At the minimum they should add a testsuite that runs at least a month into the future to catch these kinds of things. There was a similar issue[0] a few years ago that was only caught a month in advance. Even better would be to set things up to only do a verify on install instead on every startup. [0] https://bugzilla.mozilla.org/show_bug.cgi?id=1267318
> Even better would be to set things up to only do a verify on install instead on every startup. That would defeat the purpose of verification: "Add-on signing in Firefox helps protect against browser hijackers and other malware by making it harder for them to be installed." [1] And it's not just malware that was doing that. Microsoft force-installed the ".NET Framework Assistant" into Firefox on Windows, and you had…
And honestly, I think it is security theater to attempt to defend against attackers on the same or higher privilege level. If microsoft wants to force something down your throat on windows then there's not much you can do.
The problem is that mozilla turns the failures of others into their own problem and then they try to fix it themselves. That scope and responsibility creep leads us to the fallout we're seeing now.