Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

371–380 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#371
post #361
post #360

Earlier quoted context omitted.

I wish that was true, but in fact I have no way to disable this and similiar amazing security entrenchments. The monthly device bricking windows updates, for instance. If I can't do anything with my hardened computer, I don't care if is eaten alive by malware, it is useless anyways. At work, as the guy who have to fight on behalf of the sysadmins and the users dozens of clueless security advisors who are hardening ev…

This petulant antagonism ("You are the malware!", "No YOU ARE!") between users and security is contrary to everyone's interests. Go sit in separate corners, both of you. Think really, really hard about how both of your jobs are critical to the long-term success of the business. Don't come back until you've meaningfully internalized that.

I'm having hard time understanding what are you referring to. All I'm saying is that I had a perfectly working system and now it is no more functioning properly. Why would anyone see this as more secure is beyond me.

Similarily, when "security best-practices" are leading to hundreds of my users losing SSO access to their BI system, or hundreds of printers rendered unusable because of security update that requires administrative permissions for reinstalling the same drivers that were perfectly working so far, I don't care for your security benefits. They suppose to defend against the thing that you are causing. You are already damaging the organization with thousands of working hours lost, and everyone is frustrated, as a bonus.

Re: Update Regarding Add-Ons in Firefox

#372

Earlier quoted context omitted.

Now I understand why Google renamed itself Alphabet. One step ahead, literally.

Have you been able to restore your search providers? Really a kick in the nuts, this one..

Nope. Maybe I should restart Nightly again but...I just added Google back, and it was not as easy as I'd expect. The Firefox "add search engines" page is a mess and straight Google search was like 3 pages down.

Also I found another dark theme that is somewhat similar to what I had (but not official Mozilla) and installed that. All the default ones are still disabled.

Re: Update Regarding Add-Ons in Firefox

#373
I wonder if there is someone out there in the middle of the ocean with a browser extension based communication and navagation system which is dead in the water?

It sounds to me that the real headline here is that every copy of firefox out there was timebombed and we only noticed because someone forgot to elongate the fuse.

Re: Update Regarding Add-Ons in Firefox

#374
post #320

Earlier quoted context omitted.

> It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. I hate this attitude from security people so much. If for the sake of fighting malicious code you are crippling the software usability or my user experience, you are the malicious code.

I hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.

> If you don't want security, you're welcome to have a malware-ridden system

No, I am apparently not. Microsoft, Apple, and others insist on making it difficult. At least I found out today that I can install unsigned Firefox extensions once I switch to a special "unbranded" build. I'm glad Mozilla, at least, still offers that.

Here's the thing: I disable a lot of the security stuff you're not supposed to disable, when I can. I use a Jailbroken iPhone. My Mac has SIP and Gatekeeper turned off. Windows Defender is turned off on my gaming PC, and I lower Microsoft's driver signing requirements to the greatest extent allowed. I also ran an unpatched day-1 build of Windows 10 for around four years, with the autoupdate system forcibly neutered. (I now run LTSB, instead.)

I have never been bitten by a virus, ever†. I don't know if that's because of all the security measures I'm not able to turn off or because I've been lucky or something else. I suspect it's because I don't run dodgy software. Or maybe my life is a lie and all my devices have been infected for the past decade, and I never noticed.

In the meantime, I'm not seeing the upside to software forcing hardened security.

---

P.S. While I share their frustrations, I don't endorse the GP's attitude. I know that a lot of people really are doing difficult work with the best of intentions.

† Except for a handful of times when I was testing suspicious software in a disposable VM. That doesn't count for obvious reasons.

Re: Update Regarding Add-Ons in Firefox

#375
Funny, I only just noticed my extensions were gone because of advertisements on youtube.

I just assumed I somehow messed up my browser and started looking around the settings.

A banner displaying why they silently updated FF and disabled the addons would have been nice as well :)

Re: Update Regarding Add-Ons in Firefox

#377

Earlier quoted context omitted.

Switch to what? Chrome? Because you don't like having to re-opt-in to studies? That would be ludicrous given Google's privacy track record. Opera? They're owned by a Chinese investment firm now. Edge? MS's whole OS is based on data collection.

Typing this from a new Brave install. Just switched from Firefox after their handling of this.

Have they stopped whitelisting Facebook and Twitter in their "tracking blocker" yet?

The BS coming from their blog post surrounding this whitelist makes me distrust them completely: "Loading a script from an edge-cache does not track a user without third-party cookies or equivalent browser-local storage" (...) "Given that most users on the web share IP addresses with other users because of NAT, it is unlikely this can be used to reliably track users"

Not only it's quite possible to know if the user is behind CGNAT or not, meaning the tracking works just fine for millions of users, but carriers have been known to inject user IDs in the replies of users behind CGNAT.

Re: Update Regarding Add-Ons in Firefox

#378

Earlier quoted context omitted.

I hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.

Sorry, but where is the difference from a secure-system that allows central control - and a male-ware backdoored system? All that is diffrent is the promise of non-maliciousness. Which often does not hold up. Cause money is corrosive to those little centralized empires of "all-can-fail-but-me". Security is diversity, as in having a non-centrally controllable ecosystem, that is not a mono-culture. Your updates are the…

Linux's diversity also makes it difficult to package and distribute non-malicious software, so I'm not sure that's the poster child for how to do security without compromising usability.

(The situation is admittedly getting better with Flatpak.)

Re: Update Regarding Add-Ons in Firefox

#379

Earlier quoted context omitted.

I hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.

> If you don't want security, you're welcome to have a malware-ridden system No, I am apparently not. Microsoft, Apple, and others insist on making it difficult. At least I found out today that I can install unsigned Firefox extensions once I switch to a special "unbranded" build. I'm glad Mozilla, at least, still offers that. Here's the thing: I disable a lot of the security stuff you're not supposed to disable, whe…

Just because you haven't been affected by a virus doesn't mean you never will. For example, the patch for the zero-day exploited by WannaCry was sent over windows update a few months before WannaCry existed. I personally use Linux, so Windows Update doesn't exactly exist for me, but I still update my system whenever such updates are available. Both SIP and driver signing are both mechanisms to prevent the installation of rootkits. If you do get a virus, such mechanisms would prevent it from hiding itself or causing more damage to the system.

Not running dodgy software is indeed a very effective way to not get viruses, but that doesn't mean you shouldn't take more security precautions if they are available. What if, for example, malware exploits a zero-day in your browser and successfully installs itself without any interaction from the user? Windows Defender and related antivirus could detect malicious activity from such malware and remove it on windows and Gatekeeper/SIP/driver signing and related systems could severely limit its impact.

Mozilla probably introduced extension signing to prevent less technically inclined users from having adware installed into their browser. X.509 introduces certificate expiration, and X.509 is the most widely used mechanism for signing things. The only reason you have this problem is because the folks at Mozilla forgot to renew that intermediate certificate. While I agree that it should be possible for users to disable extension signing, as users should be able to do whatever they want on their own system, you shouldn't blame them for forgetting to renew a certificate associated with an additional security measure built to protect users from malware.

Re: Update Regarding Add-Ons in Firefox

#380
post #233

Earlier quoted context omitted.

> their main market is tech savvy people that tend to be more sensitive to this than most Is that so, though? Firefox is still being used by millions of users, and I doubt those are only the tech savvy internet users. (Then again, this mostly applies to Firefox users using add-ons, which probably has a higher share of technical users.)

One of their biggest 'selling points' is that they protect your privacy. It's really, really off brand for them to be distributing a critical bugfix through a telemetry collection channel.

it does feel like the normalization of deviance

it's also entirely predictable that a non-negligable fraction of users -after enabling studies and verifying everything works again- will ... simply go on with their lives and forget about disabling studies...

I also don't understand why the certificate graph is not exposed through a user interface, so that the user can add and remove certificates, or enable and disable certificates at their own discretion. This should have been obvious when the certified add-ons were introduced. Then all they would have to do is host the certificate file on their own domain and everyone could follow the simple steps in the GUI to replace the expired certificate...

Post reply on HN