Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

361–370 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#361
post #360

Earlier quoted context omitted.

I hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.

I wish that was true, but in fact I have no way to disable this and similiar amazing security entrenchments. The monthly device bricking windows updates, for instance. If I can't do anything with my hardened computer, I don't care if is eaten alive by malware, it is useless anyways. At work, as the guy who have to fight on behalf of the sysadmins and the users dozens of clueless security advisors who are hardening ev…

This petulant antagonism ("You are the malware!", "No YOU ARE!") between users and security is contrary to everyone's interests.

Go sit in separate corners, both of you. Think really, really hard about how both of your jobs are critical to the long-term success of the business. Don't come back until you've meaningfully internalized that.

Re: Update Regarding Add-Ons in Firefox

#362
post #320
post #302

Earlier quoted context omitted.

For what it's worth, the (initial) mechanism for disabling add-ons (your 1) has been present since before Firefox 1.0. It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. Here, the mechanism that kicked in was the protection against add-ons that could have been signed with stolen credentials, which would…

> It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. I hate this attitude from security people so much. If for the sake of fighting malicious code you are crippling the software usability or my user experience, you are the malicious code.

So a security feature that had 0 impact for decades is "crippling" the usability of a project due to one outage?

Re: Update Regarding Add-Ons in Firefox

#364
post #320

Earlier quoted context omitted.

> It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. I hate this attitude from security people so much. If for the sake of fighting malicious code you are crippling the software usability or my user experience, you are the malicious code.

I hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.

Sorry, but where is the difference from a secure-system that allows central control - and a male-ware backdoored system?

All that is diffrent is the promise of non-maliciousness. Which often does not hold up. Cause money is corrosive to those little centralized empires of "all-can-fail-but-me".

Security is diversity, as in having a non-centrally controllable ecosystem, that is not a mono-culture. Your updates are the danger, your urge for control is the forrest fire.

Linux is not secure because its updated often. As package maintainer take-overs have show- that is even a vector. Its secure, because its fragmented into a thousand small populations, which offer no real financially interesting attack vector for a large scale take over.

Re: Update Regarding Add-Ons in Firefox

#365
post #350

Earlier quoted context omitted.

And operating system, and smartphone, and processor, and video card.

Hahahah look at all the Firefox fanboys coming out of the woodwork to try intellectual bullying because they're mad I admitted to uninstalling a web browser.

Or maybe they take offence at your overall tone? You're clearly not interested in being constructive.

This kind of toxicity is exactly why many of us have "uninstalled" Reddit and the like.

Please refrain from bringing that toxicity to HN.

Re: Update Regarding Add-Ons in Firefox

#366
post #48

Earlier quoted context omitted.

Hold up there. Before people start clicking and installing random add-on links, how about linking to something official (either from a FF dev, or in a soure repository) that references this URL?

This is true. However it is signed by moz and looking at the source it seems safe enough (the cert is legit). It's just a normal wrapper with the following code added: // first inject the new cert try { let intermediate = "MIIHLTCCBRWgAwIBAgIDEAAIMA0GCSqGSIb3DQEBDAUAMH0xCzAJBgNVBAYTAlVTMRwwGgYDVQQKExNNb3ppbGxhIENvcnBvcmF0aW9uMS8wLQYDVQQLEyZNb3ppbGxhIEFNTyBQcm9kdWN0aW9uIFNpZ25pbmcgU2VydmljZTEfMB0GA1UEAxMWcm9vdC1jYS1wc…

Thanks to this script, I think I just managed to apply the patch to an old Firefox 56 install, whereas the .xpi had no effect.

Re: Update Regarding Add-Ons in Firefox

#368
post #357

Earlier quoted context omitted.

So that's pretty unfair. 1) They state they are working on a fix for normal, release channel users who don't want to run studies 2) they tell you to temporarily run studies to get the fix within up to 6 six hours (could be faster; set expectation) 3) You can explicitly install nightly or 66.4 before it's pushed if you want a fix now Yes, it's unfortunate, I'd expect them to meet it head on, push a tested fix in a tim…

I'm not sure I care how unfair the characterization is. I heavily use container tabs — ahem, 'usecontainers — and all of my open container tabs disappeared at once , with no indication of why or what to do about it, when this happened. I lost an absurd amount of work and state because of that. I only knew what caused it by inference, because I'd just previously read The Fine Article (which, btw, gave no indication th…

This is pretty much exactly my thought as well.

Based on the timing of initial tweets and blog posts on this fiasco, I'm pretty sure I was in the first 10%, if not first 1%, of people who experienced this. And I was in a plane at 36,000 feet trying to work on a cross country (U.S.) flight when suddenly about 130 tabs in 7 windows disappeared. Really, REALLY bad. Panic, frustration, confusion...

I was more than 50% sure that all was not lost forever, that it was some "glitch" (Extensions all showed the same bloody red status), but I was tweaked. I work in security (embedded systems, not computers/IT) so I have a very good understanding of certificates, TLS, PKI, etc. There are many ways things can get out of whack if the people in charge screw up.

Regardless, this is embarrassing, dare I say shameful (pretty much almost up there with "Ooooppsss... we just lost our domain - it expired and no one thought to renew it)

Come on, guys, get it together. Have a procedure, document it, practice it, stay in front of it.

Re: Update Regarding Add-Ons in Firefox

#369
post #320

Earlier quoted context omitted.

> It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. I hate this attitude from security people so much. If for the sake of fighting malicious code you are crippling the software usability or my user experience, you are the malicious code.

So a security feature that had 0 impact for decades is "crippling" the usability of a project due to one outage?

I use container tabs extensively.

Today, more than half of my open tabs disappeared in an instant, and were not even an option to re-open until either I waited around ("up to six hours...") or manually installed the workaround. All of my in-progress work in any of those tabs? Gone.

That absolutely qualifies as crippled usability. The mere fact of such a thing being possible is a usability defect. On what basis do I trust that my work is not going to disappear on me like that again?

Re: Update Regarding Add-Ons in Firefox

#370

This one will be emotional as this destroyed some of my today's work. F you Mozilla. I lost all my tabs opened in other containers. The containers don't work too, so I cannot reopen them. This bug has been known for 3 years, and you did nothing to fix it. You get so much money, and what you do is basically provide a pathetic software (thunderbird) and a nice browser (which you just stopped from working) and you show…

Firefox keeps session backups in the profile folder. You might be able to recover your open tabs with it. I've been in a similar situation with tab groups and managed to recover all of them, though I don't remember exactly how.
Post reply on HN