Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

171–180 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#171
post #98

I'm interested in the general writeup what went wrong that they missed this certificate expiring. That's a structural problem. Also why it took 6 hrs to assign P1 to the bug

I'm also interested in the postmortem to explain the processes that failed to allow the certificate to expire, but let's not overdramatize the situation by nitpicking about filling in form fields on bugzilla. The fact that the tree was closed is equivalent to DEFCON-1, which is all the priority anyone needs to understand the severity of this bug.

> which is all the priority anyone needs to understand the severity of this bug.

Random user: What the fuck is a tree and why is the priority of this not higher yet?

Re: Update Regarding Add-Ons in Firefox

#172
post #87

Earlier quoted context omitted.

Clearly, downstream distributors need to create a patch which causes their distributes Firefox builds to only check certificates on add-on installation (and to check revocations too, sure): it should never be possible for a browser to fail into an unsafe configuration.

What's the difference to the user between "to check revocations too, sure" and what happened?

checking revocations lists != certificate expiry

Re: Update Regarding Add-Ons in Firefox

#173
post #31

I'm interested in the general writeup what went wrong that they missed this certificate expiring. That's a structural problem. Also why it took 6 hrs to assign P1 to the bug

They closed the trees (stopped merging other code changes to prioritize this) for the bug I would assume the delay in assigning P1 is really just a result of assigning P1 not being as high priority as fixing the damn problem.

If I understand the bug report comments correctly, they didn't close the trees to other code changes to prioritize fixing this, they did it because the cert expiry broke some important tests at the same time as it broke every end user's browser.

Re: Update Regarding Add-Ons in Firefox

#174

I asked this in the other thread but I guess there's too many comments there: Is there a project for Firefox that is analogous to Chromium for Chrome? I need a Firefox build with all the Mozilla shit ripped out. I don't trust the org that decided their certificate expiration was more important than giving users the choice to run what they want.

It seems like Mozilla distributes a special version that allows this. https://wiki.mozilla.org/Add-ons/Extension_Signing > The Nightly and Developer Edition versions of Firefox have a preference to disable signature enforcement. There are also be special unbranded versions of Release and Beta that have this preference, so that add-on developers can work on their add-ons without having to sign every build. To disable…

The unbranded builds are useless for anything but internal addon testing on stable because they do not receive updates.

Custom firefox builds offered by some linux distros are a better choice, yes.

Re: Update Regarding Add-Ons in Firefox

#175
post #145

Earlier quoted context omitted.

This is bad design. Installed software shouldn't just stop working because the clock ticked. (And yes, I know browsers should stay up to date etc. etc., but come on, no software should just stop functioning because of a calendar) And to the downvoters: doesn't this entire fiasco ENTIRELY PROVE MY POINT?

> And to the downvoters: doesn't this entire fiasco ENTIRELY PROVE MY POINT? No. All it proves is that certificates expire (which is a Good Thing (tm)). If you depend on online certificates to verify content, something like this can theoretically happen.

So you think Mozilla is enjoying this right now? And that this is going to help the perception and market share of Firefox?

Hypothetically, lets say they took the opposite approach, and only checked the certificate date on installation. What would have happened? There would have been a brief period of time where people couldn't install extensions, it would have been fixed in a few hours, and this story would probably have like 20 upvotes and fallen off the front page in like 10 minutes, if it ever got there in the first place.

Now let's briefly look at what's actually taking place: a bunch of people's browsers broke. It broke in scary ways for some people that were using extensions for privacy; IE, their security might have been compromised by this decision by Mozilla. Mozilla is probably going to lose users over this. Their reputation is damaged. Not only that, but now people are evaluating other decisions that Mozilla has made separately from this in an unfavorable light (Studies and Normandy, specifically). The computing industry loses out on this too: we're all better off for chrome having a viable open source competitor. We should want Mozilla to do well, whether you use their browser or not.

Which outcome do you think Mozilla engineers would be preferring today?

Re: Update Regarding Add-Ons in Firefox

#176

Earlier quoted context omitted.

If it is, without requesting user authorisation, then that's an illegal act under the UK Computer Misuse Act (and the USA's CFAA I think too) - modification of a computer without authorisation.

except you agreed and authorized when you installed the software. Take your position to the logical extreme - software can't make any changes without explicit, interactive approval; and you thought UAC was bad. I look forward to joining your class-action lawsuit.

When the changes are unexpected, yes, further explicit authorisation is required. Just because you installed a photo-album app doesn't let the distributor delete all your photos, say.

Besides that, this sort of "but we hid something in the t&c-s so now we can shit on you" is the sort of thing I expect from over commercialised companies, not from what was once a paragon of the FOSS community.

FWIW class-actions don't exist in UK.

Re: Update Regarding Add-Ons in Firefox

#177

Earlier quoted context omitted.

Don't think so, from what I understand, the problem was the intermediate certificate expired, it would have expired regardless if there were no automatic updates.

Even on completely isolated distributions like Tor Browser or enterprise ESR installs. The only way you avoided this is if you were running Nightly or Developer or the normal one on Linux, and you disabled signature checks.

Yup. Am on macOS and Nightly and still got hit with the isdue (luckily the fix was already out).

Guess we'll see a post-mortem soon and get to know how did this even came to be.

Re: Update Regarding Add-Ons in Firefox

#178

On Android I get this: >We rolled out a hotfix that re-enables affected add-ons. The fix will be automatically applied in the background within the next few hours. For more details, please check out the update at https://support.mozilla.org/en-US/kb/add-ons-failing-install... Which is like "we did something we shouldn't have causing unauthorised changes to your computer, so we're going to make unauthorised changes to…

As I understand it, you agree to the terms of Studies as part of the ToS agreed to on installation. You can disable it later. And--while it was a ridiculous mistake--they didn't make any "unauthorized changes" to your computer. They just let a certificate expire and your computer, running the same code it always had, stopped trusting it.

Re: Update Regarding Add-Ons in Firefox

#179

Sadly, this removed my settings for multi-account containers extension :(

Just heads up here. I was able to restore it partially on Windows using https://www.shadowexplorer.com/downloads.html (which is, btw, a great tool!)

You'd be looking for a file C:\Users\YOUR_USER_NAME\AppData\Roaming\Mozilla\Firefox\Profiles\YOUR_PROFILE\containers.json

and also ...\YOUR_PROFILE\browser-extension-data\@testpilot-containers

Re: Update Regarding Add-Ons in Firefox

#180
post #124

Earlier quoted context omitted.

The blog post linked by this HN post is the official URL for the patch. Any installation method not described there is unofficial DIY, no matter how Mozilla-signed any given version of the XPI is.

Sir, this is Hacker News.

Yes, we are all quite advanced enough to footgun ourselves with abandon :) For everyone else, the fix is magically healing their browser without any intervention at all, and some of my high-skilled tech friends haven’t even noticed yet because they’re weekending and this all resolved itself before they realized it. Never underestimate the burden that being an “expert” places on your future time spend.
Post reply on HN