Can we take a moment and consider the side effects? This is a once in a lifetime chance for Google & Co. to get a glimpse of all those sly fuckers hiding behind adblockers. This effectively uncloaked a very specific subset of Internet users and exposed them to the very companies that they've been actively trying to avoid. Not just those who avoid Chrome, but those who take extra steps to explicitly evade the tracking…
Update Regarding Add-Ons in Firefox
341–350 of 504 posts
Re: Update Regarding Add-Ons in Firefox
#342IMHO it seems problematic, that they can remotely push code changes, including replacement of trusted certificate, and bypass package managers. I don't expect software to (significantly?) change during runtime, outside of what was packaged, signed, distributed and installed as part of apt/yum/pacman/etc. I understand (not that I like or agree with) that some apps are just embedded web browsers, and load everything ex…
If you didn't have browsers auto updating no-one would update them manually, meaning bad news for web developers wanting to take advantage of newer features.
I think you spelled “mass compromise of unsuspecting users due to unpatched security holes” wrong.
Like it or not, browsers as the primary networked application that people use are the prime target to exploit users. They connect to unknown endpoints of questionable trustworthiness (unlike most other networked apps) and execute code loaded from there. They also handle people’s secrets such as credentials to Homebanking. We maybe shouldn’t be at that point, but here we are and browser vendors need to handle that responsibility. Quick auto updates are crucial for that. Expert users might dislike them, but let’s face it, we’re not the majority.
Re: Update Regarding Add-Ons in Firefox
#343Earlier quoted context omitted.
Bezos and his strategy to name the company something starting with A so it always comes first finally pays off.
Now I understand why Google renamed itself Alphabet. One step ahead, literally.
Re: Update Regarding Add-Ons in Firefox
#344Earlier quoted context omitted.
Hold up there. Before people start clicking and installing random add-on links, how about linking to something official (either from a FF dev, or in a soure repository) that references this URL?
This is true. However it is signed by moz and looking at the source it seems safe enough (the cert is legit). It's just a normal wrapper with the following code added: // first inject the new cert try { let intermediate = "MIIHLTCCBRWgAwIBAgIDEAAIMA0GCSqGSIb3DQEBDAUAMH0xCzAJBgNVBAYTAlVTMRwwGgYDVQQKExNNb3ppbGxhIENvcnBvcmF0aW9uMS8wLQYDVQQLEyZNb3ppbGxhIEFNTyBQcm9kdWN0aW9uIFNpZ25pbmcgU2VydmljZTEfMB0GA1UEAxMWcm9vdC1jYS1wc…
Re: Update Regarding Add-Ons in Firefox
#345IMHO it seems problematic, that they can remotely push code changes, including replacement of trusted certificate, and bypass package managers. I don't expect software to (significantly?) change during runtime, outside of what was packaged, signed, distributed and installed as part of apt/yum/pacman/etc. I understand (not that I like or agree with) that some apps are just embedded web browsers, and load everything ex…
If you didn't have browsers auto updating no-one would update them manually, meaning bad news for web developers wanting to take advantage of newer features.
Re: Update Regarding Add-Ons in Firefox
#346Earlier quoted context omitted.
On Debian the distributed ESR has that option greyed out anyways. Maybe we’ll have to wait for maintainers to push an update?
I am sure an update will be pushed quickly. I'm waiting too, as a testing user. You can fix this temporarily via setting "xpinstall.signatures.required" to false. Toggle it back to true once update is released and you install it. Meanwhile I'm hijacking this comment that is to the upper parts of the tree to state this: the way the community treats Mozilla and Firefox is horribly, inexplicably, unacceptably unfair. Th…
While I agree with most of your comment, you're downplaying the severity here, especially since, IIUC, this situation also affected the Tor browser, disabling NoScript. If regimes like China were on the ball, and succeeded in escalating the remote code execution vulnerability into into deanonimization, this debacle may end up having a death toll attached to it.
Re: Update Regarding Add-Ons in Firefox
#347On Android I get this: >We rolled out a hotfix that re-enables affected add-ons. The fix will be automatically applied in the background within the next few hours. For more details, please check out the update at https://support.mozilla.org/en-US/kb/add-ons-failing-install... Which is like "we did something we shouldn't have causing unauthorised changes to your computer, so we're going to make unauthorised changes to…
What about this is against UK law?
Re: Update Regarding Add-Ons in Firefox
#3481. “Warning, a critical method for verifying authenticity is set to expire in X days. Please visit to update now.”
2. “A critical verification certificate has expired; while you should immediately go to to obtain an update, you may defer authentication for up to 5 more days.”
...or in other words, why can’t tools cut us some slack on either side of a deadline? Security for most things is not going to fall apart just by giving people a little room to deal with issues on their own schedule.
Re: Update Regarding Add-Ons in Firefox
#349From a UX point of view I don’t know why tools don’t have these two features: 1. “Warning, a critical method for verifying authenticity is set to expire in X days. Please visit to update now.” 2. “A critical verification certificate has expired; while you should immediately go to to obtain an update, you may defer authentication for up to 5 more days.” ...or in other words, why can’t tools cut us some slack on either…
Re: Update Regarding Add-Ons in Firefox
#350Earlier quoted context omitted.
I just switched my browser. Bye bye Firefox.
I'm curious, do you switch at every fuck up? Then it's only a matter of time until you come back to Firefox, or maybe you'll end up making your own web browser?