Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

351–360 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#351
post #320
post #302

Earlier quoted context omitted.

For what it's worth, the (initial) mechanism for disabling add-ons (your 1) has been present since before Firefox 1.0. It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. Here, the mechanism that kicked in was the protection against add-ons that could have been signed with stolen credentials, which would…

> It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. I hate this attitude from security people so much. If for the sake of fighting malicious code you are crippling the software usability or my user experience, you are the malicious code.

I hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.

Re: Update Regarding Add-Ons in Firefox

#352

Earlier quoted context omitted.

So that's pretty unfair. 1) They state they are working on a fix for normal, release channel users who don't want to run studies 2) they tell you to temporarily run studies to get the fix within up to 6 six hours (could be faster; set expectation) 3) You can explicitly install nightly or 66.4 before it's pushed if you want a fix now Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a tim…

Not saying that their current actions are wrong , just that the optics of it are terrible for them. There was a chain of bad decisions that led them here though: 1) thinking it's ok to disable software after its installed (using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion), 2) Taking more control of people's local software than many people are comfortable with, especial…

> using cert expiration -- I'm ok if the cert was revoked but that's a totally different discussion

CAs can delete certificates from their revocation lists after expiration, which means that you can't tell the difference between a certificate that was never revoked but merely expired and a revoked-and-then-expired certificate.

Re: Update Regarding Add-Ons in Firefox

#353

At the minimum they should add a testsuite that runs at least a month into the future to catch these kinds of things. There was a similar issue[0] a few years ago that was only caught a month in advance. Even better would be to set things up to only do a verify on install instead on every startup. [0] https://bugzilla.mozilla.org/show_bug.cgi?id=1267318

Verify-on-install doesn't protect you against addons that steal someone's signing certificate to push out an update, because by the time the stolen certificate is discovered, it will have been installed on a bunch of users' systems.

Re: Update Regarding Add-Ons in Firefox

#354
post #350

Earlier quoted context omitted.

I'm curious, do you switch at every fuck up? Then it's only a matter of time until you come back to Firefox, or maybe you'll end up making your own web browser?

And operating system, and smartphone, and processor, and video card.

Hahahah look at all the Firefox fanboys coming out of the woodwork to try intellectual bullying because they're mad I admitted to uninstalling a web browser.

Re: Update Regarding Add-Ons in Firefox

#355
post #211

Earlier quoted context omitted.

> Even better would be to set things up to only do a verify on install instead on every startup. That would defeat the purpose of verification: "Add-on signing in Firefox helps protect against browser hijackers and other malware by making it harder for them to be installed." [1] And it's not just malware that was doing that. Microsoft force-installed the ".NET Framework Assistant" into Firefox on Windows, and you had…

Could you explain why verifying on every startup, instead of just on install, is necessary? The page you linked doesn't mention it. Edit: Let me amend my question - why is it necessary for the certificates to expire? If a plugin is signed by Mozilla, why wouldn't it be trusted once it gets old?

> Let me amend my question - why is it necessary for the certificates to expire? If a plugin is signed by Mozilla, why wouldn't it be trusted once it gets old?

I asked essentially that question earlier, and received some good answers explaining why [1].

Briefly, if something is signed by an expired certificate, whether or not you can trust the signature depends on whether or not the signing took place while the certificate was not expired.

If all you have is the thing and the signature from the code signer, you can't tell for sure when it was signed. If a bad guy has obtained an old signing certificate and its keys, that bad guy can generate new signatures that claim to have been signed while the certificate was valid.

Some code signing systems, such as the one in Windows (and I think the one Apple uses) also use another certificate, from a timestamp service, to prevent this. The way a timestamp service works is you send them a hash of a document, and they generate a certificate signed by them that essentially says "We were shown this hash on this particular date/time".

When you include the timestamp certificate with the signature from the code signer, then when you come across code that was signed by an expired certificate but purports to have been signed while the certificate was still valid, you can check the timestamp certificate to see if that is true. If it is, you can still consider the code signing to be valid.

Forgetting to renew a signing certificate is still bad even if you do this, but not as bad. If Microsoft or Apple forget, it doesn't stop existing applications from working, so end users aren't immediately impacted. It does stop developers from shipping updates or new applications, so still would be a big deal. I could see a bad guy noticing that a company always updates expiring certificates one month in advance, say, and then noticing that a certificate is expiring in just a week, infer that the certificate renewal has slipped through the cracks and is going to expire, and time the use of a critical zero day exploit to fall in the window when updates are broken by the expired certificate.

[1] https://news.ycombinator.com/item?id=19824017

Re: Update Regarding Add-Ons in Firefox

#356

Earlier quoted context omitted.

I just switched my browser. Bye bye Firefox.

I'm curious, do you switch at every fuck up? Then it's only a matter of time until you come back to Firefox, or maybe you'll end up making your own web browser?

No, just this one because it took me more than 5 minutes to not find a working fix, and this was such a massive fuck-up that I don't feel like sticking around.

I appreciate the condescension of both your comment and the person I initially replied to, but I honestly see your comments as saying, in more words, "Fuck the user." And that's fine, but why don't you just say it? Go ahead and type it, I want you to type what you really think about the users who are so dumb and fickle that they can't handle something so trivial as not being able to use their precious stupid add-ons like HTTPS Everywhere and uBlock..

Flag it again, for the F word. Flag the comment I responded to as well, for consistency. :)

Re: Update Regarding Add-Ons in Firefox

#357

I know Firefox isn't being malicious, but ugh, this seems like the worst possible PR move for this, optics wise. "Hey so uh, we accidentally broke your browser, so you need to opt-in to becoming a guinney pig. But don't worry! You probably were already opted in anyway and just didn't realize it! Also it might take six hours to work."

So that's pretty unfair. 1) They state they are working on a fix for normal, release channel users who don't want to run studies 2) they tell you to temporarily run studies to get the fix within up to 6 six hours (could be faster; set expectation) 3) You can explicitly install nightly or 66.4 before it's pushed if you want a fix now Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a tim…

I'm not sure I care how unfair the characterization is. I heavily use container tabs — ahem, 'usecontainers — and all of my open container tabs disappeared at once, with no indication of why or what to do about it, when this happened. I lost an absurd amount of work and state because of that. I only knew what caused it by inference, because I'd just previously read The Fine Article (which, btw, gave no indication that losing state like that was something I should expect, merely, "No active steps need to be taken to make add-ons work again"...)

I still prefer Firefox over all the other browsers, and will continue to use it, but the project has lost a lot of trust and goodwill over this.

The optics are indeed awful, and this was fully preventable. Firefox fucked up, full stop.

Re: Update Regarding Add-Ons in Firefox

#358

Can we take a moment and consider the side effects? This is a once in a lifetime chance for Google & Co. to get a glimpse of all those sly fuckers hiding behind adblockers. This effectively uncloaked a very specific subset of Internet users and exposed them to the very companies that they've been actively trying to avoid. Not just those who avoid Chrome, but those who take extra steps to explicitly evade the tracking…

>Surely Mozilla, the privacy advocate

The post is still great despite that weakness.

Re: Update Regarding Add-Ons in Firefox

#359
post #334

Earlier quoted context omitted.

Typing this from a new Brave install. Just switched from Firefox after their handling of this.

The handling, or the bug itself? Sound like the damage control is fine (although worrying that they have no way to distribute hotfixes more rapidly than this). The bug in the first place, on the other hand, seems pretty negligent. Not that it's incomprehensible, just pretty stupid. Anyhow, good luck with brave!

The bug in the first place. That we can't easily rollback this "upgrade" as well.

Re: Update Regarding Add-Ons in Firefox

#360
post #320

Earlier quoted context omitted.

> It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. I hate this attitude from security people so much. If for the sake of fighting malicious code you are crippling the software usability or my user experience, you are the malicious code.

I hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.

I wish that was true, but in fact I have no way to disable this and similiar amazing security entrenchments. The monthly device bricking windows updates, for instance.

If I can't do anything with my hardened computer, I don't care if is eaten alive by malware, it is useless anyways.

At work, as the guy who have to fight on behalf of the sysadmins and the users dozens of clueless security advisors who are hardening everything according to security best-practices written by similarily clueless experts, I'm seriously astonished by the common backward thinking. If you are blocking access to all users pdf files, for an instance, you are the malware, you are causing disturbance to the business operation and annoying everyone.

Post reply on HN