Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

291–300 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#291

Earlier quoted context omitted.

They also have a frontdoor: built-in automatic updates.

This type of reply is ludicrous. An obscure feature (Normandy modifying default settings as part of studies) that requires you to actively opt out (and even then it’s still not clear if you _also_ have to go to about:config to _really_ disable it) and which can make such large scale errors as evicting all extensions is in absolutely no way comparable to the case of a user agreeing to auto-updates and fairly easily be…

I think you're overstating it.

>It is astoundingly disingenuous to act like these things are comparable.

Why aren't they comparable? In both cases, it's Mozilla pushing code to the end user. There's a different process behind both but calling one a frontdoor and one a backdoor seems apt to me.

>and which can make such large scale errors as evicting all extensions

Normandy was not used to disable all extensions. It was caused by a certificate expiration error completely independently. Normandy is being used instead to work around the error until a more permanent fix can be issued.

Re: Update Regarding Add-Ons in Firefox

#292
post #269

Earlier quoted context omitted.

Hey, just FYI, there are some good solutions in this thread to get your problem fixed ASAP. This one should work. https://news.ycombinator.com/item?id=19827302

No. JUST A HUGE NOOOO. My reply is here https://news.ycombinator.com/item?id=19828472

We’re literally in this mess because Firefox requires digital signatures on this kind of thing, please don’t make FUD posts.

This is much better than disabling the very same safe guard, signature checking, that prevents you from running arbitrary code in the first place.

Re: Update Regarding Add-Ons in Firefox

#293

Earlier quoted context omitted.

He has moved to Lynx.

CVE-2016-9179 was published about Lynx in November 2016. Lynx took more than 5 minutes to release an update, with the fix included [1] in 2.8.9dev.11 not reaching a production release until July 2018 — almost two years after the CVE was published. With a response time like that, I don't see how Lynx will satisfy their "5 minute fix" need any more than Firefox did. [1] https://lynx.invisible-island.net/current/CHANGES

Instead of pretending you're perplexed about my desire for a "5 minute fix", you can go back to the comment that said everyone here who has a problem with the issue Firefox caused is crafting a "narrative that appeals to emotion."

Read that, I don't know maybe ten times, and then read my comment which said I just switched my browser, no emotion involved.

I'm a man of action, baby. You can deliberate over my thought process all day, wondering if I would pick this browser or that one, or maybe even if I felt bad that I violated my loyalty to Mozilla Firefox (blessed be thy name). But don't think too hard, I've already moved on to the next decision in my life.

Re: Update Regarding Add-Ons in Firefox

#294

This one will be emotional as this destroyed some of my today's work. F you Mozilla. I lost all my tabs opened in other containers. The containers don't work too, so I cannot reopen them. This bug has been known for 3 years, and you did nothing to fix it. You get so much money, and what you do is basically provide a pathetic software (thunderbird) and a nice browser (which you just stopped from working) and you show…

I lose all tabs occasionally. Browsers aren't perfect, it does happen after a weird crash, or something. It's exceedingly rare, like maybe twice a year. With that said, I've always considered tabs to be volatile state. Browsers make their best effort to e.g. restore the previous session after a crash, but if you want non-volatile browser state, you should use bookmarks.

Eh, for me only that often if you include stuff caused by a dumb user (aka me). And even then I always got them back one way or another. Usually from %APPDATA%\Mozilla\Firefox\Profiles\[profile]\sessionstore-backups (thankfully there's usually a recent copy, since I'm on a test version) or last resort from backups.

Re: Update Regarding Add-Ons in Firefox

#295
post #238

On Android I get this: >We rolled out a hotfix that re-enables affected add-ons. The fix will be automatically applied in the background within the next few hours. For more details, please check out the update at https://support.mozilla.org/en-US/kb/add-ons-failing-install... Which is like "we did something we shouldn't have causing unauthorised changes to your computer, so we're going to make unauthorised changes to…

If Mozilla had barely any trust left than the industry as a whole is truly fucked.

I could say that for reliable software like SQLite or curl.

But for Firefox? My expectations for browsers in general aren't anywhere high enough to warrant raised eyebrows even in the face of monumental fuckups like the one were seeing today. Specially because users tried to warn that this could happen and Mozilla stubbornly said NO: https://news.ycombinator.com/item?id=10038999

Re: Update Regarding Add-Ons in Firefox

#296

Earlier quoted context omitted.

Studies are installed and their data sent to Mozilla without my knowledge or consent. Updates are installed with my consent. Pretty big difference.

Oh, I did not know that. Are you sure that enabling studies also means that user's data is sent to Mozilla without consent? Are you sure about this? I'm asking because there I can imagine that there is a benefit for Mozilla to develop a feature that enables studies without sending data. It could be used to fix a broken feature or a broken logic (as in the case of expired certificates here). So, I'm not convinced that…

Yes, I am 100% sure. See https://wiki.mozilla.org/Firefox/Shield/Shield_Studies#What_...

Re: Update Regarding Add-Ons in Firefox

#297
post #18

Instead of enabling studies just click on this link. It installs that specific "study" (hotfix) without installing anything else. https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

Install the official beta. This solved the issue for me https://www.mozilla.org/en-US/firefox/beta/all/

Re: Update Regarding Add-Ons in Firefox

#298
post #88
post #18

Instead of enabling studies just click on this link. It installs that specific "study" (hotfix) without installing anything else. https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

OMG. "Don't trust Mozilla to install something on your machine. Click this link instead!" Has the "privacy" community finally jumped the shark?

it's "install known-good software from mozilla"

vs

"whenever mozilla has crazy marketing or security ideas in the future, let them immediately and randomly install whatever, which maybe seems like a good idea for the mythical average user but is probably terrible for you"

Re: Update Regarding Add-Ons in Firefox

#299
post #212

Earlier quoted context omitted.

Not every piece of code needs to be signed. Should my ancient copy of Doom 2 stop working because it's not with the times? Or a level editor for it? Or an old turboC compiler? Some software lives a LONG time and it's fine, and it's up to the user whether that software is still useful to them or not. Seriously how many posts do we see on hacker news about like "We rebuilt this ancient machine from the 1970s to learn a…

Typically software signatures are not just pass/fail, but used to give audited entitlements for API. So a secure system would let you run Doom, but could forbid:' - Access to the filesystem outside the application domain due to potential for exfiltrating or destroying user data - Likewise, access to global system data may be limited - Access to the network due to (raw TCP/UDP) traffic not having been audited for secu…

Right but that's why we have sandboxes and virtual machines. There's no need to use a calendar date to enforce security.

Re: Update Regarding Add-Ons in Firefox

#300

hmm, i don't seem to have been affected by this bug somehow (my extensions are all still working). i turn off as much phoning home as i can (including turning studies off) and block connections to *.services.mozilla.com any idea why i might not be affected? it may help others who might want to retain control of their firefox browser (chromium-based browsers being non-sequiturs).

I got hit by the bug just 10 minutes ago.
Post reply on HN