most browsers now. Yeah, it sucks they removed the…

xpinstall.signatures.required in about:config is the switch you are asking for. Though, it does not allow one time checks at install, but a choice of regular checks, or no checks at all.

That switch is ignored everywhere but dev/nightly builds and on Linux builds.

Re: Update Regarding Add-Ons in Firefox

#96
I know Firefox isn't being malicious, but ugh, this seems like the worst possible PR move for this, optics wise. "Hey so uh, we accidentally broke your browser, so you need to opt-in to becoming a guinney pig. But don't worry! You probably were already opted in anyway and just didn't realize it! Also it might take six hours to work."

Re: Update Regarding Add-Ons in Firefox

#97
Another workaround if you don't want to enable "studies" is to manually re-load the add-ons in Debug Mode. I don't know the full consequences of this, but Firefox seems to be behaving normally having done it.

Go to about:debugging from the address bar. Right at the top is a button to "Load Temporary Add-on", with a checkbox "Enable add-on debugging". (On a Mac, the add-ons are in ~/Library/Application Support/Firefox/Profiles/«ID».default/extensions (assuming that you have only a single profile).) They should stay enabled until Firefox relaunches.

Re: Update Regarding Add-Ons in Firefox

#98

I'm interested in the general writeup what went wrong that they missed this certificate expiring. That's a structural problem. Also why it took 6 hrs to assign P1 to the bug

I'm also interested in the postmortem to explain the processes that failed to allow the certificate to expire, but let's not overdramatize the situation by nitpicking about filling in form fields on bugzilla. The fact that the tree was closed is equivalent to DEFCON-1, which is all the priority anyone needs to understand the severity of this bug.

Re: Update Regarding Add-Ons in Firefox

#99
post #67

I have a bunch of privacy-enhancing addons installed, which have now all been disabled. If I hadn't read HN this morning, I wouldn't even have known why. Until now, I had no idea that it was even possible to remotely disable my addons. And now Mozilla are saying that the "fix" is to allow them to install & run "studies" on my machine? What are they smoking? I'm having a hard time trusting a company that randomly & re…

Your addons have not been remotely disabled. They were marked as trustworthy by a certificate that expired and thus are no longer considered trustworthy. The effect is similar, the mechanism is different. You could also enable loading of unsigned extensions, that would “fix” the issue, too.

They were effectively remotely disabled, there was a hidden dead-mans handle that's been triggered in order to effect the result; but it's logically equivalent from an end user perspective -- an external agency caused my add-ons to be disabled without my authorisation.

"A certificate chain has expired, do you want to disable all add-ons?"

How hard is that?

Post reply on HN