Live data from Hacker News

Update Regarding Add-Ons in Firefox

blog.mozilla.org

381–390 of 504 posts

Re: Update Regarding Add-Ons in Firefox

#382
post #379

Earlier quoted context omitted.

> If you don't want security, you're welcome to have a malware-ridden system No, I am apparently not. Microsoft, Apple, and others insist on making it difficult. At least I found out today that I can install unsigned Firefox extensions once I switch to a special "unbranded" build. I'm glad Mozilla, at least, still offers that. Here's the thing: I disable a lot of the security stuff you're not supposed to disable, whe…

Just because you haven't been affected by a virus doesn't mean you never will. For example, the patch for the zero-day exploited by WannaCry was sent over windows update a few months before WannaCry existed. I personally use Linux, so Windows Update doesn't exactly exist for me, but I still update my system whenever such updates are available. Both SIP and driver signing are both mechanisms to prevent the installatio…

> The only reason you have this problem is because the folks at Mozilla forgot to renew that intermediate certificate. While I agree that it should be possible for users to disable extension signing, as users should be able to do whatever they want on their own system, you shouldn't blame them for forgetting to renew a certificate associated with an additional security measure built to protect users from malware.

Well, we agree on everything, in that case. :) I have no problem with sensible defaults that can be adjusted, nor do I take great issue with Mozilla's specific mistake in letting the certs expire.

Edit: Also, just noting that I only lessen security measures when I have a reason, not because I'm rebelling against security practices or something. I use a Jailbroken iPhone because I run Jailbroken software, and I disable driver signing because I use unsigned drivers. It's not that I don't see the risks, so much as I'm very unconvinced the risks are worth the downsides, for me.

Re: Update Regarding Add-Ons in Firefox

#383
post #373

I wonder if there is someone out there in the middle of the ocean with a browser extension based communication and navagation system which is dead in the water? It sounds to me that the real headline here is that every copy of firefox out there was timebombed and we only noticed because someone forgot to elongate the fuse.

Could other code signing systems like macOS gatekeeper also be vulnerable to problems like this?

IMO this seems like just plain bad design. The Firefox addon certificate should never have had an expiry date. If they ever needed to revoke it, they could distribute an updated version of the browser with the previous intermediate explicitly marked as revoked.

Re: Update Regarding Add-Ons in Firefox

#384
post #145

Earlier quoted context omitted.

This is bad design. Installed software shouldn't just stop working because the clock ticked. (And yes, I know browsers should stay up to date etc. etc., but come on, no software should just stop functioning because of a calendar) And to the downvoters: doesn't this entire fiasco ENTIRELY PROVE MY POINT?

> And to the downvoters: doesn't this entire fiasco ENTIRELY PROVE MY POINT? No. All it proves is that certificates expire (which is a Good Thing (tm)). If you depend on online certificates to verify content, something like this can theoretically happen.

Just because a cert expires is not a valid reason to disable functionality with no override available to the user. You may already know, you can override when visiting a website with an expired cert (once or forever). Yet nobody at Moz seemed to think it a good idea to allow it for extensions. Great.

Re: Update Regarding Add-Ons in Firefox

#385
post #320

Earlier quoted context omitted.

> It was designed to quickly deactivate any malicious add-on as soon as it was detected, before it had a chance to do too much damage. In my books, that's a good thing. I hate this attitude from security people so much. If for the sake of fighting malicious code you are crippling the software usability or my user experience, you are the malicious code.

I hate that attitude from entitled users so much. If you don't want security, you're welcome to have a malware-ridden system, but don't think that this means all users should have to put up with malware-ridden systems.

Say what now? Users are entitled for being in control of their own systems? Are you crazy?

Re: Update Regarding Add-Ons in Firefox

#386
post #292

Earlier quoted context omitted.

No. JUST A HUGE NOOOO. My reply is here https://news.ycombinator.com/item?id=19828472

We’re literally in this mess because Firefox requires digital signatures on this kind of thing, please don’t make FUD posts. This is much better than disabling the very same safe guard, signature checking, that prevents you from running arbitrary code in the first place.

How is this better then enabling studies, a setting that is already part of Firefox? Installing add-ons from random sources can be risky.

But anyways, I'm not sure why, but the addons on my main computer remained enabled... unlike my 2 other computers.

Re: Update Regarding Add-Ons in Firefox

#387

Can we take a moment and consider the side effects? This is a once in a lifetime chance for Google & Co. to get a glimpse of all those sly fuckers hiding behind adblockers. This effectively uncloaked a very specific subset of Internet users and exposed them to the very companies that they've been actively trying to avoid. Not just those who avoid Chrome, but those who take extra steps to explicitly evade the tracking…

I still don't understand why Mozilla is taking so long to simply post instructions for the .xpi install as you mention, hosted on their own domain?

it does really feel like "the great upscertificate expiration foul play"

Re: Update Regarding Add-Ons in Firefox

#389

Can we take a moment and consider the side effects? This is a once in a lifetime chance for Google & Co. to get a glimpse of all those sly fuckers hiding behind adblockers. This effectively uncloaked a very specific subset of Internet users and exposed them to the very companies that they've been actively trying to avoid. Not just those who avoid Chrome, but those who take extra steps to explicitly evade the tracking…

FWIW I think it's pretty easy to test if someone is using an adblocker anyway. (I see sites do the "It looks like you're using an adblocker" thing all the time). I don't know if there's any realistic way to entirely hide that.

That's a bit different though- generally speaking those messages show up when the javascript tracker can't talk to the server it's communicating with. Even though it's "detecting" the adblock it isn't able to send information back from the client about it.

Re: Update Regarding Add-Ons in Firefox

#390

This one will be emotional as this destroyed some of my today's work. F you Mozilla. I lost all my tabs opened in other containers. The containers don't work too, so I cannot reopen them. This bug has been known for 3 years, and you did nothing to fix it. You get so much money, and what you do is basically provide a pathetic software (thunderbird) and a nice browser (which you just stopped from working) and you show…

I lose all tabs occasionally. Browsers aren't perfect, it does happen after a weird crash, or something. It's exceedingly rare, like maybe twice a year. With that said, I've always considered tabs to be volatile state. Browsers make their best effort to e.g. restore the previous session after a crash, but if you want non-volatile browser state, you should use bookmarks.

It's not just tabs, but for many users the containers themselves are gone - as well as their cookies and other associated assumed-to-be-non-ephemeral state.
Post reply on HN